Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Fileover over 2 ESX nodes (Essential)

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    4 Posts 2 Posters 998 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      andmattia
      last edited by

      Hi All

      I try to create an HA solution with my 2 ESX node.

      I test in one node and it's works fine when disconect master switch to slave and back to normal.

      So when I move mani pf o slave pf to other node it's stop to work. My hw is:

      1 node esx DELL SRV with 3 NIC (2 nic connected to different adls, 1 nic connect to lan switch)
      2 node esx DELL SRV with 4 nic (2 nic connected to different adls, 2 nic (team) to lan switch)

      Any experience on that is possible to do that with my current configuration?

      thks

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by

        https://doc.pfsense.org/index.php/PfSense_2_on_VMware_ESXi_5

        https://doc.pfsense.org/index.php/Configuring_pfSense_Hardware_Redundancy_(CARP)

        https://doc.pfsense.org/index.php/CARP_Configuration_Sync_Troubleshooting

        https://doc.pfsense.org/index.php/CARP_Configuration_Troubleshooting

        VMware ESX Users
        Enable promiscuous mode on the vSwitch
        Enable "MAC Address changes"
        Enable "Forged transmits"
        ESX VDS Config
        If a Virtual Distributed Switch is being used, it is possible to make a port group for the firewall interfaces with promiscuous mode enabled, and a separate non-promiscuous portgroup for other hosts. This has been reported to work by users on the forum as a way to strike a balance between the requirements for letting CARP function and for securing client ports.

        1 Reply Last reply Reply Quote 0
        • A Offline
          andmattia
          last edited by

          Hi

          our vmware licensing is Essential and VDS feauture is not available. any suggestion?

          1 Reply Last reply Reply Quote 0
          • KOMK Offline
            KOM
            last edited by

            Don't pay attention to the VDS Config part?  These are the important bits:

            • Enable promiscuous mode on the vSwitch

            • Enable "MAC Address changes"

            • Enable "Forged transmits"

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.