Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    CARP and high available sync

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    4 Posts 2 Posters 853 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K Offline
      kubin
      last edited by

      Hello Pfsense community,

      i'm facing a problem with CARP and HIGH available sync on one of my firewall cluster. I have 15 CARP IPs and just 3 have bad interfaces on VHID group. VHID and IP are correct but interface isn't.
      I checked passwords, subnet masks, IP ranges but all seem OK. I also tried to fix it manually on secondary node but after applying configuration on primary it is obviously bad again. But it is working for a while…

      I have this issue just within one IP range with /27 subnet as you can see in attached pictures.

      Have anybody had something similar?

      Thank you
      Michal
      ![Screen Shot 2017-06-21 at 08.39.32.png](/public/imported_attachments/1/Screen Shot 2017-06-21 at 08.39.32.png)
      ![Screen Shot 2017-06-21 at 08.39.32.png_thumb](/public/imported_attachments/1/Screen Shot 2017-06-21 at 08.39.32.png_thumb)
      ![Screen Shot 2017-06-21 at 08.39.37.png](/public/imported_attachments/1/Screen Shot 2017-06-21 at 08.39.37.png)
      ![Screen Shot 2017-06-21 at 08.39.37.png_thumb](/public/imported_attachments/1/Screen Shot 2017-06-21 at 08.39.37.png_thumb)

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        For starters, your interfaces must match exactly on primary and secondary. They must be defined in the same order and optX on primary must equal optX on secondary.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • K Offline
          kubin
          last edited by

          aahhhh… that's it.

          I'm going to change it and let you know.

          ![Screen Shot 2017-06-21 at 09.09.58.png](/public/imported_attachments/1/Screen Shot 2017-06-21 at 09.09.58.png)
          ![Screen Shot 2017-06-21 at 09.09.58.png_thumb](/public/imported_attachments/1/Screen Shot 2017-06-21 at 09.09.58.png_thumb)

          1 Reply Last reply Reply Quote 0
          • K Offline
            kubin
            last edited by

            You saved me a lot of time… The problem was in interface numbering(OPTX). I Have just fixed it and it is working!

            Thank you!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.