• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

IP Alias // HA Cluster // Failover not working

Scheduled Pinned Locked Moved HA/CARP/VIPs
5 Posts 4 Posters 5.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • H
    henrik_meyer
    last edited by Jul 29, 2016, 3:30 PM Jul 29, 2016, 1:53 PM

    Hi,

    I have 2 pfSense version 2.3.2 in a simple HA/Cluster setup.

    LAN:
    pfSense-01: 192.168.1.2/24 // Primary
    pfSense-02: 192.168.1.3/24 // Secondary
    LAN-CARP: 192.168.1.1/24

    I have added VIP "IP Alias" 100.64.1.1/32 to interface "localhost"on the primary, and that has replicated to the secondary.

    With both pfSense-01 and pfSense-02 running:
    From a PC Client I can ping 100.64.1.1
    With a packet capture, I can see that pfSense-01 is replying.

    With pfsense-01 shutdown and pfSense-02 running:
    From a PC client I can no longer ping 100.64.1.1
    With a packet capture, I can see the echo-request on pfSense-02 but it is not replying.

    With pfsense-01 running and pfSense-02 shutdown:
    From a PC Client I can ping 100.64.1.1
    With a packet capture, I can see that pfSense-01 is replying.

    In all three (3) tests LAN-CARP 192.168.1.1 is replying just fine.

    Have I run into a bug regarding IP Alias on localhost and failover?

    Thanks in advance

    regards
    Henrik Meyer, Denmark

    1 Reply Last reply Reply Quote 0
    • H
      henrik_meyer
      last edited by Jul 29, 2016, 3:28 PM

      New discovery

      When it does not work on pfSense-02, that should answer the request, but is not doing so.
      pfSense-02 is actually forwarding the packet to pfSense-01 - who is offline..

      What the f***

      Is "IP Alias" on localhost interface not suppose to failover?

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by Jul 30, 2016, 11:16 AM

        @henrik_meyer:

        I have added VIP "IP Alias" 100.64.1.1/32 to interface "localhost"on the primary, and that has replicated to the secondary.

        Why to localhost??? What's your intention?

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Aug 4, 2016, 5:44 PM

          They should failover fine, assuming your routing and other aspects of the config are OK.

          What exactly do you mean by "pfSense-02 is actually forwarding the packet to pfSense-01"?

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • N
            Nrador007
            last edited by Oct 6, 2016, 5:06 AM

            Failover Groups I can not work like this allows me to answer.

            ibcbet

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received