Route Lost by CARP Change



  • Hello,
    I have the problem that one route is always lost. I use a HA system as shown below. The route (red) is permanently entered. The gateway is marked as always active. If I now move the CARP address from Firewall1 to Firewall2 then the route is in Firewall2 without problems. But on Firewall1 the route is already lost. When CARP moves back to Firewall1 the route is still gone. As soon as I click on save in the configuration and apply it again, the route works again.
    Unfortunately, the transfer network from the provider is not big enough to accommodate all IP addresses in it, so I only have the virtual IP address in it.
    Anybody knows this problem? or any solution suggestions
    0_1527604065922_Firewall Forum.png


  • Rebel Alliance Developer Netgate

    There is a lot of detail missing here, for example:

    • What version of pfSense?
    • How is the VIP configured?
    • How is the route configured?
    • How are you testing failover?


  • Oh Sorry so much info missing:
    Version on Both: 2.4.3-RELEASE (amd64) built on Mon Mar 26 18:02:04 CDT 2018
    VIP: 0_1527634899261_c325f4e4-ec6e-469f-81f4-4fd56f6f69d2-image.png
    Gateway+Route:
    0_1527635128058_3ebed64a-d983-473c-8623-f2f684136c12-image.png
    0_1527635187461_6b2fc0f9-59d4-4489-b6be-e4d49d2714e8-image.png

    test scenario:

    1. Save route = everything is fine
    2. Enter CARP maintenance mode on Firewall1 = route lost on FW1 but workung on FW2
    3. Disable maintenance mode = Route Complete lost
    4. Save route again on Master = everything is fine again.

    And some OT: i found a new problem while test this, when i enter the maintenance on Firewall1 all VIPs go to the backup device but afer a couple of seconds later the initial master leaves the maintenance and become the Master again.


  • Rebel Alliance Developer Netgate

    Before anything else, upgrade both nodes to the current release, 2.4.3-p1, and then run the tests again.



  • Ok, but that will take a while. Due to a high performance environment I have to register and approve a change. Maybe any other tips?


  • Rebel Alliance Developer Netgate

    No other tips. Issue reports against outdated versions are not valid.


 

© Copyright 2002 - 2018 Rubicon Communications, LLC | Privacy Policy