• CARP / HASYNC : password in cleartext in .xml

    3
    0 Votes
    3 Posts
    588 Views
    F
    Great answer. That is what I was looking for : a limited privilege account. I will try this soon. Best Regards (and Merry Xmas to all)
  • Setup HA with existing system

    4
    0 Votes
    4 Posts
    639 Views
    S
    also the Book: https://www.netgate.com/docs/pfsense/book/highavailability/index.html
  • CARP VIP not passing traffic

    18
    0 Votes
    18 Posts
    2k Views
    johnpozJ
    If you do - don't use .1 or .254 since those are common default IPs ;) Pretty much the reason pfsense IP on all its vlans is .253...
  • Virtual IP Possible Issue?

    2
    0 Votes
    2 Posts
    537 Views
    DerelictD
    You cannot use Proxy ARP for IPv6 because IPv6 does not use ARP. You'll have to use IP Alias. Any IPv6 on inside interfaces should be provisioned using an interface network and a routed prefix to you. Like a /48, /56 or /60. It sounds like you are trying to shoehorn a VPS service designed to run something like a cPanel or Plesk system into use with a router. You're going to meet with undesirable results in all likelihood. No. LADVD is something entirely different.
  • CARP/HA Issue with connection

    6
    0 Votes
    6 Posts
    851 Views
    B
    I think I may have found the issue. Both device their selves were in the NAT range tied to the single VIP. I believe the secondary box was communicating out, but any reply went back to the primary box. I found a NAT setting to map "This Firewall" to it's WAN interface address and not the VIP. That seems to have worked on both devices. I did have our upstream provider NAT all to the same public IP: VIP x.x.x.1 Device 1 x.x.x.2 Device 2 x.x.x.3 Thank you all for the help!
  • dhcp carp and automatic sync

    5
    0 Votes
    5 Posts
    1k Views
    S
    what is your point ? my carp setup does work. i have multiple machines in each vlan. no problem there. i can shutdown either firewall and unplug any cable without producing a mess. i had disabled pfsync in some previous tests which is why using the carp address as the gateway is required. am i expected to configure a LAN interface as the first interface and use the LAN address as the failover peer for each of the dhcp server instances ? this would be meaningful indeed. but in that case, it may be worth to drop a line in the documentation and there is little to no point in setting the same address for each dhcp instance.
  • OpenVPN Failback Issue in High Availablility

    6
    0 Votes
    6 Posts
    939 Views
    S
    @netblues Yeah you were on the money. Bound the OpenVPN client service to the CARP WAN VIP and failover/failback operates perfectly - as does all everything else. Perfect, thank you :) (better check my settings more thoroughly next time ;) )
  • carp/ha, sync client-hostname in dhcp lease files missing

    9
    0 Votes
    9 Posts
    1k Views
    L
    I just updated my test vms to 2.4.4-RELEASE-p1 and from what I can tell the issue has been fixed! I now get the client-hostname on the master and the backup
  • 0 Votes
    3 Posts
    805 Views
    J
    Hi jimp, Thanks for this. This stopped me making a big mistake (not adding new switches to the purchase list) and potentially wasting hours trying to work out why CARP wasn't working. It will also save me the hassle of arranging with Virgin for an upgrade we don't need. I do actually now remember reading in the pfsense book that the switches must be checked for multicast support. However, the text didn't properly register until your reply. Thanks again for your help and patience.
  • 2 X PFsense HA with 2 X WAN is it possible?

    17
    0 Votes
    17 Posts
    3k Views
    J
    @everyonelovescheese : Thanks for updating the thread with your final outcome i.e. getting new IPs. It helped me by closing the subject down at my end as not currently viable and allowing me to move on.
  • This topic is deleted!

    2
    0 Votes
    2 Posts
    35 Views
  • CARP: Web GUI on backup slow but only from LAN, WAN is fine

    3
    0 Votes
    3 Posts
    631 Views
    F
    Thanks, this was the trick!
  • CARP VIP member recovery problems

    vip carp restore
    13
    0 Votes
    13 Posts
    3k Views
    E
    i've solved the problem. its very similar to bridge behavior i encountered in another installation. I only have vlans defined for my LAGG. once i created another interface that would be untagged on the LAGG, it picked up my native vlan as expected. all of the VIPs for the tagged interfaces started working. so just for my own curiosity i deleted the native interface i crated and rebooted. everything still works. all in all i must have just jiggled the handle
  • Virtual Interface or virtual ip's

    1
    0 Votes
    1 Posts
    416 Views
    No one has replied
  • Configure virtual IP Pfsense at OVH

    6
    0 Votes
    6 Posts
    4k Views
    DerelictD
    No idea you are obfuscating too much to see what you're actually doing.
  • Virtual IP using different subnet

    Locked
    15
    0 Votes
    15 Posts
    9k Views
    DerelictD
    You probably want to start a new thread. Locking this moldy one.
  • Unicast flooding with CARP. How to debug?

    2
    0 Votes
    2 Posts
    787 Views
    DerelictD
    If the switch is not learning CARP VIPs from the CARP advertisements it is probably some sort of multicast "feature" on the switch. If the switch is receiving traffic from that MAC address it needs to: Remove that MAC address from all other ports Add the MAC address to the port it was received on If that is not happening, it's a problem with the switch.
  • Virtual IP Proxy ARP Network will use invalid IPs for Pool

    8
    0 Votes
    8 Posts
    1k Views
    DerelictD
    That (now-deleted) reply was totally to the wrong thread. Sorry. Well, right, you should not have a /25 on your WAN interface. You should have a much smaller subnet there and the /25 should be routed to you. If that was the case, as strange as it sounds, .0 and .127 would be valid NAT addresses. In order to use something other than round robin you must use type subnet. If you can use round robin, just define a host alias using a range and NAT to that.
  • HA in Azure

    1
    1 Votes
    1 Posts
    785 Views
    No one has replied
  • IPv6 CARP with a /127

    8
    0 Votes
    8 Posts
    1k Views
    DerelictD
    The backup needs to make requests to do things like check for updates.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.