• High Avail. Sync Doesn't Work - version 2.3.3 and 2.3.3-p1

    6
    0 Votes
    6 Posts
    1k Views
    DerelictD
    An IP Alias VIP will not sync unless it is riding on a CARP VIP because the same IP Alias active on both nodes at the same time will create an IP address conflict.
  • [CLOSED] CARP IP as 1:1 NAT

    8
    0 Votes
    8 Posts
    1k Views
    N
    I finally found it ! It's a bit weird though.. It turns out that on both master/slave,  of Shaper's –> System -> Routing - Gateways list, I still have the bastion firewall's IP when it was still a standalone pfsense, but it's already in DISABLED state ! and i have the new Bastion Firewall's Floating IP as HA enabled. Pure luck ? I was out of idea then just delete the hell out of that old ( and disabled ) IP... voila ! Thank you so much for you patience !!
  • Pfsync_undefer_state: unable to find deferred state

    2
    0 Votes
    2 Posts
    789 Views
    E
    I think I found this bug on the roadmap for version 2.4 (https://redmine.pfsense.org/issues/4310)
  • Can't resolve usind pfsense DNS in CARP

    5
    0 Votes
    5 Posts
    3k Views
    J
    Solved by changing firewall rule from allowing dns to " lan address", to allowing dns to "lan net". Don't want to use "This Firewall" as I don't want to allow traffic to other interfaces.
  • Carp and Openvpn (SLAVE)

    4
    0 Votes
    4 Posts
    1k Views
    M
    +1
  • Ovh Dedicated Server + multiple ip on same network card

    3
    0 Votes
    3 Posts
    2k Views
    L
    Hi I have find the problem I contact the ovh support. when I configure the ip on ovh manager I have a mac adress define for this ip (before I use this ip for a virtual machine) . and if and mac adress is define I can't use it to connect directly from a physical server. when I delete the mac adress I can ping it with no problem  :) Lolo
  • CARP done right with VLANS?

    4
    0 Votes
    4 Posts
    2k Views
    DerelictD
    SYNC has nothing to do with VIPs either. You could use a VLAN interface as a pfsync/xmlrpc sync interface. Not sure you should, but you could. It won't care either. Just has to be tagged through the switch properly to both nodes. On a busy site you do not want pfsync to get backlogged. A rule of thumb is pfsync requires about 10% of the bandwidth represented by the states that are being synced. Why not just use a dedicated interface? If it's worth HA it's worth doing right. But i can only get the sync from a VLAN to work on the same interface as the vlan. No idea what you're saying here either.
  • CARP sync renders both DHCPs enabled

    8
    0 Votes
    8 Posts
    3k Views
    I
    To get rid of that split error, just get rid of that line in the Secondary config file. It works for me ;D ;)
  • Can't add additional subnet to LAN - 2.3.3-RELEASE-p1 (amd64)

    4
    0 Votes
    4 Posts
    1k Views
    johnpozJ
    "Needed to add a second subnet to the LAN" As a vlan??  Or you wanting to run multiple layer 3 on the same layer 2??  If so that is BORKED - rethink what your doing.  And when you come up with vlans as your answer to running multiple networks on the same physical interface you have gotten to the correct answer ;)
  • 2.3.3-RELEASE-p1IPv6 CARP issue (dual master)

    1
    0 Votes
    1 Posts
    595 Views
    No one has replied
  • MLPPP and CARP possible?

    2
    0 Votes
    2 Posts
    668 Views
    A
    I too would like to know the answer to this.  I also have a similar MLPPP configuration and would like to know if CARP Failover will work.
  • Virtual ip visibility from provider

    4
    0 Votes
    4 Posts
    908 Views
    K
    Now it is working. I've had to choose for the OpenVPN server the CARP VIP as an interface. Thank you!
  • HA Wan with 802.1q tagged virtual interface

    1
    0 Votes
    1 Posts
    505 Views
    No one has replied
  • CARP + CenturyLink Enterprise Fiber

    2
    0 Votes
    2 Posts
    772 Views
    S
    Hmm, ping and RDP started working when I checked the "Default gateway" box on the Fiber Link. Not sure I understand why that is….
  • Unable to ping tier 2 CARP VIP in dual WAN [RESOLVED]

    3
    0 Votes
    3 Posts
    740 Views
    B
    Thanks, that fixed the issue.
  • Can't sync between 2.3.2-p1 and 2.3.3 ??

    2
    0 Votes
    2 Posts
    884 Views
    jimpJ
    It's disabled when the configuration format is different between them, as marked by the "<version>XX.Y</version>" in config.xml If the configuration version is different, they cannot sync because it could push incorrect data. That said, synchronizing between different versions has never been officially supported, nor recommended. It may have worked by chance before, but we never recommend running different versions for any measurable amount of time. Just long enough to make sure the updated node is functional/tested, which shouldn't involve any configuration changes.
  • Carp with single wan ip

    4
    0 Votes
    4 Posts
    5k Views
    DerelictD
    Any blog post or diagram should tell you to get a /29. That is how it is done. Anything worth HA is worth doing right, IMHO. And you cannot use Automatic outbound NAT with CARP/HA. It must be manual to the CARP VIP is used there.
  • GRE from CARP VIP and IPSec

    1
    0 Votes
    1 Posts
    555 Views
    No one has replied
  • Change CARP IGMPv3 > v2 ?

    2
    0 Votes
    2 Posts
    1k Views
    R
    Try these: net.inet.igmp.default_version=2 net.inet.igmp.sendra=0 net.inet.igmp.legacysup=1
  • States not synced between VMs

    3
    0 Votes
    3 Posts
    963 Views
    T
    I have resolved the issue, it appears I was hitting a change in pfsync as of pfsense 2.2 as shown here https://forum.pfsense.org/index.php?topic=93052.0 https://forum.pfsense.org/index.php?topic=93132.msg519077#msg519077 Since I was using VMXNET3 interfaces in ESXi and VirtIO interfaces in Proxmox they show up as different hardware since they have different drivers and pfsync cannot function properly.  The work around in the previous threads was to create a LAGG but the simpler solution in this case was to change Proxmox to use VMXNET3 interfaces and my states are synced perfectly now.  Changing both VMs to use E1000 interfaces likely would have worked too.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.