Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    CARP, HA, pfsense, and Switches

    Scheduled Pinned Locked Moved L2/Switching/VLANs
    carpm4300sg350
    11 Posts 4 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      netblues @purduephotog
      last edited by

      @purduephotog said in CARP, HA, pfsense, and Switches:

      SG350

      Can you please elaborate on where exactly the managed switch make or sw comes into play as far as carp on pf is concerned? Runs everywhere from unmanaged to cheap switches with no issues.

      P 2 Replies Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Just tell them it's VRRP, not CARP. If it works for VRRP, it'll work with CARP.

        Please let me know when Cisco says their switches don't support VRRP.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • P
          purduephotog @netblues
          last edited by

          @netblues I'm going to be putting pf into the mix as well, and be setting it up for CARP. Since I've lost a ton of time on this and am getting really contradicting info, I'm trying to figure out which sweetish I can go buy that will work.

          1 Reply Last reply Reply Quote 0
          • P
            purduephotog @netblues
            last edited by

            @netblues The word from Netgear was "It overloads the CPU and isn't supported". And I've spent a ton of hours trying to figure out why the individual NICs are pingable, but the HA interface isn't. So before I drop another couple of grand on a switch, I want to know what is supported or not.

            S 1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              All it has to support is Multicast and it needs to change the MAC address table based on the CARP advertisements as any switch should. Not really sure what Netgear is talking about. If processing one multicast frame per second per VLAN overloads the CPU you probably don't want that switch anyway.

              Most switches have no issues processing it.

              Some ISP devices with a built-in switch have problems with the multicast, moving the MAC from port to port, etc.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @purduephotog
                last edited by

                @purduephotog said in CARP, HA, pfsense, and Switches:

                before I drop another couple of grand on a switch

                Can you try a cheap "dumb" switch first? We have pfSense HA/CARP setups on a three year old 10 Gbit Netgear at our data center, and at a client that I think is just connecting to the switch in their Comcast router.

                I started to reply about pfSense but it sounds like you are saying your question is actually about different software...

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                P 1 Reply Last reply Reply Quote 0
                • P
                  purduephotog @SteveITS
                  last edited by

                  @teamits said in CARP, HA, pfsense, and Switches:

                  Can you try a cheap "dumb" switch first? We have pfSense HA/CARP setups on a three year old 10 Gbit Netgear at our data center, and at a client that I think is just connecting to the switch in their Comcast router.

                  I'm actually having this problem on a different piece of software, but I intend to put pfSense on it so I'll have the same issue. Which is why I'm trying to figure out what works for pfSense so I can make it work for both.

                  Interesting. I'm trying to get a dumb 10gbe switch but they don't exist. I might just go grab a cheap one and plug it in.

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS Galactic Empire @purduephotog
                    last edited by

                    @purduephotog said in CARP, HA, pfsense, and Switches:

                    dumb 10gbe switch but they don't exist

                    No they do not. :) I was thinking any old 5 port gigabit switch would work for testing purposes. I think the point we're collectively trying to make is there shouldn't be special requirements for a switch for this to work.

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote ๐Ÿ‘ helpful posts!

                    P 1 Reply Last reply Reply Quote 1
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      Switches have to try pretty hard to break CARP/VRRP.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 1
                      • P
                        purduephotog @SteveITS
                        last edited by

                        @teamits yeah. It should just work. It doesn't tho... And it's really messing up my holiday giving spirit.

                        I should've just did it all myself. No outside vendor. Sigh.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.