Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    CARP - NAT

    HA/CARP/VIPs
    3
    6
    958
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      khancock last edited by

      The CARP docs state to use Manual Outbound NAT and warns against NAT rules for "WAN/Public IP addresses of the cluster".  Does that include any public IP configured as a CARP IP on WAN?  Any issues using Hybrid NAT?

      https://doc.pfsense.org/index.php/Configuring_pfSense_Hardware_Redundancy_(CARP)#Setup_Manual_Outbound_NAT

      1 Reply Last reply Reply Quote 0
      • Derelict
        Derelict LAYER 8 Netgate last edited by

        You just need to make sure that all outbound NAT (and inbound connections/port forwards, VPN bindings, etc) are on addresses that will swing between the nodes in a CARP event.

        These can be CARP VIPs or IP Aliases riding on CARP VIPs. If you have a subnet routed to one of those, that will also work.

        If you terminate connections on the interface address, that address will only exist on one node not the other so if there is a failover event, the pfsynced state on the other node will be invalid and the connection will die.

        Chattanooga, Tennessee, USA
        The pfSense Book is free of charge!
        DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • K
          khancock last edited by

          Makes sense!  Thanks!  I read that to say that Hybrid NAT will not work since it auto-creates rules.  My CARP backup node has been crashing (unresponsive), I suspect this is the culprit.

          1 Reply Last reply Reply Quote 0
          • Derelict
            Derelict LAYER 8 Netgate last edited by

            You can use Hybrid if you want, but you still have to override all of the auto rules. It makes sense to get all of your interfaces configured, then switch to manual NAT so all the rules are automatically generated for you. Then just flip them all to an appropriate VIP.

            Chattanooga, Tennessee, USA
            The pfSense Book is free of charge!
            DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • O
              oeawallis last edited by

              @Derelict:

              You can use Hybrid if you want, but you still have to override all of the auto rules. It makes sense to get all of your interfaces configured, then switch to manual NAT so all the rules are automatically generated for you. Then just flip them all to an appropriate VIP.

              if i set my pfsense into Hybrid NAT using CARP the machine is frozen and has to be hard reseted!
              I also suffer strange behaviour using CARP and NATing
              -> https://forum.pfsense.org/index.php?topic=137984.0

              1 Reply Last reply Reply Quote 0
              • Derelict
                Derelict LAYER 8 Netgate last edited by

                Then you are doing it wrong somehow.

                Chattanooga, Tennessee, USA
                The pfSense Book is free of charge!
                DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post