Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    WAN link unplugged, but LAN not failoverto Backup

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    15 Posts 4 Posters 1.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @leiw
      last edited by

      @leiw
      The point is the CARP status, not the interface status.

      Check out Status > CARP.
      Which status shown up for LAN and WAN on primary and secondary?

      L 1 Reply Last reply Reply Quote 0
      • L
        leiw @viragomann
        last edited by

        @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

        @leiw
        The point is the CARP status, not the interface status.

        Check out Status > CARP.
        Which status shown up for LAN and WAN on primary and secondary?

        I am using XCP-NG to test HA, remember I can't ping the WAN CAPR interface in 10.0.11.0/24 network, I don't know is it normal:

        Master:
        ![f0bdb58f-5c9a-490e-b3cd-0b15a8f0dd0b-image.png](Input file contains unsupported image format)

        Backup:
        d30479d8-1144-4012-87f2-2619413abfd6-image.png

        Unplugged Master WAN link:

        Master:
        d27ad3b7-b1ce-48f1-8b34-7ba3e12484e5-image.png

        Backup:
        1f75d168-7a97-4d65-b680-91b6a9043716-image.png

        V 1 Reply Last reply Reply Quote 0
        • V
          viragomann @leiw
          last edited by

          @leiw
          What do you have in the CARP VIP settings?

          What is the underlying hardware? Or is pfSense virtualized?

          How are the devices connected to each over?

          If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

          What is logged regarding the failover?

          L 2 Replies Last reply Reply Quote 0
          • L
            leiw @viragomann
            last edited by

            @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

            @leiw
            What do you have in the CARP VIP settings?

            What is the underlying hardware? Or is pfSense virtualized?

            How are the devices connected to each over?

            If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

            What is logged regarding the failover?

            1. Master VIP
              10f9ca44-d9e6-47a0-b8ac-ddef37d5e7b7-image.png

            Backup VIP
            788673e8-3e01-493e-b6f1-ff443db22f58-image.png

            1. I followed this guide: https://xcp-ng.org/blog/2019/08/20/how-to-install-pfsense-in-a-vm/

            2. Both VMs WAN connected to XCP-NG nic01 that will get our local lan DHCP 10.0.11.0/24
              Both VMs LAN connected to XCP-NG nic02 that also connected to our local lan, but will change IP subnet to 192.168.1.0/24

            3. Both Sync is using Private network connect each other

            Master
            8d81313c-6dc8-4384-a4ae-2dd8617a1eb0-image.png

            Backup
            70e36117-f595-4815-9dd2-5cbc6a92b57a-image.png

            Master
            63cae027-1f81-46ff-a393-cde4b9687d98-image.png

            Backup
            ec8cd175-6602-416c-bcf0-89094569efe1-image.png

            Thanks for helping!

            L 1 Reply Last reply Reply Quote 0
            • L
              leiw @leiw
              last edited by

              @leiw said in WAN link unplugged, but LAN not failoverto Backup:

              @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

              @leiw
              What do you have in the CARP VIP settings?

              What is the underlying hardware? Or is pfSense virtualized?

              How are the devices connected to each over?

              If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

              What is logged regarding the failover?

              1. Master VIP
                10f9ca44-d9e6-47a0-b8ac-ddef37d5e7b7-image.png

              Backup VIP
              788673e8-3e01-493e-b6f1-ff443db22f58-image.png

              1. I followed this guide: https://xcp-ng.org/blog/2019/08/20/how-to-install-pfsense-in-a-vm/

              2. Both VMs WAN connected to XCP-NG nic01 that will get our local lan DHCP 10.0.11.0/24
                Both VMs LAN connected to XCP-NG nic02 that also connected to our local lan, but will change IP subnet to 192.168.1.0/24

              3. Both Sync is using Private network connect each other

              Master
              8d81313c-6dc8-4384-a4ae-2dd8617a1eb0-image.png

              Backup
              70e36117-f595-4815-9dd2-5cbc6a92b57a-image.png

              Master
              63cae027-1f81-46ff-a393-cde4b9687d98-image.png

              Backup
              ec8cd175-6602-416c-bcf0-89094569efe1-image.png

              Thanks for helping!

              Can someone help?

              1 Reply Last reply Reply Quote 0
              • L
                leiw @viragomann
                last edited by

                @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

                @leiw
                What do you have in the CARP VIP settings?

                What is the underlying hardware? Or is pfSense virtualized?

                How are the devices connected to each over?

                If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                What is logged regarding the failover?

                Hello viragomaan, can you help, please?

                V 1 Reply Last reply Reply Quote 0
                • V
                  viragomann @leiw
                  last edited by

                  @leiw said in WAN link unplugged, but LAN not failoverto Backup:

                  What do you have in the CARP VIP settings?

                  The Advertising frequency and skew were the real interesting settings on both nodes here.

                  Did you disable the 'TX Checksum Offload' as described in the setup tutorial?

                  Did you also disable 'Hardware Checksum Offloading' in pfSense?
                  System > Advanced > Networking

                  On both virtual switches, WAN and LAN you might also have to enable the promiscuous mode, at least for the pfSense interfaces.
                  I don't know, how this can be done on XCP-ng, but would be essential if there is such option.

                  If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                  What's about this??
                  This could give important information about, what's going on.

                  Go through the Troubleshooting High Availability steps in the pfSense docs.

                  L 1 Reply Last reply Reply Quote 0
                  • L
                    leiw @viragomann
                    last edited by

                    @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

                    @leiw said in WAN link unplugged, but LAN not failoverto Backup:

                    What do you have in the CARP VIP settings?

                    The Advertising frequency and skew were the real interesting settings on both nodes here.

                    Did you disable the 'TX Checksum Offload' as described in the setup tutorial?

                    Did you also disable 'Hardware Checksum Offloading' in pfSense?
                    System > Advanced > Networking

                    On both virtual switches, WAN and LAN you might also have to enable the promiscuous mode, at least for the pfSense interfaces.
                    I don't know, how this can be done on XCP-ng, but would be essential if there is such option.

                    If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                    What's about this??
                    This could give important information about, what's going on.

                    Go through the Troubleshooting High Availability steps in the pfSense docs.

                    Thanks for the help.

                    Yes, I enabled 'TX Checksum Offload' and enable the promiscuous mode on both WAN and LAN, also I just disabled 'Hardware Checksum Offloading', but no luck.

                    Also, this problem in VirtualBox.

                    If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?
                    I just quote, please avoid it.

                    Thanks

                    L 1 Reply Last reply Reply Quote 0
                    • L
                      leiw @leiw
                      last edited by

                      @leiw said in WAN link unplugged, but LAN not failoverto Backup:

                      @viragomann said in WAN link unplugged, but LAN not failoverto Backup:

                      @leiw said in WAN link unplugged, but LAN not failoverto Backup:

                      What do you have in the CARP VIP settings?

                      The Advertising frequency and skew were the real interesting settings on both nodes here.

                      Did you disable the 'TX Checksum Offload' as described in the setup tutorial?

                      Did you also disable 'Hardware Checksum Offloading' in pfSense?
                      System > Advanced > Networking

                      On both virtual switches, WAN and LAN you might also have to enable the promiscuous mode, at least for the pfSense interfaces.
                      I don't know, how this can be done on XCP-ng, but would be essential if there is such option.

                      If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?

                      What's about this??
                      This could give important information about, what's going on.

                      Go through the Troubleshooting High Availability steps in the pfSense docs.

                      Thanks for the help.

                      Yes, I enabled 'TX Checksum Offload' and enable the promiscuous mode on both WAN and LAN, also I just disabled 'Hardware Checksum Offloading', but no luck.

                      Also, this problem in VirtualBox.

                      If you sniff the CARP traffic on the secondary, when masters WAN is unplugged, what do your get?
                      I just quote, please avoid it.

                      Thanks

                      Sorry, I can ping the WAN virtual IP, after unplugged WAN on MASTER, but the LAN still on BACKUP status on BACKUP node.

                      f12cea5e-280b-40c8-8ea8-79e539628110-image.png

                      ? 1 Reply Last reply Reply Quote 0
                      • R robert1157 referenced this topic on
                      • ?
                        A Former User @leiw
                        last edited by

                        @leiw

                        I've run into this issue, too. I have pfSense in HA on two ESXi hosts. It turned out that CARP and gateway monitoring do not work together. The WAN gateway may be offline, but CARP does not know about it. CARP has its own monitoring that is set up on the network interfaces. When pfSense runs in a VM and its interfaces are connected to a vSwitch, unplugging WAN disconnects the vSwitche's uplink, but the pfSense's WAN is still up. WAN is connected to the vSwitch so it is still happy. The CARP MASTER just doesn't know that the uplink is disconnected. To eliminate this issue, the pfSenses interfaces in VM need to be pass-through. That's not only a VM issue. Netgate's own firewall, SG-7100, that comes with its own switch has the same issue which is even documented in the SG-7100 manual. So, it is what it is.

                        1 Reply Last reply Reply Quote 0
                        • P
                          Phelton
                          last edited by Phelton

                          hi everyone,
                          i have same topology and i have same issue.

                          release 2.0.7 AMD64

                          1 Reply Last reply Reply Quote 0
                          • P
                            Phelton
                            last edited by

                            i have replicated topology in GNS3 Lab and have same issue:

                            Immagine 2024-03-27 172830.jpg

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.