• HA Sync with different username

    2
    0 Votes
    2 Posts
    926 Views
    V
    Hi craCH, @craCH: Isn't it possible to use an different user for that? Correct, it's not possible to use a different user with HA-Sync. You need to use the admin user.
  • Best practice for multiple VIPs on interface

    5
    0 Votes
    5 Posts
    1k Views
    JeGrJ
    @vira A now I see :) A pity then. Thought you had something I was missing for a second. But as all networks are routed to our transfer ip, I don't have to use separate gateways for them.
  • Assigning External IP Addresses to Subnets behind pfSense Box

    8
    0 Votes
    8 Posts
    5k Views
    C
    EScottH, Are you performing 1:1NAT for ALL ports?
  • 0 Votes
    3 Posts
    1k Views
    C
    When you update the Master Password - it is synchronized to the slave, but it does not update the "password" field on the password under 'Configuration Synchronization Settings (XMLRPC Sync)'.  You have to manually update this.
  • 61st ip.

    15
    0 Votes
    15 Posts
    3k Views
    C
    @cmb: @cthomas: I just cut-over to a pair of firewalls that had 24+ CARP VIPs on the WAN - as soon as the secondary fw would boot, the primary would crash, and then continue to crash after each boot as long as the secondary fw was online.  Made for a rough 24 hours. Wow, never seen or heard of that happening. You should start a thread on that if you haven't already (I couldn't find one in your post history). I suspect some kind of weird NIC or other driver bug that's specific to some very unusual edge case on your combination of hardware. cmb - I submitted a ton of crash reports - pm me for hostname details
  • CARP and DHCP server

    6
    0 Votes
    6 Posts
    2k Views
    T
    Thank you very much for your help. Log told me some ideas. In my case, interface assignment on both devices was slightly different. After I reassigned them, it began to work. Thanks again!
  • Two NICs with CARP on the same switch/VLAN

    3
    0 Votes
    3 Posts
    2k Views
    S
    Hi Francesco and All, i'm exactly in the same situation, but with a physical server with two physical NICs Two NICs with CARP on the same switch/VLAN (WAN side) My ISP provide me 2 public IP subnets in the same cable. This cable is pluggel in my cisco switch in a port configured in access mode with VLAN X Other two ports on the same cisco switch are configured in access mode on the same VLAN X. In these two ports are connected two PFS WAN NICs with this configuration: WAN (wan)      -> em1        -> v4: a.a.a.a/27 WAN2 (opt9)    -> em3        -> v4: b.b.b.b/27 My filter.log is flooded by these messages: rule 38/0(match): block in on em3: (tos 0x0, ttl 255, id 37753, offset 0, flags [DF], proto VRRP (112), length 56)     a.a.a.a > 224.0.0.18: VRRPv2, Advertisement, vrid 108, prio 0, authtype none, intvl 1s, length 36, addrs(7): 77.110.34.171,61.17.65.165,90.166.164.7,254.92.249.181,89.34.91.45,24.56.193.51,49.113.148.220 00:00:00.001830 rule 38/0(match): block in on em3: (tos 0x0, ttl 255, id 64989, offset 0, flags [DF], proto VRRP (112), length 56) and rule 38/0(match): block in on em1: (tos 0x0, ttl 255, id 15937, offset 0, flags [DF], proto VRRP (112), length 56)     b.b.b.b > 224.0.0.18: VRRPv2, Advertisement, vrid 226, prio 0, authtype none, intvl 1s, length 36, addrs(7): 189.142.72.18,82.162.93.207,80.97.204.246,226.201.105.180,72.151.119.172,252.49.36.205,219.112.155.93 00:00:00.178021 rule 38/0(match): block in on em1: (tos 0x0, ttl 255, id 46149, offset 0, flags [DF], proto VRRP (112), length 56) I already checked: VIPs configuration ( all netmask OK, Base 1 and Skew 0 for all VIPs, VHID Group # dedicated for each VIP, same pwd) netmask in WAN and WAN2 conf; Is there a way to solve this? Or a way to hide these messages if they are not a serious network issue? Note: I have another couple of PFS firewall in the same switch and in the same VLAN X and a third public IP subnet (c.c.c.c) , but i don't see VRRP/CARP message in filter.log. With a tcpdump on wan interface I can see VRRP messsage but this is right. pfs 2.1-RELEASE (i386) Thank you and best regards Simone
  • PfSense failover with DHCP on WAN side .. feature in the future … ?

    4
    0 Votes
    4 Posts
    2k Views
    jimpJ
    In that situation the secondary would only process traffic if it is the carp master, not when it is the carp backup. If the primary fails, it would still pass traffic as expected, but when the primary is up it would have no external connectivity.
  • CARP VIP dropping packets

    3
    0 Votes
    3 Posts
    1k Views
    dotdashD
    Check the logs. A packet capture will show if something is using CARP/VRRP on the wire and what VHIDs are in use. It seems unlikely that you would see VRRP traffic on the LAN unless you are not in control of the LAN side of your network.
  • CARP 2.1.2 suddenly stops working(all client can access the internet)

    2
    0 Votes
    2 Posts
    875 Views
    M
    this is ok now, it happens that one mac address is causing that trouble when it was deleted everything works fine
  • VIP not working in 2.1.2 do in 2.1.0

    1
    0 Votes
    1 Posts
    800 Views
    No one has replied
  • Access to pfSense via VIP

    4
    0 Votes
    4 Posts
    2k Views
    T
    xxx.xxx.xxx.121 and 122 were accessible. After I modified the firewall rule (WAN address to WAN net), it began to work! Thank you very much!
  • Ok what am I missing?

    9
    0 Votes
    9 Posts
    3k Views
    M
    I think you're right, I was messing with promiscuous mode on virtualbox nics and everything started working some what  fine but still wasn't working as intended. What I wanted to do was set this up on my server which is running a virtual instance of pfsense for my network at home, lately my server has been having issues and I kept breaking stuff and the internet goes down for few hours; and it becomes difficult to fix things when you don't have the resources of the internet and have to rely on a mobile data plan from your phone. But anyways what I wanted to do was, I had a physical box which use to be my old pfsense router burning 80watts 24/7 which is why I went to virtual setup. Anyways I wanted to CARP to this box so I can take down the server for maintenance and still have internet and not interrupt anybody in the home, who may be playing video games, watching netflix so on. The server runs CentOS 6.5 with KVM, and pfsense utilizes virtio drivers. I can't find anything for promiscuous mode settings for KVM, even though a web search suggest to acknowledge that a promiscuous mode setting does exist. I just have no idea how yet, although I haven't dug deep into it yet.
  • Spontaneous Failover?

    19
    0 Votes
    19 Posts
    6k Views
    J
    You can probably swap out the cables without anyone noticing.  Do the backup box first, then disable CARP on the primary and change those too. If your NICs are all built in then I'd probably go to the switch next.  You may just have to declare a maintenance window on that one.
  • WAN2 to WAN1 failover not working

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Editing interface assigment causes VIP to stop responding…

    3
    0 Votes
    3 Posts
    1k Views
    V
    Had same issue yesterday. I was connected via OpenVPN to pfSense. The OVPN server is bound on a WAN CARP VIP and my web GUI is reachable on LAN address only. I just hit the button to add an interface and the VPN was broken. No way to get access from remote again. That's a bad circumstance if the firewall is more than 20 km away and it's late at night!    :- My pfSense is 2.1.1 Does anybody know if this behaviour just aply to bounded services on CARP VIPs or will it be the same if I bind OVPN on an IP Alias?
  • Loadbalancing Lan for 2 pfsense servers.

    2
    0 Votes
    2 Posts
    964 Views
    C
    To the best of my knowledge, this is not a supported configuration. With that said….  you could try a crossed virtual ip configuration; however, without extensive testing, I'm not sure I would attempt to toss this into a production environment... On your LAN... FW1 = 192.168.0.3/24 FW2 = 192.168.0.4/24 CARPVIP1 = 192.168.0.1/24 (Active on FW1 - Skew FW1=0 / Skew FW2=100) CARPVIP2 = 192.168.0.2/24 (Active on FW2 - Skew FW1=100 / Skew FW2=0) Have DHCP on FW1 hand out .1 as Gateway, have FW2 hand out .2 as Gateway If either FW goes down, the VIP fails over to the other FW and responds for both gateway IP's..  You'll probably need to disable XMLRPC sync for the CARP VIPs and manually configure them. ...c
  • Do interface dev numbers need to match?

    3
    0 Votes
    3 Posts
    1k Views
    A
    Great.  Thanks!
  • Question about Carp with multiple external IPs

    4
    0 Votes
    4 Posts
    2k Views
    T
    Thanks for the replies. I have installed both firewalls now, and as I went through the configuration process, it all became clear. Thanks again. :)
  • Adding Virtual Interface on LAN

    2
    0 Votes
    2 Posts
    2k Views
    D
    0/ Is the switch managed/VLAN capable? If not, go to shop. 1/ Huh? Bridging and isolation in one sentence? 2/ Where's the wireless magic thing? Cannot see any. 3/ Turn OFF the firewall on whatever you are pinging. 4/ Look at the firewall logs 5/ If you still have problems, you need to post your interfaces setup, firewall rules etc.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.