• Pfsense upgrade and sync error

    2
    0 Votes
    2 Posts
    665 Views
    DerelictD
    If you cannot upgrade the secondary, backup the configuration, install 2.4.2 fresh, and restore the configuration. It will be a surprise to nobody that you are experiencing problems with that disparity between node versions.
  • HA and CARP for the DMZ

    2
    0 Votes
    2 Posts
    561 Views
    dotdashD
    Think of the DMZ as another LAN segment. It will need a CARP VIP to float between the firewalls. The Public IPs you are using for 1-1 NAT will just be CARP VIPs off the WAN.
  • Preventing UCARP from taking over on boot

    4
    0 Votes
    4 Posts
    851 Views
    DerelictD
    In all honesty, I would go to 2.2.6 first. It is much more tolerant of being installed with the WAN disconnected. After you can do it in Maintenance mode with the WAN connected the other upgrades will go a lot smoother.
  • HA works, but can't connect to Backup node

    2
    0 Votes
    2 Posts
    504 Views
    J
    So, I may have solved my own problem. I created a new CSR and created a cert with an Alternate name, so that the cert would work for both nodes. It seems to work. I'll report any oddities. John
  • Panic pfsense_undefer_state unable to find state

    3
    0 Votes
    3 Posts
    608 Views
    artooroA
    Thanks for pointing me to that bug.
  • XMLRPC Error message

    1
    0 Votes
    1 Posts
    635 Views
    No one has replied
  • HA interface assignment best practices

    2
    0 Votes
    2 Posts
    539 Views
    DerelictD
    You can certainly use LACP and VLANs to do LAN and WAN in the lab. Many people (me included) do not like mixing inside and outside traffic on one switch/stack. Many people (me included) do it anyway. I have not seen a recent, credible case of VLAN hopping with the exception maybe of TP-Link's VLAN1 nonsense. Even less of a reason to be concerned in the lab. But in your case, I would probably do a lag for the outside and a lag for the inside, with two interfaces each even if they are to the same stack, and one of the add-on ports for SYNC.
  • Virtual IP not reachable.

    1
    0 Votes
    1 Posts
    503 Views
    No one has replied
  • CARP sync failure

    7
    0 Votes
    7 Posts
    1k Views
    DerelictD
    Glad it's working. Status > Interfaces is probably the best tool to use for this since it lists all of the interface elements in play in order in one place.
  • Can't access backup unit when primary unit is active

    1
    0 Votes
    1 Posts
    365 Views
    No one has replied
  • Undocumented protocol change in pfsync ?

    2
    0 Votes
    2 Posts
    534 Views
    jimpJ
    Any time there is an upgrade, especially across operating system versions, there is always a possibility that will happen. It doesn't always affect everyone, but you can never rely on pfsync working during a significant OS update.
  • High Availability fail-over combined with IPv6

    2
    0 Votes
    2 Posts
    1k Views
    M
    Ok, I found out the following: The described problem only occurs to VM's hosted our 2 ESX 6.5 hypervisors. All bare metal servers will work completely fine (on-link and directly connected), only VM's are affected. On Vmware the vSwitches are configured including the following settings: Promiscuous mode enabled; MAC Address changes enabled; Forged transmits enabled; However, I don't think this is strictly needed since the firewalls are physical devices. Is someone aware of a required setting that is required in VMware / pfSense to get this correctly working? Thanks anyway :)
  • CARP Failover on OVH : no Promiscuous allowed… what alternative

    14
    0 Votes
    14 Posts
    8k Views
    C
    Got an answer from OVH that CARP is not possible for their hardware dedicated servers due to network design. I've solved this using OVH Control Panel API - https://api.ovh.com buy some OVH failover IP's (one or subnet block ) and assign them to "master" firewall in OVH Control Panel create identical "IP alias(es)" for OVH failover IP's attached to WAN interfaces on both "master" and "backup" firewalls.     Yes, create identical IP Aliases - no IP conflict will ever happen. wrote a Python script that moves above OVH failover IP's to "backup" server in case "master" firewall stops responding for let's say 10 seconds     Script can work on backup server on any other Linux/Windows server anywhere. Works just fine - API failover IP move takes about 50-55 seconds to finish. So, if scripts timeout for your "master" firewall is set to 10 seconds - you are looking at max 60-65 seconds outage for your services. Boom.
  • CARP on OVH dedicated cloud

    4
    0 Votes
    4 Posts
    2k Views
    C
    Got an answer from OVH that CARP is not possible for their hardware dedicated servers due to network design. I've solved this using OVH Control Panel API - https://api.ovh.com buy some OVH failover IP's (one or subnet block ) and assign them to "master" firewall in OVH Control Panel create identical "IP alias(es)" for OVH failover IP's attached to WAN interfaces on both "master" and "backup" firewalls.     Yes, create identical IP Aliases - no IP conflict will ever happen. wrote a Python script that moves above OVH failover IP's to "backup" server in case "master" firewall stops responding for let's say 10 seconds     Script can work on backup server on any other Linux/Windows server anywhere. Works just fine - API failover IP move takes about 50-55 seconds to finish. So, if scripts timeout for your "master" firewall is set to 10 seconds - you are looking at max 60-65 seconds outage for your services. Boom.
  • Can I use different hard drives on Primary / Slaves?

    2
    0 Votes
    2 Posts
    464 Views
    dotdashD
    No, the drives don't have to match. But you really ought to get on a somewhat recent version…
  • Adding New VIP’s Causes CARP to Flap before Clicking Apply Changes

    1
    1 Votes
    1 Posts
    433 Views
    No one has replied
  • Virtual IP GRE (Resolved in Replies)

    2
    0 Votes
    2 Posts
    625 Views
    SoarinS
    Solved! Everything else was correct except the NAT Outbound, now all the servers read the correct IP and are back on the server list. [image: 7wAuUge.png]
  • Multiple Carp Clusters - Conflicting

    1
    0 Votes
    1 Posts
    568 Views
    No one has replied
  • Only master gets software updates

    5
    0 Votes
    5 Posts
    914 Views
    J
    Thank you for your answers. Everything worked using viragomann rule, in source I used "This firewall" instead of 127.0.0.0/8 and it worked anyway.
  • Using public ips for devices behind pfsense

    2
    0 Votes
    2 Posts
    612 Views
    NogBadTheBadN
    Give the servers a private address and do a 1:1 NAT ? https://doc.pfsense.org/index.php/1:1_NAT Firewall -> NAT -> 1:1
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.