Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    CARP and High Availability Sync

    General pfSense Questions
    3
    3
    535
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cjdavis4 last edited by

      I am running two pfSense routers in a failover setup. During the installation process of my secondary router last week, I tested to make sure that the failover worked by turning off my primary and seeing if the secondary became the master. It did and internet was working just fine.

      Something that I have noticed this week, however, is that the two routers are not syncing to each other. I know this because there are some NAT rules on the primary router that are not on the secondary despite the High Availability Sync having the settings for NAT sync turned on. This is my first dance with failover routers. I have tried following the guides on the docs.pfsense.org site to set up CARP and High Availability Sync but something is still missing.

      I am using this guide to help me set things up: https://doc.pfsense.org/index.php/Configuring_pfSense_Hardware_Redundancy_(CARP)

      Please let me know what I am doing wrong. I know that the IPs and passwords are correct as I have triple checked both. Thank you.






      1 Reply Last reply Reply Quote 0
      • P
        PiBa last edited by

        What foes it tell in the systemlogs?
        Does webgui of backup work properly?
        Or in the menu try: status/filterreload/force sync
        Or try to curl the webgui of the backupbox from the primary console?
        On backup the "Synchronize Config to IP" must be empty.

        1 Reply Last reply Reply Quote 0
        • Derelict
          Derelict LAYER 8 Netgate last edited by

          Can you ping the secondary's sync address from the primary?

          Firewall rules on the secondary allow webgui traffic?

          When you make changes on the primary are you getting alerts that the sync to the secondary had problems?

          Anything in the System log?

          Chattanooga, Tennessee, USA
          The pfSense Book is free of charge!
          DO NOT set a source port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post