Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Issue with CARP in DNSBL

    pfBlockerNG
    3
    14
    1.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      KKIT
      last edited by

      Hi,

      I am using two pfSense XG-7100 Firewalls in a cluster configuration and wanted to enable CARP functionality in the DNSBL settings of pfBlockerNG.

      I have tried to move the WebGUI to a different port (HTTPS) but that didn't help and the logs don't show anything unfortunately.

      Is there a manual I can follow? I am unsure whether or not I need to set up a new interface for the DNSBL CARP functionality?

      Thanks much, attached a few images, let me know if you need more information.

      Bildschirmfoto 2023-02-28 um 16.45.54.png Bildschirmfoto 2023-02-28 um 16.42.33.png Bildschirmfoto 2023-02-28 um 16.42.22.png

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @KKIT
        last edited by

        @kkit said in Issue with CARP in DNSBL:

        wanted to enable CARP functionality in the DNSBL settings of pfBlockerNG.

        What do you mean?
        You have a CARP setup already, I assume. DNSBL has nothing to do with CARP. So what do you intend to do now?

        So what is your issue?

        If the DNSBL settings you can state a VIP type for its IP. But both should work, even on a CARP setup.

        K 1 Reply Last reply Reply Quote 0
        • K
          KKIT @viragomann
          last edited by

          @viragomann

          Thanks for your reply,

          I have seen this feature (see attached image) that implies that setting it to "CARP" is for clustered routers, which is the case with my setup.

          I basically just wanted to ask for documentation. Do you suggest it should be left on IP Alias?

          Thanks again!

          CARP_Setting

          V 1 Reply Last reply Reply Quote 0
          • V
            viragomann @KKIT
            last edited by

            @kkit
            This IP is used to direct unwanted destination traffic to it. So it's not indispensable at all.

            If you take an IP alias it is assigned to an interface. When clients traffic is directed to it in case of a failover, clients which have already an ARP entry for it will fail to access the IP till the ARP is renewed.
            When using a CARP VIP the MAC stays the same after a failover and clients can access it without interrupts.

            So yes, you can select CARP VIP here.

            K 1 Reply Last reply Reply Quote 0
            • K
              KKIT @viragomann
              last edited by

              @viragomann

              I understand the basic functionality and that's what I tried to do.
              But as mentioned in my main post, after switching to CARP, the DNSBL Service goes down and I can't get it to work. I already followed other posts which suggested a collision with the pfSense GUI port, since DNSBL Web Service is listening http and https.

              I don't know what else I can do.

              V 1 Reply Last reply Reply Quote 0
              • V
                viragomann @KKIT
                last edited by

                @kkit
                Did you state a unique VHID and a password?

                Something in the system log?

                K 2 Replies Last reply Reply Quote 0
                • K
                  KKIT @viragomann
                  last edited by

                  @viragomann

                  Will check in the evening when I'm back and let you know. Thanks much

                  1 Reply Last reply Reply Quote 0
                  • K
                    KKIT @viragomann
                    last edited by

                    @viragomann

                    So:
                    I made sure the pfSense GUIs port is different from the one DNSBL Web Server listens to
                    I gave the CARP VIP a unique VHID
                    I checked the system log but nothing major, the last one was "pfblockerng: saving dnsbl changes". No errors and XMLRPC does successfully synchronize everything

                    K 1 Reply Last reply Reply Quote 0
                    • K
                      KKIT @KKIT
                      last edited by

                      @kkit Bump.
                      Can anyone help?

                      J 1 Reply Last reply Reply Quote 0
                      • J
                        juliokele @KKIT
                        last edited by

                        @kkit
                        set the DNSBL Web Server Interface to LAN

                        K 1 Reply Last reply Reply Quote 0
                        • K
                          KKIT @juliokele
                          last edited by

                          @juliokele Thanks for the suggestion. I have several VLANs, will DNSBL still function for all of them?

                          J V 2 Replies Last reply Reply Quote 0
                          • J
                            juliokele @KKIT
                            last edited by

                            @kkit
                            yes, it should work...

                            1 Reply Last reply Reply Quote 0
                            • V
                              viragomann @KKIT
                              last edited by

                              @kkit
                              It would work with the above described gap in case of a failover.

                              K 1 Reply Last reply Reply Quote 0
                              • K
                                KKIT @viragomann
                                last edited by

                                @viragomann @juliokele

                                Changing it to LAN did not help, either :(

                                Attached a few images. I just can not seem to find the log files, please see attached images.

                                Changed Web GUI https port of pfSense to 500
                                Set pfBlockerNG DNSBL to CARP with unique settings
                                Made sure subnet is not in use
                                Reloaded DNSBL

                                still no success...

                                Bildschirmfoto 2023-03-13 um 23.19.08.png Bildschirmfoto 2023-03-13 um 23.06.12.png Bildschirmfoto 2023-03-13 um 23.05.24.png Bildschirmfoto 2023-03-13 um 23.02.44.png

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.