Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    CARP and user privilege

    HA/CARP/VIPs
    2
    3
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jjavier
      last edited by

      Hello, all!

      I am in the middle of my first CARP setup.  The one thing that I noticed was Remote System Username, if you want to sync configuration settings.

      Security is a biggie in my company, and exposing a(nother) user that seems to require admin privileges doesn't seem very secure.

      Does anyone know the minimum privileges required for the user that can sync configuration between pfsense installation?

      Thanks ahead for your assistance.

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Hi!

        If you use a distinct interface for FW sync as it's suggested there will be no security issue with a user who have admin privileges.

        Furthermore if you have your WebConfigurator set to use HTTPS protocol the sync communication is also encrypted.

        1 Reply Last reply Reply Quote 0
        • J
          jjavier
          last edited by

          Thank you for your reply.

          I am still not sure of the statement about having the distinctive interface - is there a way to bind a user to login only through specific interfaces, that I am unaware of?  As far as I see, a configured user can login through any allowed interface.

          HTTPS is good for encrypting the traffic, but exposing the system to yet another full admin user is what I need to secure.

          If a configured user can login through any interface, it would be nice to know what minimum privileges are needed for the CARP user.

          Thanks ahead of time for your replies.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.