Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to ping tier 2 CARP VIP in dual WAN [RESOLVED]

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    3 Posts 2 Posters 740 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      barnettd
      last edited by

      Hi,
      I am using 2 SG-2440 units setup with HA, dual WAN, and CARP VIPs on WAN and LAN sides. Seems to be working correctly for the most part. A few problems with ipsec failover, but thats a different issue.

      The dual wan is configured with a single failover gateway group using 2 tiers and the appropriate VIPs. No load balancing is configured.

      I have added a floating rule to allow icmp echo requests to both wan interfaces (maybe this is part of the problem?)

      The issue is I am ALWAYS able to ping the VIP on the primary (tier 1) isp connection. To test, I "Mark Gateway as Down". After doing that I am able to establish a new ipsec tunnel using the VIP on the tier 2 connection. I have also tested by configuring a monitor IP where I can disable ping response and see the same rfesult.
      In both cases, I can still ping the tier 1 VIP, and I cannot ping the tier 2 VIP, even though it appears to be passing traffic.

      Am I doing somethign wrong?

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        Floating rules do not get "reply-to" so they can't return traffic out the interface it entered. Replies matching a floating rule will always exit out the default gateway/follow the routing table.

        Put the pass rules on each WAN individually.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • B Offline
          barnettd
          last edited by

          Thanks, that fixed the issue.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.