Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Move all CARP IP's together

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    4 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      neilewing
      last edited by

      Hi - I am sure the answer to this is already on these forums, I just cannot find it. I have a HA setup, single WAN interface and two VLAN's on the LAN side. I have been unable to determine what happens if say the LAN connection fails on the primary node, but the WAN stays online.

      I suspect of course that the LAN side CARP's on the VLAN interfaces will move to the secondary node, but of course the WAN CARP will still be on the primary node as it's interface is still good and they can see each other. Does this not result in no internet access because the LAN and WAN CARP's are now on different nodes?

      I must be missing the really obvious, and I apologise if I have, but if someone could just help me out with how this works, I would really appreciate it.

      Neil

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @neilewing
        last edited by

        @neilewing
        Just try it out by pulling the LAN cable from the master.

        If one interface on one node fails it should trigger a failover of all CARP interfaces.
        If an interface on the secondary stays at master state after a failover it probably cannot communicate to with the primary node by CARP protocol.

        N 1 Reply Last reply Reply Quote 0
        • N
          neilewing @viragomann
          last edited by

          @viragomann Thanks for your quick reply. I was assuming as much, but was unable to check at the time as we were needing to minimise downtime for the client. We will run the test as you describe.

          DerelictD 1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate @neilewing
            last edited by

            @neilewing When an interface with a CARP VIP loses carrier, all VIPs on that host are demoted. This makes the VIPs on the other node "better" and the rest of the VIPs on the first node swing to BACKUP status (because they see the "better" advertisements) and the ones on the backup node assume MASTER (because they see that they are the "best" VIP status).

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.