• carp preempt problem - only the fault interface vip switches

    13
    0 Votes
    13 Posts
    2k Views
    DerelictD

    https://docs.netgate.com/pfsense/en/latest/book/highavailability/example-redundant-configuration.html#setup-sync-interface

  • This topic is deleted!

    1
    0 Votes
    1 Posts
    4 Views
    No one has replied
  • Port Forwarding not working with VIP (WAN)

    4
    0 Votes
    4 Posts
    1k Views
    D

    Closing this. Thanks for pointing me into the direction of testing the Ping on the CARP VIP. That ended up being the issue. Turns out somehow ISP took back one of our 3 IPs, we got them to put it back on our account and now we are back to normal. Can ping off that CARP VIP as well as port forwarding works now using the CARP VIP as Destination Address.

    Thanks again @Derelict

  • HA Configuration with Avahi

    1
    0 Votes
    1 Posts
    390 Views
    No one has replied
  • Enable CARP maintenance when state changes for one interface

    3
    0 Votes
    3 Posts
    810 Views
    M

    Thanks @JeGr . I've now installed Filer and I can definitely see the use in it for restoring/syncing my script files. I can see that I can also probably use it for /etc/pfSense-devd.conf. But that brings the next problem of what happens when the Netgate team updates this file? The "latest" and correct version would get overwritten by my file in Filer. Out of curiosity I've checked the file on GitHub and it was indeed updated 2 months ago and those changes are in the file on my routers. So that means it will definitely change with an upcoming upgrade.

    Is there no other/better way to force the maintenance mode or execute the devd actions without modifying a system file?

  • Reasons/conditions for CARP state change

    3
    0 Votes
    3 Posts
    452 Views
    M

    Thanks for that clarification @jimp. It helps.

  • CARP failover events triggered for no obvious

    3
    0 Votes
    3 Posts
    559 Views
    M

    @Derelict said in CARP failover events triggered for no obvious:

    those
    Hallo,

    thanks for your reply.

    I have some layer 2 errors on the switch (spanning-tree). I will try to fix the errors and provide feedback as soon as possible, but I only have "downtime" at Friday to test my configs.

    Thanks for your help.

  • CARP on huge Virtual cluster (one network)

    1
    0 Votes
    1 Posts
    232 Views
    No one has replied
  • HA CARP - IPv6 Two masters

    56
    0 Votes
    56 Posts
    15k Views
    RodrinoyR

    @awebster that was exactly what i tought too!!!

  • AWS Dynamic VPN with PFSense (routed mode)

    3
    0 Votes
    3 Posts
    493 Views
    V

    The failover itself works fine by entering to maintenance mode but the VPN tunnels don't want to bring up. They should and it works when tunnels are terminated with other vendors. This situation is only with AWS cloud. Moreover, the pfsense should initiate the connection. The AWS never brings the VPN tunnels up. In case when I use the policy based VPN (the traffic initiated behind the firewall) it works fine. Moreover, the same setup as I have now such as VTI interfaces, routed-based VPNs were configured on VyOS which switchover the tunnels automatically in case of failover.

  • HA VPN Dual Provider

    1
    0 Votes
    1 Posts
    301 Views
    No one has replied
  • Virtual IP addresses for beginners

    5
    0 Votes
    5 Posts
    755 Views
    D

    Perfect - thanks so much

  • HA cfg from VPN cannot ping the nother host!

    3
    0 Votes
    3 Posts
    448 Views
    B

    @jimp

    Thanks i didnt find this.

    bolvar

  • Under HA cfg the backup node NTP sync have a 2 minute delay sometime!

    1
    0 Votes
    1 Posts
    184 Views
    No one has replied
  • In HA CARP Setup do LAGG names need to match?

    8
    0 Votes
    8 Posts
    1k Views
    JeGrJ

    Ah thanks :) That clears it up pretty much. Never actually ran into that issue besides static mappings and that is no problem in a cluster that I'm aware of ;)

  • Can't delete virtual IP address

    9
    0 Votes
    9 Posts
    4k Views
    johnpozJ

    You could always pull the vip out of the config, and then reload it.

    Backup, edit xml to remove the vip, restore the backup.

  • 0 Votes
    5 Posts
    2k Views
    K

    Thank you for your answer.

    Thanks for the input. I have examined it further. It needs to be enabled in Hyper-v vswitch MAC-spoofing, then it works.

    Thank you!

  • Can't PING carp virtual IP

    7
    0 Votes
    7 Posts
    3k Views
    DerelictD

    Packet capture on the WAN. If the traffic arrives but there is no response (there will be) it's something on the firewall.

    If the traffic doesn't arrive (it will start with ARP traffic) then it's something in your virtual infrastructure, switching, etc.

  • 0 Votes
    24 Posts
    2k Views
    H

    @Derelict Just wanted to let you know know it's looking allot better now and I think it was just that lingering interface that should have been down that caused the issue (which then caused others).

    Thanks for coming back so quick on a Sunday. FYI, I've now hit another Intel 10G known issue which I'll post once I re-read the previous ones

  • Carp. OpenVPN client - permanent connection and disconnection

    18
    0 Votes
    18 Posts
    2k Views
    A

    @Derelict
    Super. Fine. Exactly what is needed !

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.