Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Going from single to redundant wan lines

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    12 Posts 3 Posters 4.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      SeventhSon
      last edited by

      You need, per firewall:

      1 NIC per WAN
      1 SYNC interface
      1 LAN

      So in your case, unless you want to include a VLAN switch, you need 3 NICs per firewall.

      (you only have one WAN, split between 2 cables, right?)

      1 Reply Last reply Reply Quote 0
      • W Offline
        Woger
        last edited by

        Sorry SeventhSon,
        I was away last week.
        Yes, I only have one WAN split into 2 cables (redundant).

        Thanks,

        Roger

        1 Reply Last reply Reply Quote 0
        • S Offline
          SeventhSon
          last edited by

          3 should do so. I'd go for the Intel NICs btw :)

          1 Reply Last reply Reply Quote 0
          • W Offline
            Woger
            last edited by

            Well, the 2 standard nics are intel but the 3rd one is realtek, but this one is used for carp. Do you have carp working with bridged pfsense machines?

            1 Reply Last reply Reply Quote 0
            • S Offline
              SeventhSon
              last edited by

              I'm using it on routed pfSense machines, but on current 2.0.3 running CARP on a bridged interface doesn't work, if that's what you're asking.

              1 Reply Last reply Reply Quote 0
              • W Offline
                Woger
                last edited by

                Well I got the other machine working now (took a while to get the hardware).
                What I need is 2 bridged machines working together. I have several machines with public IP adresses on the inside and the gateway on the outside. The lan port has a public IP address also but the wan doesn't have an IP address. As I have now 2 internet uplinks I need both machines to do firewalling. But I just want to maintain only one.

                Thanks,

                Roger

                1 Reply Last reply Reply Quote 0
                • W Offline
                  Woger
                  last edited by

                  OK,
                  Ik didn't enable CARP but only pfsync. This worked well, so pfsense1 updates pfsense2. So this morning I put them both in but it resulted in very strange problems. From home everything worked, but from my office we couldn't reach the network. from my phone I couldn't open any website but could ping the server. I had to take the pfsense machines out of the network  :(.
                  Any ideas?

                  1 Reply Last reply Reply Quote 0
                  • W Offline
                    Woger
                    last edited by

                    Nobody a clue? I think this must be possible.

                    I hope, I am not stuck with two €400 bricks  :(

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      MLIT
                      last edited by

                      The problem is CARP is meant to do fail-over for layer 3, not for layer 2 (Which is what you are wanting because you are using PFSense as a bridge, not a router).

                      Do you have a managed switch? Can it do spanning-tree protocol? If so, configure the switch(es) to do spanning tree. Then plug both PFsense boxes to the switch and then to the lines from your ISP. STP will see the redundant lines between the PFSense boxes as a loop and block all traffic on one of the ports.

                      Something else to consider. Fail-over on STP is about 50 seconds.

                      1 Reply Last reply Reply Quote 0
                      • W Offline
                        Woger
                        last edited by

                        OK,
                        Thanks,

                        I am going to try this.

                        Roger

                        1 Reply Last reply Reply Quote 0
                        • W Offline
                          Woger
                          last edited by

                          lHmm..
                          I suddenly realized the ISP told me to be sure that the vrrp routers could see each other using my network. So if stp blocks one port, vrrp will no see the other router. It is btw a Dell 3348.

                          Greetings,
                          Roger

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.