Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense 2.0 CARP/Redundant firewall How-To?

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    5 Posts 2 Posters 4.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bubble1975
      last edited by

      Hi All,

      I've got a need to set up a pair of pfSense firewalls in a primary/failover way, with 3 WAN IPs, one for the primary, one for the failover, and one for the "floating" IP.  I'll have OpenVPN running on these guys as well, hopefully syncing the users database, certificates and OpenVPN config between the two firewalls.  Is there a "HowTo" on how to set this up with pfSense 2.0?  I saw a tutorial on how to do it on what looks like version 1 here:

      http://doc.pfsense.org/index.php/Configuring_pfSense_Hardware_Redundancy_%28CARP%29

      and here:

      ftp://reflection.ncsa.uiuc.edu/pub/pfSense/tutorials/carp/carp-cluster-new.htm

      But those look kind of dated.  Is there a HowTo somewhere for version 2.0 that would accomplish what I'm looking to do?  I searched the forums quickly but saw nothing really definitive…

      Thanks for any insight/links!

      Cheers.

      1 Reply Last reply Reply Quote 0
      • B
        bubble1975
        last edited by

        No one knows (or wants to respond)?  ;)  Is it that complicated?

        1 Reply Last reply Reply Quote 0
        • C
          cmb
          last edited by

          It hasn't really changed, the existing info is still applicable.

          1 Reply Last reply Reply Quote 0
          • B
            bubble1975
            last edited by

            Great!  Thanks, that's all I needed.  Except I have one more question…  ;)

            If I configure advanced outbound NAT, which defines the source IP address the outbound packets have (the virtual IP), is there any way to still connect to each admin web interface individually, or would I be forced to connect to whichever machine is the 'master' at the time?  Even if the outbound NAT config of both machines is rewriting the return packets' IP to look the same on both?  Does my line of thinking make sense?

            Thanks again!

            1 Reply Last reply Reply Quote 0
            • C
              cmb
              last edited by

              You always want to connect only to the interface IPs for management, so you're 100% sure which box you're on. That's covered in detail in http://pfsense.org/book and is all the same on 2.0.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.