• PFSense router failover redundancy - CARP Virtual IP not Reachable

    3
    0 Votes
    3 Posts
    3k Views
    P
    Can you print out the ifconfig from em1 on pfsense box 2? If your provider is also using CARP or VRRP, you might need to reset the VHID to something else to avoid conflict. Is there anything in the logs to indicate a problem on either machine?
  • Configure CARP over vLans Trunk Port

    3
    0 Votes
    3 Posts
    2k Views
    DerelictD
    CARP doesn't care if it's a tagged VLAN or not.  You need good layer 2 between CARP member nodes. And, yes, if you want all the VLANs to be HA you need a CARP VIP and each member node has to have an interface IP. VLAN 10 192.168.1.1 CARP VIP 192.168.1.2 Master 192.168.1.3 Backup VLAN 11 192.168.2.1 CARP VIP 192.168.2.2 Master 192.168.2.3 Backup etc etc Naturally, you set DHCP to give the CARP VIP as the default gateway, DNS Server, etc for each segment as applicable.
  • SSL Certificate error after failover

    5
    0 Votes
    5 Posts
    2k Views
    P
    I appreciate your time.  It's been very helpful.
  • CARP gateway packet loss (but it works?)

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Outbound nat pool with carp

    3
    0 Votes
    3 Posts
    1k Views
    jimpJ
    It depends on how the IP addresses are routed to you. If you have a block of routed addresses and the upstream ISP is routing them to your WAN CARP VIP – nothing special, just add the subnet in outbound NAT If you have a set of VIPs to use instead, then make an alias of them (a host type alias) and then select that alias for use in outbound NAT.
  • CARP with two DHCP

    2
    0 Votes
    2 Posts
    1k Views
    awebsterA
    Have a look at this thread, I think it covers a way to do what you're asking for. https://forum.pfsense.org/index.php?topic=87546.0
  • CARP packet loss (Hyper-V deployment)

    5
    0 Votes
    5 Posts
    2k Views
    A
    Turns out I needed to reboot the firewalls… Im surprised that wasn't step #1. Thanks for your help!
  • PfSense redundancy with two different boxes using VLAN based interfaces

    1
    0 Votes
    1 Posts
    880 Views
    No one has replied
  • Pfsync not syncing states

    15
    0 Votes
    15 Posts
    5k Views
    J
    Thank you for the help guys! One of the instances is physical, the other is virtual. We were holding up moving to 100% virtualized because of this problem, but we're going to move forward since the interfaces will be named the same after the upgrade. Cheers!
  • BT Infinity, PPPoE, Static IPs, IPSEC VPN

    5
    1 Votes
    5 Posts
    4k Views
    D
    Thanks for this, I would have never figured it out. I've kind of got there with this, the problem I currently have is that outbound traffic is still going through the dynamic IP rather than one of the statics. could anyone advise me on how to make it use the static please.
  • Colocate / constrain CARP VIPs on different interfaces to same machine

    6
    0 Votes
    6 Posts
    1k Views
    P
    @podilarius: From my experience, if any interface with a CARP address goes down, the entire system switches over. That's CARP pre-empt at work, which is enabled by default in pfSense.
  • Two separate pfsense clusters on same layer 2 and subnet

    4
    0 Votes
    4 Posts
    1k Views
    awebsterA
    I have 3 clusters of pfSense running on a nework and they all co-exist well. You absolutely need to ensure that the VHID is different between each cluster set, and also that it does not overlap any other CARP or VRRP instances running on the same L2. If you are using IPv4 and IPv6, you also need different VHID for each protocol.
  • Carp w static ip

    15
    0 Votes
    15 Posts
    10k Views
    M
    I found it's IP problem. It works well when I use a real public ip rather than a private ip (I used for test). When I use a private ip as wan ip,it's not work,even though I unchecked "Block private networks" option. Thanks again!
  • Did i miss something?

    1
    0 Votes
    1 Posts
    719 Views
    No one has replied
  • Multi-wan with failover … how correctly setup with diffirent subnet

    1
    0 Votes
    1 Posts
    735 Views
    No one has replied
  • Pfsense High Availability Sync with Multi-WAN

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Force XMLRPC Sync???

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Rule and Configuration Synchronization not for CARP

    4
    0 Votes
    4 Posts
    1k Views
    C
    That's not an answer for what you're looking to accomplish. Can only sync the entirety of that portion of the config (which almost certainly won't be identical across everything), and can only do so to one other host. Some have hacked up their own solutions to accomplish parts of that, specific to their general config management usage. We'll have a solution for centralized management in the future.
  • LAGG/LACP Slow timeout

    3
    0 Votes
    3 Posts
    2k Views
    D
    @BlueKobold: I my testing I have come across and issue with the pfsense/bsd implementation of LACP. In front of the cluster or behind it, to the LAN or WAN side I mean? Do we talking about dynamic LAG over LACP and automatic set up or do we talking about static LAG manual set up? active/passive or active/active only dynamic lacp sends the fast/slow pdus, so must be dynamic.
  • MOVED: pfSense multiple WAN IP's - HTTPS issue

    Locked
    1
    0 Votes
    1 Posts
    566 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.