Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Carp Firewall rule clears after sync

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    10 Posts 5 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      ZackSmith
      last edited by

      Hi,

      I posted this in the firewall section aswell, everytime the rules sync the allow rule setup for traffic between carp interfaces clears and has to be set again. Is this normal behavior? has it been seen before?

      thanks

      Zack

      1 Reply Last reply Reply Quote 0
      • Z
        ZackSmith
        last edited by

        Ok, Does anyone know how I could add a cron job to put the rule back every hour or so?

        Thanks

        Zack

        1 Reply Last reply Reply Quote 0
        • dotdashD
          dotdash
          last edited by

          I have never seen that happen, so I would tend to think you were doing something wrong.
          Firewall, Virtual IPs, CARP settings- sync is checked on master, not on backup unit? You are doing edits on the master? Master is logging successful sync, etc?

          1 Reply Last reply Reply Quote 0
          • Z
            ZackSmith
            last edited by

            Yep everything is set up as described..

            If I could figure out a way to check and readd the rule every hour or so that would help alot

            Cheers

            Zack

            1 Reply Last reply Reply Quote 0
            • H
              heiko
              last edited by

              Master and Backup Firewall needs the same Interface order…

              e.g. first tab LAN, second WAN, third CARP , both systems needs the same order in the firewall tabs.

              1 Reply Last reply Reply Quote 0
              • Z
                ZackSmith
                last edited by

                Yes this is correct also, all in the right order.

                The rule on the backup firewall clears after successful  sync and you have to add it in before adding a new rule/carp ip/ipsec setting

                Cheers

                Zack

                1 Reply Last reply Reply Quote 0
                • M
                  morbus
                  last edited by

                  Are the interfaces all one the same if number? eg xl0
                  I have one box with 3 xl (3com) cards in it and the other has 4 xl
                  If you have one box with
                  xl0 - WAN
                  xl1 - LAN
                  xl2 - CARP_SYNC
                  and on the other one you have
                  xl0 - WAN
                  xl1 - LAN
                  xl2 - not used
                  xl3 - CARP_SYNC

                  and you assign xl2 on the master as carp sync that rule will be copied to xl2 on the slave and not the one named CARP_SYNC
                  This will also cause problems if you have a mix of NICs from different manufactures eg xl and fxp

                  pfs used to copy on the name but this is broke in 2.0. I haven't used 1.2… for ages so I don't know if this applies there

                  1 Reply Last reply Reply Quote 0
                  • Z
                    ZackSmith
                    last edited by

                    my Interfaces are:

                    fw0:
                    LAN BGE1
                    WAN BGE0
                    Lan2 RE0
                    CARP RE1

                    fw1:
                    LAN BGE1
                    WAN BGE0
                    Lan2 RE0
                    CARP RE1

                    All other rules on other interfaces/Vlans sync fine..

                    Hoping when the new version is available it will sort it. Other than that I'll have to work out a cron job to insert the rule every hour or so..

                    Thanks

                    Zack

                    1 Reply Last reply Reply Quote 0
                    • dotdashD
                      dotdash
                      last edited by

                      I'm still of the opinion that if this were a bug, someone else would have seen it. You could post your sanitized configs from both firewalls and someone might be willing to look them over.

                      1 Reply Last reply Reply Quote 0
                      • E
                        Eugene
                        last edited by

                        what  if you try to add on master firewall some weird distinguishable rule on carp interface (i suspect this is interface for pfsync), does it appear on slave firewall on any other interface?

                        http://ru.doc.pfsense.org

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.