No internet connectivity on standby CARP member
-
Hello,
I have set up 2 firewalls sharing CARP interfaces for WAN/LAN in an active/standby state. For some reason, the standby firewall cannot ping out to 8.8.8.8 (or anywhere) on the WAN, but it CAN reach the layer 3 network device on the other side of the LAN interface. I'm sure I'm just missing something simple here, but I'm drawing a total blank. What should I check at this point? -
@clonian
Some more information would be necessary to help. -
@clonian 3 public IPs?
https://docs.netgate.com/pfsense/en/latest/highavailability/index.html#ip-address-requirements-for-carp -
@SteveITS Yes, there are 3 public IPs, and 3 LAN side IPs (firewalls both have a LAN side and WAN side interface, a layer 3 switch is doing the routing behind the LAN) - IP 1 is CARP IP shared between the two, IP 2 is assigned to pfsense 1, ip 3 is assigned to pfsense 2.
-
@clonian The secondary member does show CARP correctly, and fails over as master successfully, etc. when the primary goes down - It just has no internet presently while it's the backup member.
-
@clonian Check Diagnostics/Routes on secondary? Any chance the ISP router is locking on to the CARP IP? IOW if you remove the shared IP they should both be able to connect out on their own.