Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HA Sync breaks after restoring configuration

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    15 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stephenw10S
      stephenw10 Netgate Administrator
      last edited by

      Hmm, well I agree that 20 users is not that many and I wouldn't expect any issue there.

      However as a test try disabling the user sync from the xmlrpc settings on the primary.

      The actual issue there though is the time the secondary takes to re-build the users file from the config and that still applies I believe.

      Steve

      1 Reply Last reply Reply Quote 0
      • R
        redarmy123
        last edited by

        I only have the Users checked for syncing. I disabled it, and I do not see any errors relating to XMLRPC but that's because there isn't anything to sync but that at least rules out authentication issues etc.

        To test further, I checked only the Firewall Aliases as a test, but still get the "New alert found: A communications error occurred while attempting Filter sync with username admin" error.

        I've also changed the password disabled the sync on both machines and changed the password for the admin account and reenabled the sync, which synced fine once and failed again.

        I'm out of ideas!

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          And you did not see 504/502 errors on the secondary GUI at that time?

          Steve

          1 Reply Last reply Reply Quote 0
          • R
            redarmy123
            last edited by

            The 504 error doesn't happen all the time. The sync fails even when the GUI is responding on the second firewall.

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Hmm, it still looks like a timing issue to me from the initial logs though it's unclear what the cause is. Do you still see that same 1m delay on the primary? Nothing obviously logged as an error on the secondary?

              Steve

              1 Reply Last reply Reply Quote 0
              • R
                redarmy123
                last edited by

                In the end, I restored most of the existing config apart from the users. That seemed to work ok.

                I also restored the DHCP section which contains a lot of static mappings for a few interfaces. Once I restored this, sync broke which I guess it's taking too long to sync. I removed all static mappings and syncing worked again!

                Can I increase this default timeout period to something higher than 60 seconds?

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  There is no easy way to increase it though I believe it could be done. However you should not normally need to.

                  How many static mappings do you have? What size is your config file?

                  Steve

                  1 Reply Last reply Reply Quote 0
                  • R
                    redarmy123
                    last edited by

                    There are 186 mappings. The config xml file is 1.8MB

                    1 Reply Last reply Reply Quote 0
                    • R
                      redarmy123
                      last edited by

                      I restored the dhcp mappings again and the sync works.

                      Where it breaks is very inconsistent and makes it hard to troubleshoot. As of now, the config is complete (except with users and certificates)

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        Syncing a number of users can slow it down drastically. This is known and something we plan to address shortly: https://redmine.pfsense.org/issues/7469

                        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.