• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Using HAproxy on a CARP/HA firewall cluster

HA/CARP/VIPs
2
14
1.1k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    Pavan 1
    last edited by Nov 14, 2023, 10:02 AM

    Hi,

    Configured HAproxy with Firewall cluster with backend as Nextcloud, when i bring either primary or Secondory Firewall down everything works. As soon as i enable both Firewalls Download and Upload to Nextcloud fails immidiatly, Where exactly would be the issue?

    V 1 Reply Last reply Nov 14, 2023, 8:09 PM Reply Quote 0
    • V
      viragomann @Pavan 1
      last edited by Nov 14, 2023, 8:09 PM

      @Pavan-1
      The CARP status is well, one is master, the other one backup?

      Does it work if you bypass HAproxy by forwarding the traffic directly to the backend server?

      P 1 Reply Last reply Nov 15, 2023, 3:07 AM Reply Quote 0
      • P
        Pavan 1 @viragomann
        last edited by Nov 15, 2023, 3:07 AM

        @viragomann ,

        Hi, i can confirm when i bypass pfSense everything works also CARP functions well. Tested this with bringing down Master and slave comes up, also configuration syncs.

        Issue comes when both Firewalls are UP and on PCAP i see TCP out of order packets.

        V 1 Reply Last reply Nov 15, 2023, 8:23 AM Reply Quote 0
        • V
          viragomann @Pavan 1
          last edited by Nov 15, 2023, 8:23 AM

          @Pavan-1
          So I suspect, that you miss the CARP setting in HAproxy.

          P 1 Reply Last reply Nov 15, 2023, 9:26 AM Reply Quote 0
          • P
            Pavan 1 @viragomann
            last edited by Nov 15, 2023, 9:26 AM

            @viragomann ,

            I have used CARP IP for HAproxy. Additionally we have used single interface for LAN and SYNC cloud it cause any issues?

            Regards,
            Pavan.

            V 1 Reply Last reply Nov 15, 2023, 11:02 AM Reply Quote 0
            • V
              viragomann @Pavan 1
              last edited by Nov 15, 2023, 11:02 AM

              @Pavan-1
              What means a single interface? Non-CARP?

              I requested this setting: Services > HAproxy > Settings >Carp monitor
              If this is set properly the HAproxy service should be stopped, when the node is in backup state.

              P 1 Reply Last reply Nov 15, 2023, 11:14 AM Reply Quote 0
              • P
                Pavan 1 @viragomann
                last edited by Nov 15, 2023, 11:14 AM

                @viragomann

                @viragomann said in Using HAproxy on a CARP/HA firewall cluster:

                What means a single interface? Non-CARP

                Like we don't have dedicated Interface for SYNC we have used single interface for all traffic and SYNC.

                @viragomann said in Using HAproxy on a CARP/HA firewall cluster:

                I requested this setting: Services > HAproxy > Settings >Carp monitor

                Yes, when primary is active secondary pfSense will have HAproxy service disabled.

                V 1 Reply Last reply Nov 15, 2023, 11:27 AM Reply Quote 0
                • V
                  viragomann @Pavan 1
                  last edited by Nov 15, 2023, 11:27 AM

                  @Pavan-1 said in Using HAproxy on a CARP/HA firewall cluster:

                  Like we don't have dedicated Interface for SYNC we have used single interface for all traffic and SYNC.

                  This shouldn't matter.

                  Is HAproxy running in transparent mode?

                  If it isn't, to get closer enable the logging of the involved firewall rules and as well of the default deny rule (Status > System Logs > Settings > Log firewall default blocks).
                  Then run your firewall in HA mode and reproduce the error. Check the logs for relevant entries and post it here if possible.

                  P 1 Reply Last reply Nov 15, 2023, 5:48 PM Reply Quote 0
                  • P
                    Pavan 1 @viragomann
                    last edited by Nov 15, 2023, 5:48 PM

                    @viragomann ,

                    What exactly does transparent mode do and how to enable it?

                    Thanks i will log the default block and reproduce the issue and update.

                    Regards,

                    V 1 Reply Last reply Nov 15, 2023, 5:54 PM Reply Quote 0
                    • V
                      viragomann @Pavan 1
                      last edited by Nov 15, 2023, 5:54 PM

                      @Pavan-1
                      Transparent mode is a bad hack. You shouldn't enable it, if there isn't a very good reason to do that.

                      P 1 Reply Last reply Nov 15, 2023, 5:57 PM Reply Quote 0
                      • P
                        Pavan 1 @viragomann
                        last edited by Nov 15, 2023, 5:57 PM

                        @viragomann

                        So all the connections are made directly to backend servers instead of pfSense?

                        TCP Out Of Order is what I'm seeing in PCAP, does it suggest any misconfiguration?

                        V 1 Reply Last reply Nov 15, 2023, 6:03 PM Reply Quote 0
                        • V
                          viragomann @Pavan 1
                          last edited by Nov 15, 2023, 6:03 PM

                          @Pavan-1 said in Using HAproxy on a CARP/HA firewall cluster:

                          So all the connections are made directly to backend servers instead of pfSense?

                          In transparent mode, pfSense uses the origin source IP, when accessing the backend.
                          There are some odd (hidden) firewall rule necessary to make this work.

                          TCP Out Of Order is what I'm seeing in PCAP, does it suggest any misconfiguration?

                          This indicates a probable asymmetric traffic. Some packets might go to the backup node for whatever reason.

                          P 2 Replies Last reply Nov 15, 2023, 6:06 PM Reply Quote 0
                          • P
                            Pavan 1 @viragomann
                            last edited by Nov 15, 2023, 6:06 PM

                            @viragomann

                            @viragomann said in Using HAproxy on a CARP/HA firewall cluster:

                            This indicates a probable asymmetric traffic. Some packets might go to the backup node for whatever reason

                            I thought so, since it's all in VM i'm lost in the woods to figure out the root cause. But as per CARP, Primary and secondary works.

                            What i will do is check if the traffic is hitting the second pfSense when primary is UP, i hope it helps Else please suggest.

                            1 Reply Last reply Reply Quote 0
                            • P
                              Pavan 1 @viragomann
                              last edited by Nov 17, 2023, 12:58 AM

                              @viragomann ,

                              Observed something weird where if i turn off state synchronisation in System>> High availability. Application is working. Any suggestions for this weird behaviour??

                              1 Reply Last reply Reply Quote 0
                              2 out of 14
                              • First post
                                2/14
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.