Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    CARP failover and VLAN addition

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    4 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      ttanemori
      last edited by

      We will start using pfSense with CARP failover and 10 VLANs. After I put it under production environment, what could happen if I add another VLAN on the primary node?

      This is what I am thinking.

      1. Add a new VLAN on the primary node
      2. Create a new virtual IP for the VLAN I created
      3. Configure DHCP server
      4. Configure NAT rule for outbound (WAN IP –> WAN CARP IP)

      At the step #3, I think I need to enter the IP of the VLAN gateway on the backup node. Basically, if I want to add a new VLAN, do I have to log on to both devices?

      Or, if this kind of change may be risky, should I just made a enough number of VLAN in advance?

      Thank you.

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        VLANs and other interface configurations are not synchronized to the backup pfSense. The other configurations you need will be if the CARP setup is made accordingly.

        VIPs must be defined as IP Alias an must hook up on a CARP interface address to function and be synchronized to backup.

        Nevertheless, it is no risky to make this later when you need it.

        1 Reply Last reply Reply Quote 0
        • T Offline
          ttanemori
          last edited by

          Thank you very much.

          1 Reply Last reply Reply Quote 0
          • dotdashD Offline
            dotdash
            last edited by

            @viragomann:

            VIPs must be defined as IP Alias an must hook up on a CARP interface address to function and be synchronized to backup.

            Not sure what you mean by this. I add VLAN interfaces to CARP clusters regularly and you don't have to do anything with IP Aliases.
            The procedure is roughly-
            Configure your switches with the new VLAN.
            Create the vlan on both primary and secondary.
            Assign the new vlan to a new interface, again on both primary and secondary.
            Configure the new interface on both boxes- eg: primary 10.20.30.2 secondary 10.20.30.3
            From now on, you just need to configure the primary:
            Add a new CARP VIP (eg 10.20.30.1), configure the OB nat, firewall rules, etc.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.