Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFsense Failover

    HA/CARP/VIPs
    4
    9
    3.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • deltaendD
      deltaend
      last edited by

      So… I'm not familiar with BGP or RIP but here is what I'm looking for, perhaps it is already built into PFsense.

      1. Synced configurations between several firewalls
      2. Firewall 1 goes down RIP/BGP/STP etc... on the switch routes the incoming connections through firewall 2 instead.

      Possible?  Already built into the system?

      1 Reply Last reply Reply Quote 0
      • M
        miloman
        last edited by

        here ya go: http://www.howtoforge.com/how-to-configure-a-pfsense-2.0-cluster-using-carp

        and you dont even need to know anything about bgp, rip, ospf or isis. just follow the guide above and you'll be set. :)

        1 Reply Last reply Reply Quote 0
        • N
          nicolas010
          last edited by

          HI, would you have another tutorial for pfSense 2.0.2, because the options changed a lot.

          BTW I follow the tutorial the best I could and and it works likely, why likely, because when I configured the VIPs, in the backup pfSense, the WAN VIP says backup, but the LAN VIP says "MASTER" as it does the primary pfSense. So, is this ok? is this a bug? do I have to change something else? My 2 pfSense are not firewalls BTW, and so in the LAN interface I have other 4 VLANs with DHCP server and a Captive Portal. So what other change do I have to make? Thanks before hand.

          1 Reply Last reply Reply Quote 0
          • M
            miloman
            last edited by

            You're supposed to configure everything on the primary firewall. The VIP's included. Under your carp synchronization settings theres settngs for syncing the conf to the backup firewall.

            Where are you from? Your name and writing style leeds me to think you mit be from scandinavia? If thats e cae, i might be able to explain it to you in your native language. :)

            1 Reply Last reply Reply Quote 0
            • H
              hackin8
              last edited by

              Not wanting to hijack this thread - but one quick question:

              If I have two non-identical systems (different PC's, CPU, NIC's etc) will this still work if I name interfaces the same or do I need to set up some other way?

              Thanks

              1 Reply Last reply Reply Quote 0
              • M
                miloman
                last edited by

                Quick answer; yes.  :)

                1 Reply Last reply Reply Quote 0
                • N
                  nicolas010
                  last edited by

                  Hi, I am from South America, so I have a question about configuring VIPs, do I need to create VIPs for the VLANs as well?

                  When I first configure the two pfSense, in the MASTER I had the two VIPs (WAN and LAN), on MASTER, but, in the BACKUP I had only the WAN on BACKUP and the LAN was as MASTER as well, so is this ok??? I dont know why, all the configuration I made was in the MASTER.

                  1 Reply Last reply Reply Quote 0
                  • M
                    miloman
                    last edited by

                    Have you tried rebooting them? This sometimes happens for me as well on the initial install.

                    1 Reply Last reply Reply Quote 0
                    • N
                      nicolas010
                      last edited by

                      No, I have not try to reboot them, I will try it later in the afternoon.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.