• Carp State takeover with cisco layer3 stacked switches

    1
    0 Votes
    1 Posts
    834 Views
    No one has replied
  • CARP using VPN IPsec

    9
    0 Votes
    9 Posts
    3k Views
    dotdashD
    I leave it enabled at defaults. It shouldn't need DPD to fail to the second node- the secondary should take over the existing IPSec connections.
  • Pfi_table_update: cannot set xx new ip addresses into table self: 22

    5
    0 Votes
    5 Posts
    1k Views
    C
    This issue was fixed in 2.2.3.
  • CARP + Stacked IP Aliases causing CARP conflicts on 2.2.2-RELEASE

    2
    0 Votes
    2 Posts
    790 Views
    V
    One more thing I've noticed - the behaviour seems to be the same when adding new CARP VIPs. When you click save to add a VIP, it is immediately synced and applied to the secondary node, and only gets applied on the primary after clicking 'apply'. It's not so much of a problem in that case of course, because it's a new VIP, and doesn't matter if it's MASTER on the secondary initially.
  • CARP Cluster - LACP - VLAN

    2
    0 Votes
    2 Posts
    1k Views
    I
    Ok,…Interface Order was different on the two nodes, so the Virtual IP Synchronization was incorrect, and so it didn't work at all,...same order on both nodes, everything fine.
  • Pfsync not syncing states to backup (2.2.2)

    17
    0 Votes
    17 Posts
    7k Views
    P
    Just Confirmation. I did the work around and the LAGG setup is working as intended.
  • 0 Votes
    3 Posts
    1k Views
    jimpJ
    There's already a patch for this in 2.2.3.
  • 2.2.2 Crash after enabling Syncronize States option

    5
    0 Votes
    5 Posts
    1k Views
    A
    I have had a similar issue, seemingly out of nowhere, with my master that was running 2.2 and my slave at 2.2.2 for a couple weeks (until Sunday afternoon).  Master affected with very slow performance, both throughput and it's own web interface.  I do not use any limiters, but I do use BGP.  I will also downgrade to 2.1.5.
  • PfSense 2.2.2 CARP-Backup becomes Master

    3
    0 Votes
    3 Posts
    2k Views
    M
    Figured out my issue. port security was enabled and set to restrict on the switchport that the LAN interfaces were connected to and I could see in the switch logs that it was getting tripped. Disabled port security now all is well.
  • High network latency between firewall and Dell clients

    2
    0 Votes
    2 Posts
    1k Views
    R
    Hello, Did you find something ? I have a similar configuration and have same troubles. It's quite temporary on my side but sometimes the ping between two systems in two different vlans can go from 0.200ms to 5/15 ms without any reason. Thank you
  • Using port other than 443 for webconfig

    2
    0 Votes
    2 Posts
    738 Views
    DerelictD
    Change the port on both primary and secondary.  That setting isn't synced.
  • What CARP interface name I must use for OpenBGP "Depend on" parameter? v2.2

    22
    0 Votes
    22 Posts
    6k Views
    G
    thank you jimp I already switch to new 2.2.2 with this patch I made a short test but when I switch back to master, bgp remains in ACTIVE for 2 sessions from a total of 4 I wil make more tests on this weekend P.S: attached my old 2.0.2 uptime  8) ![pfsense master.PNG](/public/imported_attachments/1/pfsense master.PNG) ![pfsense master.PNG_thumb](/public/imported_attachments/1/pfsense master.PNG_thumb)
  • Crash / BUG with CARP

    2
    0 Votes
    2 Posts
    932 Views
    jimpJ
    We've seen that before but not lately. What version of pfSense is on both units? And do you have Captive Portal + voucher sync enabled on that cluster?
  • Unable to delete VIP

    7
    0 Votes
    7 Posts
    2k Views
    S
    @jme: That is what i did too. @Jimp: i didn't verified, i'll check this next time and give you the log related to this action
  • Failover with 2 Pfsese boxex

    8
    0 Votes
    8 Posts
    2k Views
    KOMK
    Sorry, you've hit the limit of my knowledge on this subject.  Yes, I believe that the shared WAN IP is a Virtual IP.
  • Confused about what type of Virtual IP to use

    7
    0 Votes
    7 Posts
    2k Views
    C
    IP alias is fine. Some modems aren't happy with just proxy ARP, which sounds like the case for you.
  • CARP with 2 pfsenses boxes and WANFailover - HELP ;) !

    3
    0 Votes
    3 Posts
    1k Views
    F
    Hello Dotdash, Thanks for your reply. My diagram was not complete, I already had the VIP setup for all interfaces. It's working since this morning. I'm not exactly sure what was wrong. I've setup the DHCP servers as I've already done a few times without success, but this time it worked. I let a few days go by before making my final attempt. I red the chapter about configuring CARP (especially the DHCP part) before proceeding. Maybe I needed the break. Anyway, this issue is solved. Thanks !
  • Firewall rules disappear with asymetric NICS

    6
    0 Votes
    6 Posts
    2k Views
    B
    Viragomann put me on the right track, though there was a catch.  The original problem was that I wanted to perform CARP firewall rules synchronization between a master and a backup, but the backup had an extra interface (a wireless access point) the master didn't have.  Consequently, the rules for the extra interface were been deleted whenever the rules synchronized.  Viragomann suggested creating a dummy interface on the master for a non-existent VLAN, giving it the same name as the wireless interface on the backup firewall, and putting the rules there.  The basic idea was good, but with a problem. The problem comes in the way that the interfaces are named.  When I created the dummy VLAN on the master, pfSense named it "OPT5".  I then renamed it to "wireless" to match the interface name on the backup.  It seems that renaming OPT5 to "wireless" is a cosmetic change only.  Internally pfSense still calls it "OPT5", and all the rules are associated with "OPT5".  When CARP performs the firewall synchronization, it copied all those wireless rules to the backup firewalls "OPT5", which was some other VLAN.  On the backup, pfSense knows the wireless interface as "OPT4".  I had to delete everything on the master firewall associated with OPT4 and above, and recreate them in the right order so that their internal "OPT" names aligned with the ones on the backup firewall.  Once I did that, synchronization worked great. Thanks, Viragomann, for putting me on the right path.
  • Internal Firewall traffic issues after CARP Failover

    4
    0 Votes
    4 Posts
    1k Views
    D
    I appreciate the honesty and I totally see your point.
  • DeCARP

    3
    0 Votes
    3 Posts
    984 Views
    jimpJ
    To switch from CARP back to a stand-alone unit you can remove the sync settings from System > High Avail Sync and from the DHCP server tabs. CARP VIPs and NAT can be left as-is.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.