• HA proxy port 80 in use after upgrade to 23.09.1

    2
    0 Votes
    2 Posts
    1k Views
    I

    @ironwood Ok, I found the solution, or rather, ChatGPT found the solution. Under System > Advanced > Admin Access, there is a setting called WebGUI Login Redirect. This is the description:

    When this is unchecked, access to the webConfigurator is always permitted even on port 80, regardless of the listening port configured. Check this box to disable this automatically added redirect rule.

    The redirect is enabled for port 80 by default and was conflicting with the http to https redirect I had set up in HAproxy a long time ago. I check the box to disable it, saved, enabled my redirect and voila, it works!

    I'm guessing this was either a new feature in 23.09.1 or it I had it checked before and it "unchecked" itself? Would be interested in finding if that setting exists in earlier versions if anyone hasn't upgraded.

  • CARP Mode Multicast / Unicast ?

    3
    0 Votes
    3 Posts
    1k Views
    Y

    @kiokoman said in CARP Mode Multicast / Unicast ?:

    @Yathus
    indeed, if you can't use multicast., peer address is the second node for primary pfsense and vice versa for secondary pfsense
    forget about PFSYNC interface it is used only for configuration synchronization and pfsync state synchronization

    I made a test, i create a "Virtual IP" on primary pfsense and i put IP from secondary on "peer IP" and it's working. I create only on the primary node, nothing on second node, Sync did the job.

  • HAProxy issue after update Pfsense from 2.7.0 to 2.7.1

    2
    1 Votes
    2 Posts
    697 Views
    M

    Does nobody know or have any ideas? I am really stuck on this.

  • HA Firewall rules keep disappearing

    3
    0 Votes
    3 Posts
    491 Views
    P

    @SteveITS And that is what is strange...the rules on the primary firewall are there...and for that matter ALL the rules for all the interfaces are there and not overwritten or deleted...just the HA ones. And I don't change any of the rules on the prmary as it relates to HA.

  • carp adress not avaible from lan/wan1/wan2

    5
    0 Votes
    5 Posts
    635 Views
    M

    @SteveITS the carp began to work after entering the second gateway in first High Availability option

    thanks!)

  • ICMP Fragmentation Needed sent from real IP instead of VIP

    2
    0 Votes
    2 Posts
    413 Views
    No one has replied
  • DHCP Issues

    12
    0 Votes
    12 Posts
    868 Views
    V

    @Daniel_Hyde
    Yes, as the hint there is mentioning.
    This setting needs only to be made on the primary.

  • Using HAproxy on a CARP/HA firewall cluster

    14
    0 Votes
    14 Posts
    2k Views
    P

    @viragomann ,

    Observed something weird where if i turn off state synchronisation in System>> High availability. Application is working. Any suggestions for this weird behaviour??

  • Disabling a VIP temporarily?

    1
    0 Votes
    1 Posts
    312 Views
    No one has replied
  • CARP/HA in GCP

    1
    0 Votes
    1 Posts
    369 Views
    No one has replied
  • Redundant carp mesh best practices

    1
    0 Votes
    1 Posts
    270 Views
    No one has replied
  • Why does my HA VLANs show so much traffic on the graph?

    1
    0 Votes
    1 Posts
    276 Views
    No one has replied
  • Single node to HA cluster -> Config migration

    5
    0 Votes
    5 Posts
    757 Views
    B

    @SteveITS Thank you!
    Unfortunately there does not seem to be a backup option for users and/or certificates only. So looks like i'm going to have to copy those sections of config over manually.

  • Sync not working

    9
    0 Votes
    9 Posts
    1k Views
    S

    @jeffsmith82 said in Sync not working:

    used to force you to use the admin account until a relativity recent version

    Oh, good to know, thanks.

  • Potential DNS Rebind attack detected and Web UI Certificates

    2
    0 Votes
    2 Posts
    438 Views
    johnpozJ

    @Kajetan321 the vip just points to one of them, whoever is the master. So yeah to it the name is not correct.

    What you would want to setup is alternative name..

    systemadv.jpg

    so if you pfsense1.home.arpa, and pfsense2.home.arpa on the 2 boxes. Here for the vip name you would want pfsense.home.arpa

    This is located under system / advanced / admin access

  • HA on two different types of hardware

    9
    0 Votes
    9 Posts
    3k Views
    A

    @SteveITS Thank you very much. I appreciate immensely your input. It clarified my misunderstanding.

  • Custom CARP failover script

    5
    0 Votes
    5 Posts
    1k Views
    C

    @jimp , thanks for the directions.

  • WAN CARP IP stops responding - requires cable modem reboot

    4
    0 Votes
    4 Posts
    547 Views
    D

    @mi8088 The firewall was sending traffic out, but the cable modem was dropping it.

    There's really only two fixes I can see:

    The cable modems need to change their behavior to accommodate changes in MAC addresses. pfSense's CARP IP and all associated traffic needs to use the same MAC address that doesn't change when failing over.

    I ended up disabling CARP on the WAN IP and haven't had any issues with the connection going down since.

  • Pfsense Authentication on second device from HA

    6
    0 Votes
    6 Posts
    729 Views
    M

    @SteveITS Solved the issue.

    After reboot works on both devices.
    Thanks a lot for your support!

  • 0 Votes
    4 Posts
    668 Views
    V

    @mi8088 said in No traffic on a WAN CARP IP from outside, working internally and for Virtual IP:

    Do you mean this behaviour?

    The behavior of not allowing MAC changes on the router in front of pfSense.
    I don't know any device, which doesn't let you change this.

    I don't know if we can get the CPE configured somehow, our provider is claiming they can't do anything with it.

    This is required for CARP, however.

    Is there a way to get around it with an extra switch? (Which of course introduces another point of failure...)

    Not with an L2 device. You can put an L3 switch (router) in between and nat the traffic to pfSense as its best.

    However, pfSense send the response packet back from the hardware MAC, not the virtual.

    Can I change this somehow?

    No, pfSense will use the interface MAC, when responding. You can spoof this MAC though, but you cannot spoof the CARP vMAC, and both must be different naturally.
    So the only option to make CARP work is to allow this on the connected devices.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.