Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Use spare interfaces as a switch

    2.0-RC Snapshot Feedback and Problems - RETIRED
    4
    7
    2.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      Ozzik
      last edited by

      Hi,
      I'm building a CARP setup. It involves one main pfSense as a main firewall and two pfSense boxes as redundant routers (routers being the only ones in the CARP setup).
      I need to connect both of the routers to the main firewall in order to have a CARP interface, that means I need to go through a switch, but my question is whether this can be bypassed. I mean, if I have two spare interfaces in the firewall box - can I somehow use them as a switch for CARP interface from the routers?

      maybe with LAGG interface somehow?

      thanks.

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        ~~This would defeat the purpose of CARP….

        Of course it would technically work, but then if you have a hardware failure, the backup would fail as well. (Since it's "switched" over the failing machine)~~

        Maybe i'm missreading.

        Are you talking about such a setup?

        pfSense(Firewall)
                              |
                              |
                           Switch
                          /        
                         |           |
        pfSense(Router)       pfSense(Router)

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • E
          eri--
          last edited by

          No you cannot since carp does not support this and it runs on the interface where the link connects.

          Though its considered a feature because you do not need teh extra hardware.
          Really carp does not add that much traffic to the network.

          Nobody plans to do this unless someone asks for it through paid development!

          1 Reply Last reply Reply Quote 0
          • O
            Ozzik
            last edited by

            Maybe i'm missreading.

            Are you talking about such a setup?

            pfSense(Firewall)
                                  |
                                  |
                                Switch
                              /       
                              |          |
            pfSense(Router)      pfSense(Router)

            yes, exactly. I realize that the firewall would be a single point of failure.
            With every cheap router of $50 you usually get a 4-ports switch/hub and I was wondering if there's a way to this with pfSense.

            1 Reply Last reply Reply Quote 0
            • rcfaR
              rcfa
              last edited by

              Even outside the CARP setup this woult be useful.
              My Lanner box e.g. has 6-NICs built-in. I need one for LAN, one for WAN, maybe one for a guest WiFi AP/DMZ.

              That leaves me with three unused NICs, which all could be assigned to LAN use. If all four LAN NICs could be on the same IP and act like a switch, I could save one switch in the basement, with all the power and cable mess that would go away with that.

              Not a top priority, but certainly a nice-to-have feature, cause right now the extra NICs are just potential homes for spiders (the 8-legged non-electronic kind)

              1 Reply Last reply Reply Quote 0
              • E
                eri--
                last edited by

                Bridge?!

                1 Reply Last reply Reply Quote 0
                • O
                  Ozzik
                  last edited by

                  ermal,
                  if so, then what I want is possible? I just need to bridge the two interfaces?

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.