Proxy ARP + Redundancy
-
Hi,
I'm a hosting provider and my ISP gave me lots of public IP addresses (~500).
Some of my customers require many adresses for the same web server.What I do today :
-> Create VIP using carp
-> Add NAT to server address based on created VIPThe problem is that I have two pf-sense boxes redundantly connected (carp failover). Could I use proxy-arp instead of carp for my customers additionnal IPs (since this is a lot quicker to set-up compared to carp (password, id, etc..)?
What if I set-up proxy-arp for the same address on the two pf-sense boxes? Would some trafic run through the second box?Thanks for your help,
Regards,Gaëtan
-
You definitely don't want to mix Proxyarp with CARP. Use CARP and they'll be available on both firewalls so all your customers are able to enjoy your redundant setup.
-
If the additional IPs are routed to your main shared CARP IP, you can use the "other" type VIP. You'll just need to set them up on the backup unit by hand the same way.