• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Failover and PPPoE

Scheduled Pinned Locked Moved HA/CARP/VIPs
4 Posts 3 Posters 3.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    decibel83
    last edited by Apr 6, 2013, 9:00 AM

    Hi.

    I have a PPPoE WAN connection with 1 public IP address, and I have two pfSense boxes.

    The first pfSense box is working good, but I would like to install the second one to have a failover using CARP or something like that.
    How I could manage the PPPoE connection?
    Could I configure CARP only on the LAN and have the PPPoE connection active only on the master system?
    I could ask my ISP for a subnet, but they give me only one PPPoE account so I cannot have both pfSense boxes connected to the WAN on the same time.

    I don't like to add a PPPoE router before the pfSense systems (natting the WAN network) because doing so I'll add a single point of failure.

    Could you help me, please?

    Thank you very much!
    Bye.

    1 Reply Last reply Reply Quote 0
    • C
      cmb
      last edited by Apr 6, 2013, 9:05 AM

      The modem will have to do the PPPoE to have stateful failover in that case. CARP can't function with PPPoE.

      1 Reply Last reply Reply Quote 0
      • D
        decibel83
        last edited by Apr 6, 2013, 9:07 AM

        @cmb:

        The modem will have to do the PPPoE to have stateful failover in that case. CARP can't function with PPPoE.

        Ok, I know, but is it possible to configure the second pfSense router to dial the PPPoE connection only when the first router is down (and so the second router is the master one)?
        What if I configure the PPPoE connection on the second router to be on-demand?

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Apr 8, 2013, 3:50 PM

          That wouldn't work without some manual hacking and even then isn't likely to do what you really want/need.

          It might be best set set the modem to do PPPoE and then have it do 1:1/DMZ from the PPPoE WAN IP to a CARP VIP on the shared segment. Much less hacking, plus you get stateful failover. It does add another layer of NAT, but it may be unavoidable in this case.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          3 out of 4
          • First post
            3/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received