Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Netgate 7100 with HA update issues

    Scheduled Pinned Locked Moved General pfSense Questions
    carpfailoverupdates
    22 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nick.loenders
      last edited by

      I have setup 2 7100 devices with CARP HA Failover.
      One works perfect and has updated to 24.03.
      The other says "Unable to check for updates"

      If I do a ping from this one to 1.1.1.1 it has no replies either. It seems the failover device has no access to internet?

      The rules and NAT on both are the same....
      What else can I do ?

      w0wW 1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        Do both devices have public IPs? If you have a shared single public IP only the master node would have connectivity.

        Otherwise check for a default route in Diag > Routes.

        N stephenw10S 2 Replies Last reply Reply Quote 0
        • N
          nick.loenders @stephenw10
          last edited by

          @stephenw10 Both devices have public ip's AND there is a virtual public ip, which we use to usually access it, but also for the openvpn, for the RDS servers that run behind it,...

          The outbound nat rules (:anual outbound NAT rule) are the same on both devices and use the virtual wan ip to get out

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by stephenw10

            What outbound NAT rules do you have exactly?

            Importantly the rules should not include traffic from the firewall itself. Otherwise only the node owning the shared VIP will be able to connect as traffic is translated to it.

            N 1 Reply Last reply Reply Quote 0
            • N
              nick.loenders @stephenw10
              last edited by

              @stephenw10

              893b5569-d2a2-4316-9976-91c36416aaa1-image.png

              1 Reply Last reply Reply Quote 0
              • w0wW
                w0w @nick.loenders
                last edited by

                @nick-loenders

                Hmm... That's fun. Two weeks ago, I found that 1.1.1.1 was not responding to my pings anymore. Additionally, on one of the CARP firewalls, it was used for gateway monitoring. I don't really know what's happening, but I used an alternative, 8.8.4.4, which worked fine, and I just forgot about it until I read your story. I don't know if it's related, but what is the status of your gateway on the status page?

                N 1 Reply Last reply Reply Quote 0
                • N
                  nick.loenders @w0w
                  last edited by

                  @w0w

                  476def06-abfe-4131-b938-c154f22ea0f3-image.png

                  I don't have a google dns there.... just the gateway of my provider.

                  w0wW 1 Reply Last reply Reply Quote 0
                  • w0wW
                    w0w @nick.loenders
                    last edited by

                    @nick-loenders
                    Ok, so it is not related.
                    Did your try traceroute from diagnostic menu? Some public ip or Microsoft.com, anyone?

                    N 1 Reply Last reply Reply Quote 0
                    • N
                      nick.loenders @w0w
                      last edited by

                      @w0w @stephenw10
                      very weird stuff here, I did a tracert and ping and I had internet....
                      Also the 24.03 update was visible and I could install it...

                      Now it has rebooted, the internet is gone again...
                      So I need to wait another day before it comes back....

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        Did you check the default route?

                        N 1 Reply Last reply Reply Quote 0
                        • N
                          nick.loenders @stephenw10
                          last edited by

                          @stephenw10 where do I check this, I have no static routes setup

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator @stephenw10
                            last edited by

                            @stephenw10 said in Netgate 7100 with HA update issues:

                            Otherwise check for a default route in Diag > Routes.

                            😉

                            Also check that the default route shown there is valid/expected assuming it is there.

                            N 1 Reply Last reply Reply Quote 1
                            • N
                              nick.loenders @stephenw10
                              last edited by

                              @stephenw10 NO idea how that actually works but here it is:

                              c2ec6daa-c8c4-4516-9ea7-ed559ae8c615-image.png

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                Ok, that looks good.

                                Can you test a ping to, say, 8.8.8.8 from the command line on that node?

                                Whilst that ping is running check the state table in Diag > States. Filter it by 8.8.8.8 and make sure the outbound state exists and on the correct interface.

                                N 1 Reply Last reply Reply Quote 0
                                • N
                                  nick.loenders @stephenw10
                                  last edited by

                                  @stephenw10 Well then there is no reply, in the states it says:

                                  6dff1261-dddb-4385-9289-c01fe3dbab5b-image.png

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Hmm, what is that connected to? How are the other NICs connected?

                                    I assume the primary node can ping everything OK?

                                    N 1 Reply Last reply Reply Quote 0
                                    • N
                                      nick.loenders @stephenw10
                                      last edited by

                                      @stephenw10 the primary node can ping perfectly

                                      The WAN nics are connected to a patchpanel and get a direct ip from the hosting in the datacenter.
                                      WAN on pri;ary is .35
                                      WAN on secondary is .36
                                      Virtual WAN for HA and how we go out is .33 (if we are on a server and do whatismyip.com we see .33 )

                                      1 Reply Last reply Reply Quote 0
                                      • stephenw10S
                                        stephenw10 Netgate Administrator
                                        last edited by

                                        Hmm. Traffic just disappearing like that I start to suspect something odd upsteam.

                                        Check on the primary node to see if replies are somehow being incorrectly sent to it. So you would see that in the firewall log there unless you have rules to pass it.

                                        I assume the CARP VIPs are all failing over correctly?

                                        N 1 Reply Last reply Reply Quote 0
                                        • N
                                          nick.loenders @stephenw10
                                          last edited by

                                          @stephenw10

                                          I do see this on the firewall, don't know what that is:

                                          b2464615-6e59-467c-993f-8dafe696246a-image.png

                                          I already added that to the rules, but it does not help.

                                          I do seem not to be able to ping the other SYNC side:

                                          62974caa-cd27-4c71-993d-a84303203048-image.png

                                          N 1 Reply Last reply Reply Quote 0
                                          • N
                                            nick.loenders @nick.loenders
                                            last edited by

                                            @stephenw10 nevermind the ping, I solved that by a rule

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.