Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Client cant reach internet under HA

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    12 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      viragomann
      last edited by

      Have you set the WAN VIP in the outbound NAT?

      1 Reply Last reply Reply Quote 0
      • L Offline
        Lon Townsend
        last edited by

        yes.

        1 Reply Last reply Reply Quote 0
        • DerelictD Offline
          Derelict LAYER 8 Netgate
          last edited by

          Well, what is actually failing? Diagnose that and fix it.

          https://doc.pfsense.org/index.php/Connectivity_Troubleshooting

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • L Offline
            Lon Townsend
            last edited by

            Here is an idea. If we have a physical public IP of .13 in use and we try using a virtual public IP of .13, will there be a conflict at the modem?

            1 Reply Last reply Reply Quote 0
            • DerelictD Offline
              Derelict LAYER 8 Netgate
              last edited by

              Depends on the modem and the ISP provisioning, bro.

              Proper HA needs at least a /29 and good layer 2 between the two WAN interfaces and the ISP gateway.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • L Offline
                Lon Townsend
                last edited by

                we have a /28 so no issue there. But we are trying to test this on an already established network where IPs might be in use on another device. .13 is a single firewall(public IP), in use, and we are trying to use .13 as WAN VIP for this HA lab. We are thinking IP conflict at the modem.

                1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  Well yeah you can only have one device on .13

                  If you set the two interfaces and can ping .13 without making a VIP for it you need to use something else.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • M Offline
                    moh10ly
                    last edited by

                    I have the exact same issue. Tried different public IPs for WAN VIP! Set the clients to use the LAN VIP and set the Outbound NAT but no matter what Clients never connect to the internet.

                    Pfsense versions are 2.4.2-RELEASE-p1
                    Carp is working well, sync is good and there are no errors in the logs.
                    My only issue is clients are not getting internet when I setup Manual Outbound NAT.

                    Power is Knowledge.

                    1 Reply Last reply Reply Quote 0
                    • DerelictD Offline
                      Derelict LAYER 8 Netgate
                      last edited by

                      This is not a guessing game. You need to know what addresses you have available.

                      You need to be able to generate traffic from the CARP VIP on the node that currently holds MASTER and get proper responses to the CARP MAC address from the ISP. This requires them doing the correct thing with both the CARP traffic (adds the CARP MAC address to the CAM table in their layer 2) and ARP (sets their layer 3 gear to send traffic for the CARP VIP address to the CARP MAC).

                      Diagnostics > Ping source from the CARP VIP and ping things on the outside like 8.8.8.8, the ISP gateway, etc.

                      If that works then try Diagnostics > Test Port, again source from the CARP VIP, and connect to something you know should respond like 587 on smtp.gmail.com.

                      If those don't work you need to packet capture and look at everything to see what the ISP is screwing up. Source/Dest MAC addresses, ARP, etc. CARP does not break any rules. Much ISP gear does not play by those rules, however.

                      Look at the generated states. Are they NATting to the proper VIP?

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • M Offline
                        moh10ly
                        last edited by

                        The IP address I placed I am certain of is available and already tried it with RDP on another server. Pinging to 8.8.8.8 from the WAN VIP is not working but from LAN VIP does.

                        Telnet to port 587 didn't work either, I will check the capture of packets to see what's wrong with that it could be the ISP.

                        Thanks

                        Power is Knowledge.

                        1 Reply Last reply Reply Quote 0
                        • DerelictD Offline
                          Derelict LAYER 8 Netgate
                          last edited by

                          It might work fine using an interface address or an IP Alias VIP but not work CARP (using the identical IP address) because of improper handling of the necessary MAC address behavior by something upstream.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.