• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Routing problem in secondary CARP node

Scheduled Pinned Locked Moved HA/CARP/VIPs
5 Posts 2 Posters 1.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    rubenc
    last edited by Feb 22, 2017, 11:39 AM

    Hi,

    Regular CARP setup, 2.3.2 on both nodes.

    The problem is the secondary (inactive) node has no internet access, despite having the routing setup exactly as the primary (active) node.

    Primary fw WAN is 77.X.X.2, secondary fw WAN is 77.X.X.3, and gateway for both of them is 77.X.X.1

    After reviewing stuff, I don't know what I'm missing. Any ideas?

    Thanks a lot,

    Rubén.

    Hardware: SC1935 | WAN: em (PCIe) | LAN: bge (onboard) | RAM: 2Gb
    2.0-RC2-IPv6 (i386)
    built on Sat May 21 21:38:32 EDT 2011

    1 Reply Last reply Reply Quote 0
    • V
      viragomann
      last edited by Feb 22, 2017, 12:18 PM

      What are your outbound NAT rules?

      1 Reply Last reply Reply Quote 0
      • R
        rubenc
        last edited by Feb 22, 2017, 1:19 PM

        AON with the "any" rule using a specific public IP (77.X.X.4) bounded to the primary firewall as NAT Address.

        Ok so. In fact the "any" rule was missing in slave (I suppose it wasn't automatically created due to 77.X.X.4 not being active in secondary), so I created one using as NAT Address the WAN's Interface Address (77.X.X.3) as I understand I can't use 77.X.X.4 on the secondary node since it's only active in the primary. In this way, Internet connectivity works.

        But then I guess in the event of a failover I'll have to manually change the outgoing IP from 77.X.X.3 to 77.X.X.4 right?

        Thanks!

        Hardware: SC1935 | WAN: em (PCIe) | LAN: bge (onboard) | RAM: 2Gb
        2.0-RC2-IPv6 (i386)
        built on Sat May 21 21:38:32 EDT 2011

        1 Reply Last reply Reply Quote 0
        • V
          viragomann
          last edited by Feb 22, 2017, 1:46 PM

          The outbound traffic from all other devices than pfSense should be use the CARP VIP. Only the traffic from the pfSense box itself (127.0.0.0/8) should use the WAN address.
          That is valid for both boxes and can be synced from one to the other.

          A failover is no problem with this settings.

          1 Reply Last reply Reply Quote 0
          • R
            rubenc
            last edited by Feb 22, 2017, 3:39 PM

            Thanks viragomann  ;)

            Hardware: SC1935 | WAN: em (PCIe) | LAN: bge (onboard) | RAM: 2Gb
            2.0-RC2-IPv6 (i386)
            built on Sat May 21 21:38:32 EDT 2011

            1 Reply Last reply Reply Quote 0
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received