• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pfsync w/o CARP

Scheduled Pinned Locked Moved HA/CARP/VIPs
5 Posts 3 Posters 3.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    mrquintopolous
    last edited by Jun 11, 2007, 9:13 PM

    Any way to enable pfsync ( so that two firewalls can keep in sync ) without using CARP, or are they tied together? I am looking to keep two firewalls with the same set of rules but not deal with the CARP fail over, as the managed switch will handle fail over.

    Thanks!

    1 Reply Last reply Reply Quote 0
    • C
      cmb
      last edited by Jun 12, 2007, 3:08 AM

      How is your switch going to handle failover?

      pfsync isn't what synchronizes rules though, that synchronizes firewall states. Not sure if you can use the XMLRPC sync for rules without using CARP, someone else will have to chime in on that.

      1 Reply Last reply Reply Quote 0
      • M
        mrquintopolous
        last edited by Jun 12, 2007, 6:06 PM

        Ah, ok. Thanks for the info. Saving states would be nice but syncing the rules would be my main goal. I could probably script something (or add a feature to the GUI such that when one updates its rules, it'll send it over to the other ones).

        The failover is done by HSRP, http://en.wikipedia.org/wiki/Hot_Standby_Router_Protocol, which is similar to CARP.

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by Jun 13, 2007, 2:04 AM

          I asked how you were going to fail over with the switch because I think you may be misunderstanding the capabilities of your switch. If it supports HSRP, it's only on L3 functionality of the switch, and it's only going to fail the switch's routing capabilities over to another switch (or HSRP capable router). HSRP isn't going to allow you to fail between pfsense boxes, you'll need CARP and pfsync for that.

          1 Reply Last reply Reply Quote 0
          • G
            gtdawg
            last edited by Jun 22, 2007, 4:32 AM

            I have gotten this to work by just enabling "Synchronize Enabled" in the CARP Settings and selecting the interface desired, the firewalls will find each other via multicast and tell each other what states they have. I am load balancing across multiple firewalls and need to handle as many states as possible. I have also gotten syncing of rules working by following all the instructions for CARP but leaving out the virtual IP parts.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received