• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

HA Cluster - Backup problem

HA/CARP/VIPs
2
15
943
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    Derelict LAYER 8 Netgate
    last edited by Derelict Jan 10, 2019, 4:47 PM Jan 10, 2019, 4:46 PM

    You generally don't run OpenVPN on the backup node. It starts when it fails over.

    How about posting the DNS results so we can be the judge of what is working fine and what isn't?

    Chattanooga, Tennessee, USA
    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
    Do Not Chat For Help! NO_WAN_EGRESS(TM)

    X 1 Reply Last reply Jan 10, 2019, 4:54 PM Reply Quote 1
    • X
      xlameee @Derelict
      last edited by Jan 10, 2019, 4:54 PM

      @derelict Master is dark theme Backup is light

      192.168.10.1 is the upstream pfsense unbound

      I set the downstream pfsense to forwarding mode

      login-to-view

      login-to-view
      login-to-view

      1 Reply Last reply Reply Quote 0
      • D
        Derelict LAYER 8 Netgate
        last edited by Derelict Jan 10, 2019, 4:57 PM Jan 10, 2019, 4:56 PM

        How about names out on the internet? Like files00.netgate.com?

        You rattled off about 6 different problems in your initial post. What, specifically, is your priority to fix?

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        X 1 Reply Last reply Jan 10, 2019, 4:58 PM Reply Quote 1
        • X
          xlameee @Derelict
          last edited by Jan 10, 2019, 4:58 PM

          @derelict

          both have the same output

          login-to-view

          1 Reply Last reply Reply Quote 0
          • D
            Derelict LAYER 8 Netgate
            last edited by Jan 10, 2019, 4:59 PM

            OK. It looks like that webgui is functioning fine.

            So what is the problem you are having? Please be as complete and specific as possible.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            X 1 Reply Last reply Jan 10, 2019, 5:33 PM Reply Quote 1
            • X
              xlameee @Derelict
              last edited by xlameee Jan 10, 2019, 5:34 PM Jan 10, 2019, 5:33 PM

              @derelict

              It looks yes, but before I started this post it was very very slow loading any page on the backup's web GUI and the web gui was unresponsive when you try to go to any page on the webgui. Even now sometimes when I hit the link on the menu browser is loading and then stopped like nothing happen and when I hit the same link again on the menu the page is loading fine. If the problem was the unbound Yes the unbound service was down on the backup and I started it so far I don't have any problems I just walked around the webgui's menu going to different pages without any issues

              I just put the master into CARP Maintenance Mode as you said openvpn service came up

              I have tested the SYNC after I put the master into CARP Maintenance Mode the master becomes a backup. When backup becomes a master and I make some changes like adding aliases to it they don't sync to the backup is that how it should be? If you can understand what I am trying to say!!!! Everything else seems to work fine

              1 Reply Last reply Reply Quote 0
              • D
                Derelict LAYER 8 Netgate
                last edited by Jan 10, 2019, 5:37 PM

                If it is having trouble syncing settings it really depends. Does the system log show successful XMLRPC sync when you make a change?

                If not that will have to be fixed.

                If sync is working but changes to firewall rules don't appear to be syncing, you might have mismatched interfaces between the two nodes.

                If you are having GUI problems, the first thing I would do is eliminate the custom theme. I would also try another browser. I have not heard of any issues like that with the dark theme, and all major browsers work fine with the firewall, but that is where I would start.

                I would also check for any logs that state something like "X is using my ip address" or something of that nature.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                X 1 Reply Last reply Jan 10, 2019, 6:07 PM Reply Quote 1
                • X
                  xlameee @Derelict
                  last edited by Jan 10, 2019, 6:07 PM

                  @derelict hello

                  My SYNC Interfaces are Direct attached 10G Fiber between both nodes no switch/hub between them.

                  My question was is the syncing process one way ?

                  When my MASTER NODE failed and my BACKUP NODE become a MASTER is not actually a MASTER - MASTER it was design to pass a traffic until the MASTER is back online right ? or to test some settings before you put them into the MASTER NODE

                  That's why this clustering system is design when new update came up you update the BACKUP NODE to see if everything is working fine before you UPDATE the MASTER NODE

                  1 Reply Last reply Reply Quote 0
                  • D
                    Derelict LAYER 8 Netgate
                    last edited by Jan 10, 2019, 6:11 PM

                    Yes. You make changes to the primary node. It doesn't matter which one is master at the time.

                    If something happens and you have to run on the secondary node for any length of time, it is incumbent upon you to log any necessary changes so they can be duplicated when the primary node is back online.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    X 1 Reply Last reply Jan 11, 2019, 7:41 AM Reply Quote 1
                    • X
                      xlameee @Derelict
                      last edited by Jan 11, 2019, 7:41 AM

                      @derelict Understand thank you

                      1 Reply Last reply Reply Quote 0
                      15 out of 15
                      • First post
                        15/15
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.