• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

CARP and High Availability Sync

Scheduled Pinned Locked Moved General pfSense Questions
3 Posts 3 Posters 660 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    cjdavis4
    last edited by Oct 11, 2017, 7:02 PM

    I am running two pfSense routers in a failover setup. During the installation process of my secondary router last week, I tested to make sure that the failover worked by turning off my primary and seeing if the secondary became the master. It did and internet was working just fine.

    Something that I have noticed this week, however, is that the two routers are not syncing to each other. I know this because there are some NAT rules on the primary router that are not on the secondary despite the High Availability Sync having the settings for NAT sync turned on. This is my first dance with failover routers. I have tried following the guides on the docs.pfsense.org site to set up CARP and High Availability Sync but something is still missing.

    I am using this guide to help me set things up: https://doc.pfsense.org/index.php/Configuring_pfSense_Hardware_Redundancy_(CARP)

    Please let me know what I am doing wrong. I know that the IPs and passwords are correct as I have triple checked both. Thank you.

    HAS1.PNG
    HAS1.PNG_thumb
    HAS2.PNG
    HAS2.PNG_thumb
    SYNC.PNG
    SYNC.PNG_thumb

    1 Reply Last reply Reply Quote 0
    • P
      PiBa
      last edited by Oct 11, 2017, 7:43 PM

      What foes it tell in the systemlogs?
      Does webgui of backup work properly?
      Or in the menu try: status/filterreload/force sync
      Or try to curl the webgui of the backupbox from the primary console?
      On backup the "Synchronize Config to IP" must be empty.

      1 Reply Last reply Reply Quote 0
      • D
        Derelict LAYER 8 Netgate
        last edited by Oct 11, 2017, 7:46 PM

        Can you ping the secondary's sync address from the primary?

        Firewall rules on the secondary allow webgui traffic?

        When you make changes on the primary are you getting alerts that the sync to the secondary had problems?

        Anything in the System log?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received