• HA Sync does not work (Error: Operation timed out)

    2
    0 Votes
    2 Posts
    699 Views
    D
    Solution: I connected the two PFS with a virtual Switch (VXLAN+IPSEC). For this i had to lower the MTU to 1360. Unfortunatelly the Adapter in PFSense was set to 1500 and not appling for the new MTU. Setting down the MTU (in my case to 1360) manually in the SYNC-Interface-Options solved the problem.
  • no internet browsing via pfsense ha

    1
    0 Votes
    1 Posts
    140 Views
    No one has replied
  • dup on ping to external ip in carp setup

    2
    0 Votes
    2 Posts
    208 Views
    S
    @Snailkhan Have never seen that. Only one is Master? You’re NATting to the shared LAN IP? What is that for?
  • HA failover in case of one member interface down

    2
    0 Votes
    2 Posts
    265 Views
    V
    @Snailkhan Ensure that all interface pairs can communicate with the respective other node.
  • LAN communication via CARP IP

    2
    0 Votes
    2 Posts
    256 Views
    V
    @Snailkhan By default the primary interface IP is used for communication with other devices. If you want pfSense to use the CARP VIP you have to add an outbound NAT rule to LAN or the respective interface and set the CARP VIP as translation address. However, don't do this for any traffic! It would lead into issues with services running on both nodes, e.g. DHCP. So limit the destination (IP and port) to the domain controller or whatever you need it for.
  • HA/CARP with two WAN same /29

    3
    0 Votes
    3 Posts
    348 Views
    F
    @SteveITS I would prefer not to add more gear for now, since this is temporary until I have two pfSense units and CARP. Maybe I'll just have both connected, but configure the 2nd one in case of longer downtime then.
  • HA CARP Failover Sensitivity

    1
    0 Votes
    1 Posts
    178 Views
    No one has replied
  • CARP: adding additional Interface/VLAN

    4
    0 Votes
    4 Posts
    4k Views
    W
    i have the exact set up but not able to sync
  • Connection lost on second failover/failback switch

    1
    0 Votes
    1 Posts
    180 Views
    No one has replied
  • carp: demoted by 0 to 0 (send error 55 on ix3)

    1
    0 Votes
    1 Posts
    215 Views
    No one has replied
  • HA XMLRPC Error

    2
    0 Votes
    2 Posts
    218 Views
    No one has replied
  • 0 Votes
    1 Posts
    173 Views
    No one has replied
  • pfBlocker frequent updates

    1
    0 Votes
    1 Posts
    252 Views
    No one has replied
  • CARP + UniFi controller

    1
    0 Votes
    1 Posts
    251 Views
    No one has replied
  • Far too many BE's! One HA-proxy backend per service!! Possible !!??

    2
    0 Votes
    2 Posts
    250 Views
    L
    @louis2 I think separate back-ends for IPV4 and IPV6 are not necessary not even a good idea since the proxy has two completely isolated connections. One to the front end, one to the server. So I decided to handle all server related connections via IPV4 since local IPV4 can not be reached from the internet. That action already reduced the number of backends by a factor two
  • HA development IPV6 backend seems to have a problem !?!

    2
    0 Votes
    2 Posts
    282 Views
    L
    @louis2 I worked around the problem by defining the mail-server addresses in my local DNS and using those names in the GUI. Never the less it is definitively not OK Also note that I had the problem back when switching the health check on (to basic). Even more obscure switching the problem did persist when switching the health check off again. No idea how the check should be done since there is no proper field to define the health check port number.
  • HAproxy usage of "Type" and "Expression fields"

    1
    0 Votes
    1 Posts
    169 Views
    No one has replied
  • Right way to hardware HA for LANs,- LAGGr?

    laggr
    4
    0 Votes
    4 Posts
    577 Views
    Sergei_ShablovskyS
    Up
  • load balancing using my neighbourg

    5
    0 Votes
    5 Posts
    577 Views
    P
    from wan2, i can ping common website when the both wan are connected. But when wan1 is disconnected, everything is very slow and i can't ping anything : [image: 1729167097512-screenshot-2024-10-17-140902.png]
  • Can I use virtual IP as gateway?

    4
    0 Votes
    4 Posts
    746 Views
    V
    @accidentallyadmin pfSense can only translate the source address to the stated IP. Maybe your ISP does an additional translation, but this is unusual if you have a public IP already. You can verify the function of your outbound NAT rule by sniffing the traffic on WAN (Diagnostic > Packet Capture). The outbound NAT rule is the last in the pipe, before packets leave the firewall. See Firewall/NAT Processing Order Example for details.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.