Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN link unplugged, but LAN not failoverto Backup

    HA/CARP/VIPs
    4
    15
    903
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      leiw
      last edited by

      Hello,

      I am testing WAN disconnect (unplugged cable), but only WAN can failover to Backup, but LAN didn't, can someone help? thanks

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @leiw
        last edited by

        @leiw
        So the LAN is still shown up as backup on the secondary and as master on the primary?

        L 1 Reply Last reply Reply Quote 0
        • L
          leiw @viragomann
          last edited by

          @viragomann

          @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

          @leiw
          So the LAN is still shown up as backup on the secondary and as master on the primary?

          MASTER:
          WAN DOWN
          LAN UP

          BACKUP:
          WAN UP
          LAN DOWN

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @leiw
            last edited by

            @leiw
            The point is the CARP status, not the interface status.

            Check out Status > CARP.
            Which status shown up for LAN and WAN on primary and secondary?

            L 1 Reply Last reply Reply Quote 0
            • L
              leiw @viragomann
              last edited by

              @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

              @leiw
              The point is the CARP status, not the interface status.

              Check out Status > CARP.
              Which status shown up for LAN and WAN on primary and secondary?

              I am using XCP-NG to test HA, remember I can't ping the WAN CAPR interface in 10.0.11.0/24 network, I don't know is it normal:

              Master:
              ![f0bdb58f-5c9a-490e-b3cd-0b15a8f0dd0b-image.png](Input file contains unsupported image format)

              Backup:
              d30479d8-1144-4012-87f2-2619413abfd6-image.png

              Unplugged Master WAN link:

              Master:
              d27ad3b7-b1ce-48f1-8b34-7ba3e12484e5-image.png

              Backup:
              1f75d168-7a97-4d65-b680-91b6a9043716-image.png

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @leiw
                last edited by

                @leiw
                What do you have in the CARP VIP settings?

                What is the underlying hardware? Or is pfSense virtualized?

                How are the devices connected to each over?

                If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                What is logged regarding the failover?

                L 2 Replies Last reply Reply Quote 0
                • L
                  leiw @viragomann
                  last edited by

                  @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

                  @leiw
                  What do you have in the CARP VIP settings?

                  What is the underlying hardware? Or is pfSense virtualized?

                  How are the devices connected to each over?

                  If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                  What is logged regarding the failover?

                  1. Master VIP
                    10f9ca44-d9e6-47a0-b8ac-ddef37d5e7b7-image.png

                  Backup VIP
                  788673e8-3e01-493e-b6f1-ff443db22f58-image.png

                  1. I followed this guide: https://xcp-ng.org/blog/2019/08/20/how-to-install-pfsense-in-a-vm/

                  2. Both VMs WAN connected to XCP-NG nic01 that will get our local lan DHCP 10.0.11.0/24
                    Both VMs LAN connected to XCP-NG nic02 that also connected to our local lan, but will change IP subnet to 192.168.1.0/24

                  3. Both Sync is using Private network connect each other

                  Master
                  8d81313c-6dc8-4384-a4ae-2dd8617a1eb0-image.png

                  Backup
                  70e36117-f595-4815-9dd2-5cbc6a92b57a-image.png

                  Master
                  63cae027-1f81-46ff-a393-cde4b9687d98-image.png

                  Backup
                  ec8cd175-6602-416c-bcf0-89094569efe1-image.png

                  Thanks for helping!

                  L 1 Reply Last reply Reply Quote 0
                  • L
                    leiw @leiw
                    last edited by

                    @leiw said in WAN link unplugged, but LAN not failoverto Backup:

                    @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

                    @leiw
                    What do you have in the CARP VIP settings?

                    What is the underlying hardware? Or is pfSense virtualized?

                    How are the devices connected to each over?

                    If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                    What is logged regarding the failover?

                    1. Master VIP
                      10f9ca44-d9e6-47a0-b8ac-ddef37d5e7b7-image.png

                    Backup VIP
                    788673e8-3e01-493e-b6f1-ff443db22f58-image.png

                    1. I followed this guide: https://xcp-ng.org/blog/2019/08/20/how-to-install-pfsense-in-a-vm/

                    2. Both VMs WAN connected to XCP-NG nic01 that will get our local lan DHCP 10.0.11.0/24
                      Both VMs LAN connected to XCP-NG nic02 that also connected to our local lan, but will change IP subnet to 192.168.1.0/24

                    3. Both Sync is using Private network connect each other

                    Master
                    8d81313c-6dc8-4384-a4ae-2dd8617a1eb0-image.png

                    Backup
                    70e36117-f595-4815-9dd2-5cbc6a92b57a-image.png

                    Master
                    63cae027-1f81-46ff-a393-cde4b9687d98-image.png

                    Backup
                    ec8cd175-6602-416c-bcf0-89094569efe1-image.png

                    Thanks for helping!

                    Can someone help?

                    1 Reply Last reply Reply Quote 0
                    • L
                      leiw @viragomann
                      last edited by

                      @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

                      @leiw
                      What do you have in the CARP VIP settings?

                      What is the underlying hardware? Or is pfSense virtualized?

                      How are the devices connected to each over?

                      If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                      What is logged regarding the failover?

                      Hello viragomaan, can you help, please?

                      V 1 Reply Last reply Reply Quote 0
                      • V
                        viragomann @leiw
                        last edited by

                        @leiw said in WAN link unplugged, but LAN not failoverto Backup:

                        What do you have in the CARP VIP settings?

                        The Advertising frequency and skew were the real interesting settings on both nodes here.

                        Did you disable the 'TX Checksum Offload' as described in the setup tutorial?

                        Did you also disable 'Hardware Checksum Offloading' in pfSense?
                        System > Advanced > Networking

                        On both virtual switches, WAN and LAN you might also have to enable the promiscuous mode, at least for the pfSense interfaces.
                        I don't know, how this can be done on XCP-ng, but would be essential if there is such option.

                        If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                        What's about this??
                        This could give important information about, what's going on.

                        Go through the Troubleshooting High Availability steps in the pfSense docs.

                        L 1 Reply Last reply Reply Quote 0
                        • L
                          leiw @viragomann
                          last edited by

                          @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

                          @leiw said in WAN link unplugged, but LAN not failoverto Backup:

                          What do you have in the CARP VIP settings?

                          The Advertising frequency and skew were the real interesting settings on both nodes here.

                          Did you disable the 'TX Checksum Offload' as described in the setup tutorial?

                          Did you also disable 'Hardware Checksum Offloading' in pfSense?
                          System > Advanced > Networking

                          On both virtual switches, WAN and LAN you might also have to enable the promiscuous mode, at least for the pfSense interfaces.
                          I don't know, how this can be done on XCP-ng, but would be essential if there is such option.

                          If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                          What's about this??
                          This could give important information about, what's going on.

                          Go through the Troubleshooting High Availability steps in the pfSense docs.

                          Thanks for the help.

                          Yes, I enabled 'TX Checksum Offload' and enable the promiscuous mode on both WAN and LAN, also I just disabled 'Hardware Checksum Offloading', but no luck.

                          Also, this problem in VirtualBox.

                          If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?
                          I just quote, please avoid it.

                          Thanks

                          L 1 Reply Last reply Reply Quote 0
                          • L
                            leiw @leiw
                            last edited by

                            @leiw said in WAN link unplugged, but LAN not failoverto Backup:

                            @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

                            @leiw said in WAN link unplugged, but LAN not failoverto Backup:

                            What do you have in the CARP VIP settings?

                            The Advertising frequency and skew were the real interesting settings on both nodes here.

                            Did you disable the 'TX Checksum Offload' as described in the setup tutorial?

                            Did you also disable 'Hardware Checksum Offloading' in pfSense?
                            System > Advanced > Networking

                            On both virtual switches, WAN and LAN you might also have to enable the promiscuous mode, at least for the pfSense interfaces.
                            I don't know, how this can be done on XCP-ng, but would be essential if there is such option.

                            If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                            What's about this??
                            This could give important information about, what's going on.

                            Go through the Troubleshooting High Availability steps in the pfSense docs.

                            Thanks for the help.

                            Yes, I enabled 'TX Checksum Offload' and enable the promiscuous mode on both WAN and LAN, also I just disabled 'Hardware Checksum Offloading', but no luck.

                            Also, this problem in VirtualBox.

                            If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?
                            I just quote, please avoid it.

                            Thanks

                            Sorry, I can ping the WAN virtual IP, after unplugged WAN on MASTER, but the LAN still on BACKUP status on BACKUP node.

                            f12cea5e-280b-40c8-8ea8-79e539628110-image.png

                            ? 1 Reply Last reply Reply Quote 0
                            • R robert1157 referenced this topic on
                            • ?
                              A Former User @leiw
                              last edited by

                              @leiw

                              I've run into this issue, too. I have pfSense in HA on two ESXi hosts. It turned out that CARP and gateway monitoring do not work together. The WAN gateway may be offline, but CARP does not know about it. CARP has its own monitoring that is set up on the network interfaces. When pfSense runs in a VM and its interfaces are connected to a vSwitch, unplugging WAN disconnects the vSwitche's uplink, but the pfSense's WAN is still up. WAN is connected to the vSwitch so it is still happy. The CARP MASTER just doesn't know that the uplink is disconnected. To eliminate this issue, the pfSenses interfaces in VM need to be pass-through. That's not only a VM issue. Netgate's own firewall, SG-7100, that comes with its own switch has the same issue which is even documented in the SG-7100 manual. So, it is what it is.

                              1 Reply Last reply Reply Quote 0
                              • P
                                Phelton
                                last edited by Phelton

                                hi everyone,
                                i have same topology and i have same issue.

                                release 2.0.7 AMD64

                                1 Reply Last reply Reply Quote 0
                                • P
                                  Phelton
                                  last edited by

                                  i have replicated topology in GNS3 Lab and have same issue:

                                  Immagine 2024-03-27 172830.jpg

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.