Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    What's the right way to update 2 pfsense in HA through VPN?

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 3 Posters 468 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      Tony Soprano
      last edited by

      Hello everybody, as title says, i bump into a "lost connection" last time i tried to update 2 pfsense in HA via VPN.
      I first update the "backup" pfsense, and everything goes smooth.
      When i lunch update from webgui on main pfsense, i suddenly lost connection on my VPN and when i reconnect i was connected to VPN but on backup pfsense, and main got stuck, didn't see the update, stick on old version and can't see the new version either.
      I resolved this already, but i wonder how to avoid this shit next update!
      Any help will be appreciated, thanks!

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @Tony Soprano
        last edited by

        @Tony-Soprano
        As suggested in Upgrading a High Availability Cluster, you should set primary into the CARP maintenance mode before upgrading it.
        So your connections use the secondary for the whole process. You can reboot the primary before and after upgrading and ensure that is working properly.

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Sounds like your VPN is using the CARP IP and it gets disconnected when it fails over. You want to be connected the firewall IPs directly when making this sort of change.

          T 1 Reply Last reply Reply Quote 1
          • T
            Tony Soprano @stephenw10
            last edited by

            @stephenw10 tnx this is exactly what happened, and i used the solution purposed by @viragomann , which is in the end same of yours and it works fine thanks guys!
            You're precious as usual!
            Respect!

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.