Dual VRRP Links cause CARP to fail - IGMP Related?



  • Hello all,

    I'm finishing a new deployment and I'm a bit stumped by an issue w/ VRRP.

    I have two PFSense firewalls in an HA cluster using CARP. Each firewall has it's own Adtran 1534 switch and each switch has a one uplink to our data center provider using VRRP. LAN and WAN are segmented using vlans. Failover works perfectly.

    When both VRRP uplinks are connected (one to each switch), my WAN drops. I'm currently operating with one uplink until I figure out how to get both of them to play nicely. I read that it might be the switches not handling multicast correctly and I may need to make a change to IGMP snooping on the vlan used for WAN traffic.

    I've deployed several of these PFSense clusters and identical topology switching with uplinks using HSRP, hasn't been an issue before. Any ideas?

    Thanks in advance!


  • Netgate

    Same VHID on the CARP VIP and the VRRP?

    Though that should blow up with only one link due to the identical MAC addresses.

    I would pcap on both nodes for CARP and connect both and see what's really happening.