Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HA issue

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    5 Posts 3 Posters 583 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bakisho
      last edited by

      I have a cluster of 2 pfsense physical machines.
      Everything work well regarding HA:

      1. I see pfsync packets over the "sync" interface.
      2. I see carp broadcasts (once in each second) on each interface (wan1 / wan2 / lan ).
      3. XMLRPC is working OK, whenever I create/change a rule it is reflected immidiatelly to the secondary.
        If I disable carp on the master, the secondary is promoted with downtime of a 1-5 seconds (which is OK for me).

      The problem is whenever I restart the Master "unexpectedly".
      On my last test I noticed that the following:

      1. The secondary is promoted.
        • It is broadcasting carp packets on every interface.
        • I see it shows up as master in "Status -> Carp".
      2. on the sync interface there was an arp "who has <master IP>".
        But nothing works until the master is back....

      What can the root cause for that?
      How can I troubleshoot it ?
      Thanks

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Are you LAN devices using the LAN CARP VIP as default gateway?

        Have you configured the outbound NAT to translate source addresses into the WAN CARP VIP instead of WAN address?

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          on the sync interface there was an arp "who has <master IP>".

          There should not be CARP configured on the sync interface so no idea what this is about.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • B
            bakisho
            last edited by

            Yes I am using my carp VIP as a default gateway.
            I did not understand, is it good or bad ?
            Some of my servers have a 1:1 NAT.
            Some of my servers do not have 1:1 Nat and use the WAN CARP VIP as the their public IP.

            There is no CARP on the SYNC interface, only "Sync" packets and "XMLRPC".

            1 Reply Last reply Reply Quote 0
            • V
              viragomann
              last edited by

              Yes, that's OK, the CARP VIP should be used as upstream gateway.

              Do you syncing the states?

              When the second box is master and upstream traffic is blocked, what does the filter log show?

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.