Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Setting up CARP cluster for LAN and WAN VIPs at the same time

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    15 Posts 5 Posters 7.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sullrich
      last edited by

      Recent snapshots sync the time with ntpdate on bootup.  Please upgrade.

      1 Reply Last reply Reply Quote 0
      • H
        heiko
        last edited by

        Hello,

        i think i misunderstand something. I have also a carp cluster with 25 ipsec tunnels and all works fine without ipsec. The Master WAN Ip ist 217.6.55.4 , the backup carp ist 217.6.55.5 and the VIP ist 217.6.55.6. On the master i cannot change anything on the tunnel def., because the remote side is setting to 217.6.55.4. In the carp cluster i syncronize IPSEC, so when the master fails, the remote side have a settting to 217.6.55.4, but the backup member is 217.6.55.5. I can set the ipsec failover on the master to the vip 217.6.55.6 but i cannot understand this scenario, because the backup member ist at the WAN 217.6.55.5…..

        I think, i get a little bit help to understand the settings.... a liitle bit confusing?

        Grreetings from Germany
        Heiko

        1 Reply Last reply Reply Quote 0
        • S
          sullrich
          last edited by

          #1. Setup your tunnels to use "IP address" and the VIP carp member
          #2. Visit Vpn, IPSEC, Failover IPSEC, define the VIP ip address
          #3. Visit the other end of the tunnel, make sure the remote gateway is
          set as the CARP VIP
          #4. There is no step 4.  Enjoy your failover IPSEC.

          1 Reply Last reply Reply Quote 0
          • H
            heiko
            last edited by

            Hello,

            it´s all greek to me. Scott, i found this with google, but i understand not which settings are do you mean

            –> Setup your tunnels to use "IP address" and the VIP carp member

            Do you mean the tunnel settings my identifier as the ip adress?
            I have to have lost one's way...., i think

            Thank you for your help!
            Heiko

            1 Reply Last reply Reply Quote 0
            • S
              sullrich
              last edited by

              IP address = CARP public ip

              1 Reply Last reply Reply Quote 0
              • H
                heiko
                last edited by

                Hello Scott,

                excuse me…

                do you mean the settings in the conn. of ipsec or other...?

                i`m stupid

                Heiko

                1 Reply Last reply Reply Quote 0
                • H
                  hoba
                  last edited by

                  vpn>ipsec, failover tab. Set your shared CARP IP there.

                  1 Reply Last reply Reply Quote 0
                  • H
                    heiko
                    last edited by

                    Hallo Hoba,
                    ich schreibs noch einmal auf deutsch, habe wahrscheinlich wirklich nen Brett vorm Kopf. Tut mir leid, aber ich will´s halt verstehen..

                    wenn ich doch zwei wan-adressen und eine vip wan habe, diese  als failover einsetze, die tunnel doch aber auf die wan adresse des masters gemappt sind, wie funktioniert dann ein failover. oder wird in einem Carp Cluster mit eingesetzter VIP als IPSEC failover immer diese in die racoon.conf geschrieben und die eigentliche WAN Adresse des masters vernachlässigt?

                    Vielleicht verstehe ich es ja diese Jahr noch?
                    Gruß
                    Heiko

                    1 Reply Last reply Reply Quote 0
                    • H
                      hoba
                      last edited by

                      Richtig, die im IPSEC failover tab angegebene Adresse wird dann für den lokalen IPSEC Traffic verwendet und kann somit auch vom Slave übernommen werden.

                      1 Reply Last reply Reply Quote 0
                      • H
                        heiko
                        last edited by

                        danke, jetzt habe ich es
                        gruß
                        heiko

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.