Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Client cant reach internet under HA

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    12 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L Offline
      Lon Townsend
      last edited by

      1. gateway is online
      2. physical wan/lan is active
      3. virtual wan/lan is active
      4. Lan not offering dhcp.
      5. client statically assigned ip, gateway is Virtual LAN.
      6. DNS is quad 8s and quad 75s

      Why does getting to the internet from client have to be sooo dang difficult.

      HELP

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann
        last edited by

        Have you set the WAN VIP in the outbound NAT?

        1 Reply Last reply Reply Quote 0
        • L Offline
          Lon Townsend
          last edited by

          yes.

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            Well, what is actually failing? Diagnose that and fix it.

            https://doc.pfsense.org/index.php/Connectivity_Troubleshooting

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • L Offline
              Lon Townsend
              last edited by

              Here is an idea. If we have a physical public IP of .13 in use and we try using a virtual public IP of .13, will there be a conflict at the modem?

              1 Reply Last reply Reply Quote 0
              • DerelictD Offline
                Derelict LAYER 8 Netgate
                last edited by

                Depends on the modem and the ISP provisioning, bro.

                Proper HA needs at least a /29 and good layer 2 between the two WAN interfaces and the ISP gateway.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • L Offline
                  Lon Townsend
                  last edited by

                  we have a /28 so no issue there. But we are trying to test this on an already established network where IPs might be in use on another device. .13 is a single firewall(public IP), in use, and we are trying to use .13 as WAN VIP for this HA lab. We are thinking IP conflict at the modem.

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate
                    last edited by

                    Well yeah you can only have one device on .13

                    If you set the two interfaces and can ping .13 without making a VIP for it you need to use something else.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      moh10ly
                      last edited by

                      I have the exact same issue. Tried different public IPs for WAN VIP! Set the clients to use the LAN VIP and set the Outbound NAT but no matter what Clients never connect to the internet.

                      Pfsense versions are 2.4.2-RELEASE-p1
                      Carp is working well, sync is good and there are no errors in the logs.
                      My only issue is clients are not getting internet when I setup Manual Outbound NAT.

                      Power is Knowledge.

                      1 Reply Last reply Reply Quote 0
                      • DerelictD Offline
                        Derelict LAYER 8 Netgate
                        last edited by

                        This is not a guessing game. You need to know what addresses you have available.

                        You need to be able to generate traffic from the CARP VIP on the node that currently holds MASTER and get proper responses to the CARP MAC address from the ISP. This requires them doing the correct thing with both the CARP traffic (adds the CARP MAC address to the CAM table in their layer 2) and ARP (sets their layer 3 gear to send traffic for the CARP VIP address to the CARP MAC).

                        Diagnostics > Ping source from the CARP VIP and ping things on the outside like 8.8.8.8, the ISP gateway, etc.

                        If that works then try Diagnostics > Test Port, again source from the CARP VIP, and connect to something you know should respond like 587 on smtp.gmail.com.

                        If those don't work you need to packet capture and look at everything to see what the ISP is screwing up. Source/Dest MAC addresses, ARP, etc. CARP does not break any rules. Much ISP gear does not play by those rules, however.

                        Look at the generated states. Are they NATting to the proper VIP?

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • M Offline
                          moh10ly
                          last edited by

                          The IP address I placed I am certain of is available and already tried it with RDP on another server. Pinging to 8.8.8.8 from the WAN VIP is not working but from LAN VIP does.

                          Telnet to port 587 didn't work either, I will check the capture of packets to see what's wrong with that it could be the ISP.

                          Thanks

                          Power is Knowledge.

                          1 Reply Last reply Reply Quote 0
                          • DerelictD Offline
                            Derelict LAYER 8 Netgate
                            last edited by

                            It might work fine using an interface address or an IP Alias VIP but not work CARP (using the identical IP address) because of improper handling of the necessary MAC address behavior by something upstream.

                            Chattanooga, Tennessee, USA
                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.