Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    High network traffic on secondary firewall when CARP in BACKUP mode

    HA/CARP/VIPs
    2
    5
    2.2k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rkelleyrtp
      last edited by

      Greetings,

      Upgraded from 2.2.6 to 2.3.2 and am seeing a very bizarre issue.  I have a pair of 2.3.2 pfSense VMs running on ESXi 5.5U2.  For some reason, the secondary/standby firewall is seeing very high network traffic on the WAN interface ( >50Mb/sec) when the CARP interfaces are in BACKUP mode.  As soon as I disable CARP the traffic goes to 1KB each direction (as it should).  Once I re-enable CARP, the unit goes to BACKUP and the high traffic continues.  After some time, I get "em1 watchdog timeout" on the console and have to reboot the appliance (running on ESXi 5.5).  It appears the secondary firewall is responding to traffic (as per the traffic graphs).  Yet, all the CARP interfaces are active on the primary firewall.

      I have not seen this behavior in 2.2.6.  Any clues on how to troubleshoot?

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Packet capture on the secondary WAN and see what the traffic is?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • R
          rkelleyrtp
          last edited by

          Thanks for the quick reply.

          Packet capture on the WAN interface indicates the secondary firewall is processing traffic for the VIPs.  I see a ton of VIP-to-internet traffic.  Why is the secondary firewall is responding to VIP traffic at all if it is in BACKUP mode?

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Is it responding to traffic or being sent the traffic? In all honesty this is probably something in your ESXi environment and not your HA pair.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • R
              rkelleyrtp
              last edited by

              In a last ditch effort to get things running again, I blew reset the config on FW2 and started over.  Since this is an HA pair, I just did the initial setup and had FW1 sync over the settings.  This seems to have fixed the problem.  The secondary FW is in BACKUP mode and the traffic is very minor (16KB/sec).

              Not sure what happened, but something must have gone wrong during the upgrade from 2.2.6 to 2.3.2.  I might consider doing the same on FW1 (reset to factory then sync from FW2).

              Thanks again for helping out!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.