• CARP with multi-wan [SOLVED]

    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    @chris4916: This computer (Anne) requests IP and get offers from the 2 DHCP servers, with different IP. I'm just wondering how this work  ;) Notice that some devices are receiving same IP from each DHCP server. That is normal. They will both offer since they are both active, but whichever lease the client accepts will be shared between the two systems. @chris4916: Problem was with FW rules for incoming flow on the WAN "group" interface. Having removed these rules and replaced with rules on each WAN1 & WAN2 interface fixed this issue with incoming flow. Great!
  • Failover VPN

    3
    0 Votes
    3 Posts
    911 Views
    C
    –keepalive directive?
  • CARP and transparent-mode

    1
    0 Votes
    1 Posts
    409 Views
    No one has replied
  • High Availability HA authentication failure

    10
    0 Votes
    10 Posts
    3k Views
    DerelictD
    Hmm. I have never done an HA pair with an LDAP-configured authentication backend for the webgui (which will also be xmlrpc sync.) Later versions (including 2.4.X) fixed the long-standing issue of being unable to specify the xmlrpc username and password. It might be worth creating a local user on the primary, which should sync to the secondary, that specifically includes the System - HA node sync permission then specifying that user on the primary in the XMLRPC settings. The secondary is the one that is controlling where things are authenticated. Are you certain the user being specified is present there? Does the XMLRPC sync user and password pass on the secondary in Diagnostics > Authentication? Is there any significant delay? Are the Authentication servers specified identical on the primary and the secondary? Do both nodes pass Diagnostics > Authentication? ![Screen Shot 2017-11-03 at 12.12.06 PM.png](/public/imported_attachments/1/Screen Shot 2017-11-03 at 12.12.06 PM.png) ![Screen Shot 2017-11-03 at 12.12.06 PM.png_thumb](/public/imported_attachments/1/Screen Shot 2017-11-03 at 12.12.06 PM.png_thumb)
  • CARP on AWS

    3
    0 Votes
    3 Posts
    2k Views
    DerelictD
    You can't do that. Their AWS network will not allow the multicast between nodes, addresses are tied to specific instances, etc.
  • How common are IP Aliases on WAN interfaces?

    5
    0 Votes
    5 Posts
    2k Views
    jimpJ
    @coreybrett: If I ever run into this again and want to use the CARP option, would I need to fill in the Virtual IP Password, VHID Group or Advertising frequency when using a single firewall? Yes, you still need to fill that in even if it's a single unit since they are all required parameters to configure CARP.
  • Problems with HA and CARP

    1
    0 Votes
    1 Posts
    566 Views
    No one has replied
  • CARP + OpenVPN - slave not reachable over VPN

    3
    1 Votes
    3 Posts
    1k Views
    P
    Ahh, after re-read, re-read and re-read i found the solution! With 'The VPN tunnel network' they mean the subnet from the 'remote side' of the VPN tunnel. After change it works :)
  • CARP failover causes default route on master to go missing

    2
    0 Votes
    2 Posts
    1k Views
    P
    Go to Firewall > NAT > Outbound: Make sure you have 'Manual (or Hybrid) Outbound NAT' and create an extra rule: WAN - This Firewall - * - * - * - (WAN CARP IP) - * Also i think you need to reboot so the apinger is refreshed.
  • Virtual IP on Subnets

    3
    0 Votes
    3 Posts
    804 Views
    S
    THX for your help, and thx for the hint with udp, i think this is the problem, since the needed UDP traffic is not forwarded within these subnets. From Cisco i remember to configure ip helper addresses, f.e. UDP: 32410, 32412, 32413, 32414. ip helper-address 192.168.1.187 ip forward-protocol udp 32410 etc… is there something similar on pfsense?
  • Disable CARP

    5
    0 Votes
    5 Posts
    2k Views
    DerelictD
    Do you have any other suggestions? Yes. Upgrade.
  • Client peer-to-peer tunnels between CARP'd pfsenses

    3
    0 Votes
    3 Posts
    813 Views
    T
    Thanks for that! I double checked, and OpenVPN is not selected to sync.
  • CARP Entire Network

    1
    0 Votes
    1 Posts
    457 Views
    No one has replied
  • CARP Network Allocation Problem

    9
    0 Votes
    9 Posts
    1k Views
    T
    @Derelict: It is those who are making you do this who don't understand. Yep. I guess i am not the only one.
  • CARP setup on load balancing network

    1
    0 Votes
    1 Posts
    515 Views
    No one has replied
  • NAT Trouble with CARP

    4
    0 Votes
    4 Posts
    938 Views
    DerelictD
    Hard to say. But if the only difference is the CARP address being used for NAT that is where I would look. ISPs do crazy things. Also, you want to move that static port 500 NAT rule above the rule since, if left like that, it will never be matched. Unrelated to your speed issue. Just sayin'.
  • CARP - NAT

    6
    0 Votes
    6 Posts
    2k Views
    DerelictD
    Then you are doing it wrong somehow.
  • Cant leave CARP maintenance mode

    3
    0 Votes
    3 Posts
    774 Views
    V
    @jimp: You may have some other problem causing the node to demote itself. What does the CARP status page look like on both units? Before leaving m.mode - old master shows all interfacess backup, backup shows all interfaces - master after leaving m.mode - vice versa. @jimp: Are there any interfaces enabled but in a 'down' state either on purpose or unintentionally? No. As I wrote upper - all interfaces is UP state and answer for icmp requests (ping - ok)
  • Strange ip addresses in multicast VRRP/CARP packets

    4
    0 Votes
    4 Posts
    1k Views
    DerelictD
    Yeah what kind of connection is this on? You will see any other CARP/VRRP on that broadcast/multicast domain. Strange to see such varying IP addresses but it depends on what you're connected to. You can set Wireshark to decode protocol 112 as CARP though. Those other multicasts might actually be VRRP though. They can coexist.
  • CARP on WAN with redundant uplinks

    6
    0 Votes
    6 Posts
    1k Views
    DerelictD
    Nothing different should apply. That is all dependent on your STP configuration but it would generally be safe to have portfast enabled I would think.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.