• WAN "disabled" after adding a VIP

    5
    0 Votes
    5 Posts
    1k Views
    JeGrJ
    Just as I'm curious: I thought 2.4.4(-p1+) was already config rev 19.1? At last that's what my cluster systems tell me in system log?
  • 0 Votes
    2 Posts
    270 Views
    No one has replied
  • Pfsense with HA closing sessions when apply any rule.

    9
    2
    0 Votes
    9 Posts
    1k Views
    DerelictD
    Again, the proper forum for documentation feedback is the give feedback link on the page.
  • CPU load/loss of Packets after 2-3 days with HA-setup

    1
    0 Votes
    1 Posts
    280 Views
    No one has replied
  • Problem of CARP with IPSEC

    13
    4
    0 Votes
    13 Posts
    2k Views
    A
    @JeGr thank you for your reply finally i found the problem it was related with GNS3 because my 2 sites are connected with it. the cloud's i used to represent my LAN block the VIP of the LAN when i shutdown the Master.
  • How can make Dependency between 2 Vhid Group

    1
    0 Votes
    1 Posts
    249 Views
    No one has replied
  • Multiple Public IPs Assigned directly to machines

    8
    0 Votes
    8 Posts
    1k Views
    johnpozJ
    Huh? No a router can not have the same networks or overlapping networks on multiple interfaces, ie its wan and lan.. But if the /29 is routed to you this would never be the case since your wan would be the transit network and wouldn't overlap with your routed /29 This has zero to do specific with pfsense - and is just basic 101 routing. Here lets do an example... isp .1 --- 1.2.3.0/30 --- .2 wan pfsense opt .1 --- 4.5.6.0/29 --- devices .2, .3, .4 etc.. And sure pfsense could also have lan network in 192.168.1.0/24 Now your isp routes 4.5.6.0/29 to your 1.2.3.2 address.
  • XMLRPC sync operation timed out

    6
    0 Votes
    6 Posts
    1k Views
    N
    Okay. Noted. Thank you.
  • HA with Netgate + esxi

    1
    0 Votes
    1 Posts
    229 Views
    No one has replied
  • This topic is deleted!

    1
    0 Votes
    1 Posts
    11 Views
    No one has replied
  • messed up dhcpd.conf (and probably other settings)

    1
    0 Votes
    1 Posts
    288 Views
    No one has replied
  • OpenVPN with Radius not working correctly with HA

    3
    0 Votes
    3 Posts
    663 Views
    H
    I spoke too soon, it's still not working 100% of the time. When the backup-pfsense is entering MASTER-status, not all of the time Radius gets started correctly, sometimes I see the following in the Radius-logfile, right afster started it gets stopped again: Mon Apr 15 14:16:21 2019 : Info: Ready to process requests Mon Apr 15 14:16:21 2019 : Info: Signalled to terminate Mon Apr 15 14:16:21 2019 : Info: Exiting normally
  • 0 Votes
    2 Posts
    2k Views
    DerelictD
    Sorry. I have no idea what you are even asking. The basic things that need to be changed to run pfSense HA in VMware ESXi are described here: https://docs.netgate.com/pfsense/en/latest/highavailability/troubleshooting-high-availability-clusters.html?highlight=esxi#hypervisor-users-especially-vmware-esx-esxi
  • NTP not running on backup FW?

    11
    0 Votes
    11 Posts
    1k Views
    P
    So now everything worked fine for a little while. But then I saw this: [image: 1555034313766-ntp_status_unreachable.png] Using a shell on pfsense I can ping each NTP server and I can also use ntpdate to set the clock. So basically it's not a firewall or routing problem I think. NTP log doesn't show anything unusual or different compared to the master firewall. I'll keep looking.
  • Multiple WAN HA setup (No Multi-WAN LB or FO)

    3
    0 Votes
    3 Posts
    623 Views
    DerelictD
    You can probably get away with having only one proper WAN with two single-address WANs as long as: All addresses are static (not DHCP, PPPoE, etc) You ensure that the default gateway in the routing table is always the interface where the secondary can get out (has its own routeable interface address) The main issue is that the secondary can access the internet (get updates, resolve DNS, etc) when it is CARP BACKUP.
  • Recovering HA device

    3
    0 Votes
    3 Posts
    604 Views
    J
    Is there a quick way to copy the config from the secondary over to the replaced device? We had a similar failure here.
  • CARP both becoming master on a subnet

    5
    1
    0 Votes
    5 Posts
    937 Views
    V
    Thanks, I will continue my investigation, if I have any further information or questions I will get back to this topic. Thanks
  • Maybe a bug with sync of descriptions of firewall rules

    3
    0 Votes
    3 Posts
    554 Views
    P
    OK, I found the problem. https://github.com/pfsense/pfsense/blob/master/src/etc/rc.filter_synchronize A bunch of these lines: $config_copy['nat']['outbound']['rule'][$x]['descr'] = remove_special_characters($config_copy['nat']['outbound']['rule'][$x]['descr']); The function remove_special_characters strips out everything but a-z, A-Z, 0-9 _ - + Should have maybe used the function htmlspecialchars instead to get special characters encoded instead of stripping them. Also having the xml in UTF-8 allows you to put a lot of international characters in the xml file. Anyway, it's looks like it's been working like this for years.
  • CARP limiters and Traffic Shaping

    2
    0 Votes
    2 Posts
    376 Views
    jimpJ
    I was able to reproduce both of those bugs. We've hit similar things in the past. I created new issues for them: Limiters: https://redmine.pfsense.org/issues/9468 ALTQ Shaper: https://redmine.pfsense.org/issues/9469
  • Pfsense HA setup Issue

    4
    0 Votes
    4 Posts
    759 Views
    DerelictD
    All changes that are synced.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.