• CARP/HA Issue with connection

    6
    0 Votes
    6 Posts
    790 Views
    B
    I think I may have found the issue. Both device their selves were in the NAT range tied to the single VIP. I believe the secondary box was communicating out, but any reply went back to the primary box. I found a NAT setting to map "This Firewall" to it's WAN interface address and not the VIP. That seems to have worked on both devices. I did have our upstream provider NAT all to the same public IP: VIP x.x.x.1 Device 1 x.x.x.2 Device 2 x.x.x.3 Thank you all for the help!
  • dhcp carp and automatic sync

    5
    0 Votes
    5 Posts
    1k Views
    S
    what is your point ? my carp setup does work. i have multiple machines in each vlan. no problem there. i can shutdown either firewall and unplug any cable without producing a mess. i had disabled pfsync in some previous tests which is why using the carp address as the gateway is required. am i expected to configure a LAN interface as the first interface and use the LAN address as the failover peer for each of the dhcp server instances ? this would be meaningful indeed. but in that case, it may be worth to drop a line in the documentation and there is little to no point in setting the same address for each dhcp instance.
  • OpenVPN Failback Issue in High Availablility

    6
    0 Votes
    6 Posts
    861 Views
    S
    @netblues Yeah you were on the money. Bound the OpenVPN client service to the CARP WAN VIP and failover/failback operates perfectly - as does all everything else. Perfect, thank you :) (better check my settings more thoroughly next time ;) )
  • carp/ha, sync client-hostname in dhcp lease files missing

    9
    0 Votes
    9 Posts
    1k Views
    L
    I just updated my test vms to 2.4.4-RELEASE-p1 and from what I can tell the issue has been fixed! I now get the client-hostname on the master and the backup
  • 0 Votes
    3 Posts
    758 Views
    J
    Hi jimp, Thanks for this. This stopped me making a big mistake (not adding new switches to the purchase list) and potentially wasting hours trying to work out why CARP wasn't working. It will also save me the hassle of arranging with Virgin for an upgrade we don't need. I do actually now remember reading in the pfsense book that the switches must be checked for multicast support. However, the text didn't properly register until your reply. Thanks again for your help and patience.
  • 2 X PFsense HA with 2 X WAN is it possible?

    17
    0 Votes
    17 Posts
    3k Views
    J
    @everyonelovescheese : Thanks for updating the thread with your final outcome i.e. getting new IPs. It helped me by closing the subject down at my end as not currently viable and allowing me to move on.
  • This topic is deleted!

    2
    0 Votes
    2 Posts
    35 Views
  • CARP: Web GUI on backup slow but only from LAN, WAN is fine

    3
    0 Votes
    3 Posts
    597 Views
    F
    Thanks, this was the trick!
  • CARP VIP member recovery problems

    vip carp restore
    13
    0 Votes
    13 Posts
    3k Views
    E
    i've solved the problem. its very similar to bridge behavior i encountered in another installation. I only have vlans defined for my LAGG. once i created another interface that would be untagged on the LAGG, it picked up my native vlan as expected. all of the VIPs for the tagged interfaces started working. so just for my own curiosity i deleted the native interface i crated and rebooted. everything still works. all in all i must have just jiggled the handle
  • Virtual Interface or virtual ip's

    1
    0 Votes
    1 Posts
    397 Views
    No one has replied
  • Configure virtual IP Pfsense at OVH

    6
    0 Votes
    6 Posts
    4k Views
    DerelictD
    No idea you are obfuscating too much to see what you're actually doing.
  • Virtual IP using different subnet

    Locked
    15
    0 Votes
    15 Posts
    9k Views
    DerelictD
    You probably want to start a new thread. Locking this moldy one.
  • Unicast flooding with CARP. How to debug?

    2
    0 Votes
    2 Posts
    760 Views
    DerelictD
    If the switch is not learning CARP VIPs from the CARP advertisements it is probably some sort of multicast "feature" on the switch. If the switch is receiving traffic from that MAC address it needs to: Remove that MAC address from all other ports Add the MAC address to the port it was received on If that is not happening, it's a problem with the switch.
  • Virtual IP Proxy ARP Network will use invalid IPs for Pool

    8
    0 Votes
    8 Posts
    1k Views
    DerelictD
    That (now-deleted) reply was totally to the wrong thread. Sorry. Well, right, you should not have a /25 on your WAN interface. You should have a much smaller subnet there and the /25 should be routed to you. If that was the case, as strange as it sounds, .0 and .127 would be valid NAT addresses. In order to use something other than round robin you must use type subnet. If you can use round robin, just define a host alias using a range and NAT to that.
  • HA in Azure

    1
    1 Votes
    1 Posts
    761 Views
    No one has replied
  • IPv6 CARP with a /127

    8
    0 Votes
    8 Posts
    1k Views
    DerelictD
    The backup needs to make requests to do things like check for updates.
  • High Availabilty Multi WAN VIP Gateway failover fault

    1
    1 Votes
    1 Posts
    401 Views
    No one has replied
  • CARP/HA IPSec on Backup Node - connection not found?

    17
    0 Votes
    17 Posts
    1k Views
    S
    I think the XMLRPCSync is working, there are no errors. All changes are visible in the ipsec user interface of the second node and if I make a "diff" of the configuration-backup XML of both nodes... all ipsec changes are included in the configuration of the second node. There must be an additional step after the XMLRPCSync which transfers the changes to "/var/etc/ipsec/ipsec.conf" and that fails or is not executed... Because after a reboot the file is "in-sync" with the configuration. Is it possible to change the debuglevel somewhere or add log output to the php source code?
  • CARP ERROR

    1
    0 Votes
    1 Posts
    299 Views
    No one has replied
  • WAN VIP Troubles

    2
    0 Votes
    2 Posts
    523 Views
    DerelictD
    Going to have to slow down and take things one at a time. When you put your primary WAN interface on one address, your secondary WAN interface on another, and your CARP VIP on the third, is the Primary the CARP MASTER, and the Secondary the CARP BACKUP? You can packet capture on your WAN to see if anyone else is using CARP/VRRP. That's pretty much the only way to know.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.