• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Rule problem in a cluster

Scheduled Pinned Locked Moved HA/CARP/VIPs
6 Posts 3 Posters 1.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    cisco0613
    last edited by Mar 7, 2022, 8:11 PM

    Hello,
    I have a cluster of two pfsense netgate xg1541. The master manages all traffic. HA is therefore set to both firewalls. When I create a rule from the master, it is duplicated on the second. However, after a few seconds I lose my internet connection. The Ping still works on the carp lan but it is impossible to go outside. This problem occurs only on the master. I am obliged to disable the master's carp mode to redirect traffic to the slave. The slave does not have this problem. It works normally. However, I reinstalled the master several times using a usb key and reimported its configuration but the problem persists. I don't have a problem displayed in the logs. Are you aware of this problem? Thank you for your help.
    Regards.

    S 1 Reply Last reply Mar 11, 2022, 3:33 PM Reply Quote 0
    • C
      cisco0613
      last edited by Mar 7, 2022, 8:15 PM

      The cluster version is 22.01.

      1 Reply Last reply Reply Quote 0
      • K
        Klaws
        last edited by Klaws Mar 11, 2022, 8:59 AM Mar 11, 2022, 8:36 AM

        No clue. Did you check that "Synchronize Config to IP" in "Configuration Synchronization Settings (XMLRPC Sync)" is empty on the second firewall?

        C 1 Reply Last reply Mar 11, 2022, 5:11 PM Reply Quote 0
        • S
          SteveITS Galactic Empire @cisco0613
          last edited by Mar 11, 2022, 3:33 PM

          @cisco0613 If you have a lot of rules, and the outage is very temporary, there is a patch in the System Patches package for "Disable pf counter data preservation to temporarily work around latency when reloading large rulesets (Redmine #12827)."

          However your description doesn't sound very temporary. When this happens does the Status/CARP page look correct on both routers as to the primary having all the Masters?

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          C 1 Reply Last reply Mar 11, 2022, 5:21 PM Reply Quote 0
          • C
            cisco0613 @Klaws
            last edited by Mar 11, 2022, 5:11 PM

            @klaws
            Hello,
            The "Synchronize Config to IP" field is empty on the slave pfsense. The configuration has been checked several times.

            1 Reply Last reply Reply Quote 1
            • C
              cisco0613 @SteveITS
              last edited by Mar 11, 2022, 5:21 PM

              @steveits
              Hello,
              When I add the rule on the master, it is duplicated on the second pfsense. The master pfsense remains master in "status/CARP".
              The second pfsense is in "Backup".
              Yes the problem is not temporary, I have a total loss to the internet.
              The master's wan interfaces are up and communicating with their gateway. But unable to access the internet.
              The interfaces are in green on the dashboard.

              Regards.

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received