Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Configuring 2 PfSense in HA with CARP in LAN/WAN

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    3 Posts 2 Posters 309 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      Phelton
      last edited by

      Hi,
      im trying to configure 2 PfSense in a Test Scenario with following topology:

      Screenshot 2024-07-30 122729.png

      I have configured a HA and CARP following the official guide

      I have some problems:
      1- if i shut interface that arrive on primary PfSense from LAN side, all CARP ip go in Standby and traffic continue to work, but when i try to shut only the WAN
      interface of primary PfSense (on switch), CARP LAN stay in Active state and WAN change in blank state on primary. Instad the Second PfSense have all CARP in Active.

      2- if i don't shutdown nothing and i try to ping il 10.10.10.1 (VyOS dvice) from the PC Test and enabling packet capture (wireshark) in WAN and LAN side of both interface of both PfSense's, i can see ping packet on the LAN and WAN of Primary PfSense and this is right, but i can see also a ping exiting from WAN interface of secondary PfSense and on this firewall the CARP stayng in standby (as a right way).

      Before configure in a real scenario (i want try to implement a couple of PfSense in TestPlant of my organization) i need understand where is a problem in this topology.

      thanks very much for your support.

      Bye
      Enrico from Italy

      1 Reply Last reply Reply Quote 0
      • P
        Phelton
        last edited by

        now work inserting in WAN CARP parameter "Advertising Frequency/Base" the same value of LAN CARP Interface:

        38793cba-7a63-44de-8118-bf3864457061-image.png

        T 1 Reply Last reply Reply Quote 0
        • T
          tboston @Phelton
          last edited by

          @Phelton Don't know what you mean by your last comment but make sure that BASE is e.g. 1 on main and at least 100 on secondary. Also, use a different VHID Group for each network/carp ip

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.