• 0 Votes
    3 Posts
    870 Views
    J
    Hi jimp, Thanks for this. This stopped me making a big mistake (not adding new switches to the purchase list) and potentially wasting hours trying to work out why CARP wasn't working. It will also save me the hassle of arranging with Virgin for an upgrade we don't need. I do actually now remember reading in the pfsense book that the switches must be checked for multicast support. However, the text didn't properly register until your reply. Thanks again for your help and patience.
  • 2 X PFsense HA with 2 X WAN is it possible?

    17
    1
    0 Votes
    17 Posts
    3k Views
    J
    @everyonelovescheese : Thanks for updating the thread with your final outcome i.e. getting new IPs. It helped me by closing the subject down at my end as not currently viable and allowing me to move on.
  • This topic is deleted!

    2
    0 Votes
    2 Posts
    35 Views
  • CARP: Web GUI on backup slow but only from LAN, WAN is fine

    3
    0 Votes
    3 Posts
    678 Views
    F
    Thanks, this was the trick!
  • CARP VIP member recovery problems

    vip carp restore
    13
    0 Votes
    13 Posts
    3k Views
    E
    i've solved the problem. its very similar to bridge behavior i encountered in another installation. I only have vlans defined for my LAGG. once i created another interface that would be untagged on the LAGG, it picked up my native vlan as expected. all of the VIPs for the tagged interfaces started working. so just for my own curiosity i deleted the native interface i crated and rebooted. everything still works. all in all i must have just jiggled the handle
  • Virtual Interface or virtual ip's

    1
    0 Votes
    1 Posts
    445 Views
    No one has replied
  • Configure virtual IP Pfsense at OVH

    6
    0 Votes
    6 Posts
    4k Views
    DerelictD
    No idea you are obfuscating too much to see what you're actually doing.
  • Virtual IP using different subnet

    Locked
    15
    0 Votes
    15 Posts
    10k Views
    DerelictD
    You probably want to start a new thread. Locking this moldy one.
  • Unicast flooding with CARP. How to debug?

    2
    0 Votes
    2 Posts
    836 Views
    DerelictD
    If the switch is not learning CARP VIPs from the CARP advertisements it is probably some sort of multicast "feature" on the switch. If the switch is receiving traffic from that MAC address it needs to: Remove that MAC address from all other ports Add the MAC address to the port it was received on If that is not happening, it's a problem with the switch.
  • Virtual IP Proxy ARP Network will use invalid IPs for Pool

    8
    0 Votes
    8 Posts
    1k Views
    DerelictD
    That (now-deleted) reply was totally to the wrong thread. Sorry. Well, right, you should not have a /25 on your WAN interface. You should have a much smaller subnet there and the /25 should be routed to you. If that was the case, as strange as it sounds, .0 and .127 would be valid NAT addresses. In order to use something other than round robin you must use type subnet. If you can use round robin, just define a host alias using a range and NAT to that.
  • HA in Azure

    1
    1 Votes
    1 Posts
    806 Views
    No one has replied
  • IPv6 CARP with a /127

    8
    0 Votes
    8 Posts
    1k Views
    DerelictD
    The backup needs to make requests to do things like check for updates.
  • High Availabilty Multi WAN VIP Gateway failover fault

    1
    1 Votes
    1 Posts
    451 Views
    No one has replied
  • CARP/HA IPSec on Backup Node - connection not found?

    17
    0 Votes
    17 Posts
    1k Views
    S
    I think the XMLRPCSync is working, there are no errors. All changes are visible in the ipsec user interface of the second node and if I make a "diff" of the configuration-backup XML of both nodes... all ipsec changes are included in the configuration of the second node. There must be an additional step after the XMLRPCSync which transfers the changes to "/var/etc/ipsec/ipsec.conf" and that fails or is not executed... Because after a reboot the file is "in-sync" with the configuration. Is it possible to change the debuglevel somewhere or add log output to the php source code?
  • CARP ERROR

    1
    0 Votes
    1 Posts
    307 Views
    No one has replied
  • WAN VIP Troubles

    2
    0 Votes
    2 Posts
    579 Views
    DerelictD
    Going to have to slow down and take things one at a time. When you put your primary WAN interface on one address, your secondary WAN interface on another, and your CARP VIP on the third, is the Primary the CARP MASTER, and the Secondary the CARP BACKUP? You can packet capture on your WAN to see if anyone else is using CARP/VRRP. That's pretty much the only way to know.
  • Squid HA

    1
    0 Votes
    1 Posts
    498 Views
    No one has replied
  • Virtual IP and NAT Troubleshooting

    2
    0 Votes
    2 Posts
    489 Views
    johnpozJ
    So this is basic port forward troubleshooting issue. For starters RDP open to the public - Would NOT suggest!!! If you need to rdp to some server on your network, vpn into your network than access. Please look over the troubleshooting guide https://www.netgate.com/docs/pfsense/nat/port-forward-troubleshooting.html Come back if you have specific questions.. My guess off the top without any details at all would be your servers firewall... Out of the box windows sure and hell not going to allow rdp from some public IP.. Out of the box only the local network can rdp, etc.
  • DNS Forwarder on CARP doesn't register hostname in DHCP lease on secondary

    Locked
    20
    0 Votes
    20 Posts
    6k Views
    DerelictD
    The solution is right there. Set up a DDNS server off the firewall and have both nodes update that. Locking this ancient thread.
  • bidirectionnal sync

    6
    0 Votes
    6 Posts
    1k Views
    jimpJ
    @skullnobrains said in bidirectionnal sync: i assume carp load sharing is a no-go as well Correct. There is no active/active CARP, and no plans for it. @skullnobrains said in bidirectionnal sync: would netgate be interested into adding the feature to the stock pfsense ? As far as I'm aware, we do not have any interest in that. We are focusing any effort in that area on working toward a proper API rather than adding to the current less-than-ideal methods.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.