Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How should it run ?

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    23 Posts 4 Posters 8.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sullrich
      last edited by

      And the master's ADVSKEW is set to what again?

      1 Reply Last reply Reply Quote 0
      • J
        Juve
        last edited by

        Master : 0
        Slave 100

        configuration sync enabled between firewalls

        master.GIF_thumb
        master.GIF
        slave.GIF
        slave.GIF_thumb
        settings.GIF
        settings.GIF_thumb
        slave.GIF_thumb
        master.GIF_thumb
        settings.GIF_thumb

        1 Reply Last reply Reply Quote 0
        • S
          sullrich
          last edited by

          Hrm.  Wish that I could reproduce this…

          1 Reply Last reply Reply Quote 0
          • J
            jakehathaway
            last edited by

            I am seeing the same issue. I have 3 carp addresses, lan, wan, qmoe plus the pfsense internal address. All items seem to sync just fine. I created the backup from the master. I have all 3 master carps at 0 and all 3 backup carps at 100. sometimes only 1 or 2 of the carps failover and it just holds them. I have to re-save carp settings on backup or reboot backup pf box to get it to fail back.
            I would love to send any configs, or debug logs if I can do something to help you see the issue. Please let me know.
            Currently my boxes are not in a production environment so now is the prime time to debug.
            Thanks.

            1 Reply Last reply Reply Quote 0
            • J
              Juve
              last edited by

              Have you checked if your switches are not blocking CARP traffic ?
              Just to be sure….

              1 Reply Last reply Reply Quote 0
              • S
                sullrich
                last edited by

                Switches are constantly an issue with CARP it seems.  Definitely ensure that its not being blocked/stopped at the switch level.

                1 Reply Last reply Reply Quote 0
                • J
                  jakehathaway
                  last edited by

                  I don't have my pfsync interfaces plugged into a switch, they are plugged in with a crossover cable to each other.

                  1 Reply Last reply Reply Quote 0
                  • S
                    sullrich
                    last edited by

                    CARP != pfSync.  CARP traffic will still be present on all interfaces that have a CARP address assigned.  If they cannot communicate then it will not work.

                    1 Reply Last reply Reply Quote 0
                    • H
                      hoba
                      last edited by

                      CARP is the mechnism used to detect the state of machines in a cluster and to swap the macadress back and forth between clustermembers. This traffic will happen on every interface where a carp ip resides.

                      pfSync is an additional mechanism used to sync the statetables between clustermembers so that already established connections don't need to be reestablished after a failover. This traffic will happen on the interface that you set as sync interface.

                      Both features do work independently of each other but are often used together.

                      1 Reply Last reply Reply Quote 0
                      • J
                        jakehathaway
                        last edited by

                        So what do I look for on the switch as CARP traffic?

                        1 Reply Last reply Reply Quote 0
                        • H
                          hoba
                          last edited by

                          See http://www.countersiege.com/doc/pfsync-carp/ for how it works.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.