Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Carp failover - pfsense 2.2.6

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    10 Posts 3 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      leonardo.silva311290
      last edited by

      I have two servers of the pfsense with version 2.2.6, and i try to do a redundancy carp failover both them.

      I tried to do the carp failover and I discover some possible bugs how for example:

      I have six interfaces in the two firewall's in with static IP both them, so when i applied the carp FAILOVER.
      I have to renew the Ip wan INTERFACE to continue the navigation by the internet

      The same behavior occurs to tre others interfaces.

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        You're trying to CARP a DHCP WAN interface? I don't think that's supported at all. Get a static /29.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • L
          leonardo.silva311290
          last edited by

          Hi, thank you for reply,

          I don't use DHCP in wan interface, In all my interfaces I use static IP.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            I have to renew the Ip wan INTERFACE to continue the navigation by the internet

            Then I guess I don't know what this means.

            Example:

            .1 CARP
            .2 Primary interface
            .3 Secondary interface

            The HA node that is MASTER responds on .1

            It all works fine.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • C
              cmb
              last edited by

              @Derelict:

              I have to renew the Ip wan INTERFACE to continue the navigation by the internet

              Then I guess I don't know what this means.

              My guess, has one IP statically configured on WAN and same on both systems, so has an IP conflict. The gratuitous ARP from the save and apply on WAN ("renew") temporarily "fixes" (read: wins the secondary the IP conflict for the time being).

              Can't put the same IP on multiple systems.

              1 Reply Last reply Reply Quote 0
              • L
                leonardo.silva311290
                last edited by

                Hi cmb,

                Thank you for reply,  in my case, i am not the same Ip in the wan interface i  am try the follow configurartion for wan interface

                pfsense one –> x.x.159.247
                pfsense one --> x.x.159.243
                Ip carp interface wan --> x.x.159.242

                When I try to apply the failover in the interface, i have this problem type.

                Obs: I am an Autonomo System and the gateway of my wan interface is an hsrp that i have both two routers with BGP

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  I am not aware of any bugs in CARP.

                  About the only thing I can think to suggest you check is for another CARP/VRRP setup on the same subnet with the same VHID? Maybe the other side isn't really HSRP but is VRRP and you're both using 1 or n?

                  A look at the ARP cache might tell a story.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • L
                    leonardo.silva311290
                    last edited by

                    Hi Derelict,

                    Thank for reply,

                    I am using HSRP both two routers BGP, I am conected in two diferent's autonomo systems.
                    The first that  I Applied the carp Failover, I can applied, but when I was tested, Turn off the primary firewall to the secondary firewall
                    become the primary firewall.

                    I see very problems with the cache of the Ip's in my interfaces. For exemple, In my all the interfaces I am using static Ip's
                    And after the time, I had to renew the Ip of the WAN interface, because I can not go out to wan.

                    I am not to understand this behavior

                    After the I had to renew the Ip of my wan interface to continue go out to wan.

                    Complementing, I made the carp in my firewall that have six interfaces, I made in all the interfaces.

                    Best Regargs.

                    1 Reply Last reply Reply Quote 0
                    • C
                      cmb
                      last edited by

                      You have to NAT your outbound traffic to a CARP IP. Not clear whether or not that's the case. Otherwise all your existing connections will be dead because they're trying to use the primary's WAN IP which doesn't exist on the secondary.

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Yeah it's probably time to post your Firewall > Virtual IPs, Firewall > NAT, Outbound screens.

                        And you don't have to power down the primary to test. Just temporarily disable CARP on Status > CARP for basic functionality testing.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.