Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    IP Alias // HA Cluster // Failover not working

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    5 Posts 4 Posters 5.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      henrik_meyer
      last edited by

      Hi,

      I have 2 pfSense version 2.3.2 in a simple HA/Cluster setup.

      LAN:
      pfSense-01: 192.168.1.2/24 // Primary
      pfSense-02: 192.168.1.3/24 // Secondary
      LAN-CARP: 192.168.1.1/24

      I have added VIP "IP Alias" 100.64.1.1/32 to interface "localhost"on the primary, and that has replicated to the secondary.

      With both pfSense-01 and pfSense-02 running:
      From a PC Client I can ping 100.64.1.1
      With a packet capture, I can see that pfSense-01 is replying.

      With pfsense-01 shutdown and pfSense-02 running:
      From a PC client I can no longer ping 100.64.1.1
      With a packet capture, I can see the echo-request on pfSense-02 but it is not replying.

      With pfsense-01 running and pfSense-02 shutdown:
      From a PC Client I can ping 100.64.1.1
      With a packet capture, I can see that pfSense-01 is replying.

      In all three (3) tests LAN-CARP 192.168.1.1 is replying just fine.

      Have I run into a bug regarding IP Alias on localhost and failover?

      Thanks in advance

      regards
      Henrik Meyer, Denmark

      1 Reply Last reply Reply Quote 0
      • H
        henrik_meyer
        last edited by

        New discovery

        When it does not work on pfSense-02, that should answer the request, but is not doing so.
        pfSense-02 is actually forwarding the packet to pfSense-01 - who is offline..

        What the f***

        Is "IP Alias" on localhost interface not suppose to failover?

        1 Reply Last reply Reply Quote 0
        • V
          viragomann
          last edited by

          @henrik_meyer:

          I have added VIP "IP Alias" 100.64.1.1/32 to interface "localhost"on the primary, and that has replicated to the secondary.

          Why to localhost??? What's your intention?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            They should failover fine, assuming your routing and other aspects of the config are OK.

            What exactly do you mean by "pfSense-02 is actually forwarding the packet to pfSense-01"?

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • N
              Nrador007
              last edited by

              Failover Groups I can not work like this allows me to answer.

              ibcbet

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.