Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    CARP with 1 WAN IP

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    13 Posts 4 Posters 6.3k Views 1 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • dotdashD Offline
      dotdash
      last edited by

      Sounds about right, but I would use more specific NAT rules. Mine are something like-
      WAN 'This Firewall' * * * (Public carp VIP) * (no static)
      WAN (lan subnet) * * * (Public carp VIP) * (no static)

      1 Reply Last reply Reply Quote 0
      • S Offline
        sagaroth
        last edited by

        I applied this same configuration to my NAT.
        My Gateway remains offline on my master, I have restarted, as you advised me, the dpinger service but the logs return a no route to host. This Gateway is however well configured and is applied as the default Gateway.
        (I've enabled the promiscious mode in my vswitch)

        1 Reply Last reply Reply Quote 0
        • dotdashD Offline
          dotdash
          last edited by

          @sagaroth:

          My Gateway remains offline on my master, I have restarted, as you advised me, the dpinger service but the logs return a no route to host.

          Try, from Diagnostics / Ping, selecting the Public CARP VIP as the source address, and pinging the gateway.
          Just to verify, subnet mask on the CARP VIP is correct and gateway is reachable from that subnet?

          1 Reply Last reply Reply Quote 0
          • S Offline
            sagaroth
            last edited by

            The ping doesn't work even if I put the CARP VIP as a source.
            After verification, the subnet mask of my CARP VIP is correct.
            My gateway uses this same mask and is in the same network as my VIP CARP.

            1 Reply Last reply Reply Quote 0
            • S Offline
              sagaroth
              last edited by

              I added my VIP LAN CARP today that I configured like this:

              IP LAN PFsense1:10.10.10.10.252/24
              IP LAN PFsense2:10.10.10.10.253/24
              VIP LAN: 10.10.10.10.254/24

              What surprises me is that this VIP CARP is not reachable from my LAN network (A Virtual Machine in 10.10.10.61).

              1 Reply Last reply Reply Quote 0
              • dotdashD Offline
                dotdash
                last edited by

                @sagaroth:

                (I've enabled the promiscious mode in my vswitch)

                Any way you can test with a physical setup to rule out the hypervisor config? Honestly sounds like something is up with the vswitch if you can't ping each box from the vmnetwork…

                1 Reply Last reply Reply Quote 0
                • S Offline
                  sagaroth
                  last edited by

                  I also think there is a problem with the hypervisor, because my WAN connection works perfectly without CARP.
                  Unfortunately I don't have the possibility to physically test this configuration because this hypervisor is hosted at OVH.

                  1 Reply Last reply Reply Quote 0
                  • O Offline
                    oeawallis
                    last edited by

                    @dotdash:

                    Sounds about right, but I would use more specific NAT rules. Mine are something like-
                    WAN 'This Firewall' * * * (Public carp VIP) * (no static)
                    WAN (lan subnet) * * * (Public carp VIP) * (no static)

                    Good Morning!

                    I followed the official CARP Tut from Netgate Wiki and also yours (dotdash).

                    I am using 2.4.2-RELEASE Version on supermicro servers (2 identical machines), now i can succesfully Ping the WAN-CARP-VIP (193.xy.x.y.), the LAN-CARP-VIP (172.16.x.y) from INSIDE my LAN.
                    Pinging my client (172.16.x.30) form pfsense to LAN is also possible.

                    How can I prove that the CARP is working correctly? Especially I suffer from not being able to ping any IP outside (WAN-IP-range). NAT-Rules are set like dotdash's, reboots took place too. pinging devices on WAN is messing up with "Request timeout" on Windows - Client, and on PF with "ping: sento: Host is down"

                    Would be more then nice if you could help me out of this! Have a nice day and greetings from Austria

                    1 Reply Last reply Reply Quote 0
                    • dotdashD Offline
                      dotdash
                      last edited by

                      You can't ping from a machine on the LAN, or from the firewalls? Not being able to ping outside from the secondary is normal.
                      Best way to test HA is to shut down the primary during a slow time, and verify machines on the LAN can still get out.

                      1 Reply Last reply Reply Quote 0
                      • M Offline
                        markieparkie
                        last edited by

                        To get around the hassle of this setup, much like my own you can always do the following:

                        • Virtual side make the vNICS MAC for both boxes the same for the WAN interface.

                        I use a termination box in front of mine for VDSL and a switch before it goes into the virtual environment.

                        That's pritty much it. Will work, but note it will show as up on both boxes for WAN interface and the WAN graph will look a little odd on the standby box as expected.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.