Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Netgate 7100 with HA update issues

    Scheduled Pinned Locked Moved General pfSense Questions
    carpfailoverupdates
    22 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nick.loenders @stephenw10
      last edited by

      @stephenw10 NO idea how that actually works but here it is:

      c2ec6daa-c8c4-4516-9ea7-ed559ae8c615-image.png

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Ok, that looks good.

        Can you test a ping to, say, 8.8.8.8 from the command line on that node?

        Whilst that ping is running check the state table in Diag > States. Filter it by 8.8.8.8 and make sure the outbound state exists and on the correct interface.

        N 1 Reply Last reply Reply Quote 0
        • N
          nick.loenders @stephenw10
          last edited by

          @stephenw10 Well then there is no reply, in the states it says:

          6dff1261-dddb-4385-9289-c01fe3dbab5b-image.png

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Hmm, what is that connected to? How are the other NICs connected?

            I assume the primary node can ping everything OK?

            N 1 Reply Last reply Reply Quote 0
            • N
              nick.loenders @stephenw10
              last edited by

              @stephenw10 the primary node can ping perfectly

              The WAN nics are connected to a patchpanel and get a direct ip from the hosting in the datacenter.
              WAN on pri;ary is .35
              WAN on secondary is .36
              Virtual WAN for HA and how we go out is .33 (if we are on a server and do whatismyip.com we see .33 )

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Hmm. Traffic just disappearing like that I start to suspect something odd upsteam.

                Check on the primary node to see if replies are somehow being incorrectly sent to it. So you would see that in the firewall log there unless you have rules to pass it.

                I assume the CARP VIPs are all failing over correctly?

                N 1 Reply Last reply Reply Quote 0
                • N
                  nick.loenders @stephenw10
                  last edited by

                  @stephenw10

                  I do see this on the firewall, don't know what that is:

                  b2464615-6e59-467c-993f-8dafe696246a-image.png

                  I already added that to the rules, but it does not help.

                  I do seem not to be able to ping the other SYNC side:

                  62974caa-cd27-4c71-993d-a84303203048-image.png

                  N 1 Reply Last reply Reply Quote 0
                  • N
                    nick.loenders @nick.loenders
                    last edited by

                    @stephenw10 nevermind the ping, I solved that by a rule

                    1 Reply Last reply Reply Quote 0
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      I wouldn't expect to see CARP multicast traffic on the SYNC interface. There shouldn't normally be a CARP VIP on it.

                      I also wouldn't expect that to make any difference to secondary connectivity though.

                      Try pinging something from the secondary and then running a pcap on the primary WAN for that same target and see if packets are coming back incorrectly there.

                      N 1 Reply Last reply Reply Quote 0
                      • N
                        nick.loenders @stephenw10
                        last edited by

                        @stephenw10 I sent you a chat

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.