Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Whats My IP Not Showing CARP IP

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    4 Posts 3 Posters 480 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      acp
      last edited by

      I have set up CARP on our new firewalls with 3 external ips

      xxx.xxx.xxx.98 - Main PFSense Machine
      xxx.xxx.xxx.99 - Backup PFSense Machine
      xxx.xxx.xxx.100 CARP IP

      As you can see here CARP seems to be setup correctly as it shows MASTER MASTER on the main machine and SLAVE SLAVE on the backup.

      CARP.PNG

      However only the LAN Carp IP seems to be working. I have setup a machine to use the LAN CARP as its gateway and it can reach the internet however when I do whats my ip in google it doesn't show the CARP ip but shows the main pfsense machines IP.

      Even when I click the maintenance CARP mode it just swaps the IP to the backup pfsense machine's ip.

      OutboundNAT.PNG

      I have setup the outbound rules like this which seems to be correct according the guide. So I can't understand what the problem is.

      The main difference is that on the main machine it has access to another local network on an OPT1 interface which is the 10.1.1.0/24 range while the backup only has the 10.1.2.0/24 on LAN which the main also has setup.

      Both machines are on VMWare and have the following settings on the switches

      VMWare Switch.PNG

      I would appreciate any suggestions that you could provide.

      1 Reply Last reply Reply Quote 0
      • N
        netblues
        last edited by

        First rule works, so your entries with the vip are never used.

        1 Reply Last reply Reply Quote 1
        • A
          acp
          last edited by

          Thank you very much I didn't see that as most of the guides only suggested the other two.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            And none of the guides said to put a rule like that in place at the top. In fact many caution against it.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.