How to do use this NAT?
-
I know carp will use three WAN IP address.Two pfsense wan interface will use two wan IP address.And carp will use one shared IP address.Please see information.
one primary pfsense use wan ip address is 1.2.3.4
one backup pfsense use wan ip address is 1.2.3.5
carp ip use 1.2.3.6
I set NAT on primary pfsense 1.2.3.4 --> 192.168.0.5:80
If primary pfsense break.The primary ip address 1.2.3.4 haven't set on backup pfsense.
This NAT rule should can't run it. Is right?Could any solution to setup it on backup pfsense if primary pfsense break?
-
@akong77 said in How to do use this NAT?:
one primary pfsense use wan ip address is 1.2.3.4
one backup pfsense use wan ip address is 1.2.3.5
carp ip use 1.2.3.6So 1.2.3.4 can only be used on the primary and 1.2.3.5 can only be used on the backup.
1.2.3.6 is used by the master (whether it's the primary or the secondary) and is meant for fail-over. -
@akong77 said in How to do use this NAT?:
I set NAT on primary pfsense 1.2.3.4 --> 192.168.0.5:80
Set the port forward to forward 1.2.3.6 --> 192.168.0.5:80
That same rule will be synced to the secondary.
Whatever node happens to be the CARP MASTER will receive the connection and forward it.
Whatever states already exist to that server should be synced and continue to work.
-
Because these three IP address I has set for some service.
1.2.3.4 for web service and forward to 192.168.0.5:80
1.2.3.5 for mail service and forward to 192.168.0.6:25 and 110
1.2.3.6 for ftp service and forward to 192.168.0.7:21
If I set 12.3.6 forward to 192.168.0.5:80,I will change my dns mapping ip address. Is it right?
Could I only set all service on 1.2.3.6 this ip address? -
Yes.
If you expect HA to work you need to port forward connections to the CARP VIP.
In general, you can forward one protocol:address:port tuple to one inside destination.
There is no reason you cannot forward these:
1.2.3.6:80 --> 192.168.0.5:80
1.2.3.6:25 --> 192.168.0.6:25
1.2.3.6:110 --> 192.168.0.6:110
1.2.3.6:21 --> 192.168.0.7:21They are all different listening ports so they can be forwarded inbound independently.
Yes, You would change the A record for these services to 1.2.3.6.
-
So,If I have two web server and use 80 port.Could I use HA CARP?
-
So,If I want building carp service. It's must use three IP address and two IP address not use any service. Is it right?
-
Yes, that’s the way it’s recommended to set up CARP.
However, there are also ways to set up CARP with three private IPs and hook up the public IPs on the CARP VIP with some drawbacks.
E. g. you will have to set up a second default route over the master for the backup to reach the internet and draw updates.Another way to use to webserver is to run HA proxy on pfSens and let it do the spreadind.
-
If I have three wan ip.
IP is 1.2.3.4~1.2.3.6 and gateway is 1.2.3.254
I want use 192.168.13.2~192.168.13.4 these private ip to set it.
Could you tell me how to do it?
Thanks a lot. -
For now, I had only set up something like that for a second WAN, where the backup WAN connection was given by the first WAN.
This may look like this:
pfSense 1: 192.168.13.2
pfSense 2: 192.168.13.3
CARP VIP: 192.168.13.4Then go to Firewall > Virtual IPs and add 1.2.3.4 to the WAN CARP VIP as „IP alias“. Set the correct mask (/24, I guess). Do the same with your other public IPs.
Go to System > Routing > Gateways and add 1.2.3.254 as a gateway to WAN and set it as default.
Go to Firewall > NAT > Outbound, switch to manual mode and edit the rules for your internal subnets and for pfSense itself to translate outbound packets to one of your public IPs, e.g. the CARP VIP.Now your WAN interface should work in CARP mode and your public addresses should be reachable from the internet. However, the backup will not be able to draw updates.
-
So, I should set 192.168.13.2 to pfsense1 wan interface and 192.168.13.3 to pfsense2 wan interface.
Then I set 192.168.13.4 to Firewall--Virtual IPs--CARP.
And 1.2.3.4 this IP set on Firewall--Virtual IPs--IP Aliases. Is it correct? -
Yes, for 1.2.3.4 and all other public IPs select type "IP Alias" and at interface select "192.168.13.4", which is the CARP VIP.
-
Hello,
Thank you teach us.
I want know two question.
WAN interface I has set 192.168.13.2.The upstream gateway should be set none. Is it correct?
Outbound NAT the NAT address set should use public ip address e.g. 1.2.3.4. Is it correct? -
If it is a WAN and you want it to act like a WAN you should set the upstream gateway on the interface.
-
@viragomann
WAN interface I has set 192.168.13.2.The upstream gateway should be set none. Is it correct?
Outbound NAT the NAT address set should use public ip address e.g. 1.2.3.4. Is it correct? -
@Derelict
Thanks a lot.
Because I will set private ip on wan. So I need understand this setup.Thanks a lot. -
-
@Derelict @viragomann Thanks all friend.
But it's can't monitor internet ip status if I set private ip on wan. Right?
I want know if I use multi wan with carp. What do I want to know? -
You can configure the gateway monitoring to use an alternative (public) IP.
Edit the gateway settings in System > Routing > Gateways and enter a public IP which responses to ICMP into the "Monitor IP" box. -
@viragomann I has use alternative (public) IP like 1.1.1.1 this ip address to monitor.I also test diag--ping to test wan. It's can ping to 1.1.1.1 this ip address.But it's always show offline.How to set monitor ip use ICMP?