Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple VLANs in HA config

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    vlanhigh availabili
    10 Posts 4 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nick.loenders
      last edited by nick.loenders

      Re: Adding VLANs in HA Config
      As in this previous post ( /topic/166871/adding-vlans-in-ha-config )
      I also have 1 WAN, 1 LAN cable connected to a switch. But I have a LAN, VLAN2, VLAN3, and VLAN4. On the master Netgate it is all ok, but the VLANs are not synced to the 2nd Netgate.

      I read something about adding a VIP for each VLAN, but I tried this and it did not help.
      Can anyone help me out here?

      I also am working from a remote location now and I can access Netgate-1 (master-firewall) to change things, but I am unable to access Netgate-2 to check if all is synced ok??

      S dotdashD 2 Replies Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @nick.loenders
        last edited by

        @nick-loenders said in Multiple VLANs in HA config:

        working from a remote location now and I can access Netgate-1 (master-firewall) to change things, but I am unable to access Netgate-2

        I can help with this part. We have set up a NAT forward from our office IP on the -1 router to redirect a port to -2's LAN IP:443.

        Note if you use a hostname it may warn of a rebinding attack. See System/Admin/Alternate Hostnames.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        N 1 Reply Last reply Reply Quote 0
        • dotdashD
          dotdash @nick.loenders
          last edited by

          @nick-loenders
          You treat a vlan interface like any other interface. Keep the OPTx and name consistent on both systems. You put an ip on the primary and on the seconday, and then add the vips. Make sure the switch ports are configured to carry the vlan.

          N 1 Reply Last reply Reply Quote 0
          • N
            nick.loenders @dotdash
            last edited by nick.loenders

            @dotdash Hi, the VLANs work fine, but they don't get synced to the second firewall.
            I have this now:

            979715c2-ac26-4ead-93da-ee1546ea1827-image.png

            ebe896ed-2cf4-48dc-b0c5-524a6daf2a5e-image.png

            69498cef-fb28-4612-843f-6f997ce43dae-image.png

            bffbba0f-5438-4734-82c8-58adeec7caf6-image.png

            01f015c6-664f-49b8-b1a7-1195a65338d9-image.png

            3a1a036e-338b-4e94-a3e6-c73ba395f3d0-image.png

            But if I look on FW1 I see this:

            de5c17c1-503c-4099-9b7a-52340e067717-image.png

            But if I look on FW2 I only see this:

            4152a69e-6c7c-40fe-b13e-385651db0510-image.png

            So where should I add/change what, so it does sync to the FW2 ?

            1 Reply Last reply Reply Quote 0
            • N
              nick.loenders @SteveITS
              last edited by

              @steveits I added a NAT rule:

              c7d6643d-9c73-4fdb-b875-0bbb7cff458d-image.png

              and a rule:
              8bbdea97-80bd-4239-8d2d-8003311fca3c-image.png

              But it does not help?

              N V 2 Replies Last reply Reply Quote 0
              • N
                nick.loenders @nick.loenders
                last edited by

                Anyone?

                1 Reply Last reply Reply Quote 0
                • V
                  viragomann @nick.loenders
                  last edited by

                  @nick-loenders
                  The suggested outbound NAT rule has to be added to the LAN.
                  It's meant to access the secondary node via VPN. It is described in the docs here: Troubleshooting VPN Connectivity to a High Availability Secondary Node

                  Regarding the VLANs:
                  This behaves as regular interfaces. Means, you have to configure the VLAN on both nodes and assign different IP addresses to each.
                  Then on the primary go to Firewall > Virtual IPs and add a CARP VIP to each of the VLANs.

                  1 Reply Last reply Reply Quote 1
                  • N
                    nick.loenders
                    last edited by nick.loenders

                    @viragomann That document says nothing.

                    But I managed to get that to work.

                    for the VLANs, I created the VLANs manually on the FW2, and that seems to do the trick...
                    Stupid it does not sync them and all we need to add is a VIP.

                    But I still do have 1 fault , the VLAN4 is now primary on both devices ?

                    c3bd64a9-3c87-49c5-9b22-715663e94c32-image.png

                    V 1 Reply Last reply Reply Quote 0
                    • V
                      viragomann @nick.loenders
                      last edited by

                      @nick-loenders said in Multiple VLANs in HA config:

                      That document says nothing.

                      The document descripes what its title implies and is the solution to your additional question in your first post.

                      But I still do have 1 fault , the VLAN4 is now primary on both devices ?

                      This indicates that the involved interfaces of both nodes are not able to communicate. If the secondary does not get advertisements from the master on this VLAN, it switch over to master.
                      So ensure the VLAN is also properly configured on the switch.

                      N 1 Reply Last reply Reply Quote 1
                      • N
                        nick.loenders @viragomann
                        last edited by

                        @viragomann said in Multiple VLANs in HA config:

                        So ensure the VLAN is also properly configured on the switch.

                        omg , so stupid :)

                        Thx it all works now

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.