Best way to set up and maintain a cold spare for pfSense 2.8.0 CE
-
Hi all,
I’m running pfSense 2.8.0 CE on my main router and I’d like to build a cold spare in case the primary fails.
Main box: 4 ports in use → WAN / LAN / IoT / Guest
Spare box: Only 3 ports available → I’d drop the Guest network if I needed to switch over
I know I can install pfSense cleanly on the spare, but I’m unclear on the best way to:
-
Transfer my current configuration to the spare.
-
Keep that configuration up to date as I make changes on the main router.
Questions:
-
Is it best practice to back up and restore configs manually, or is there a cleaner way to sync across different hardware (since the interfaces don’t match)?
-
How do others handle maintaining a cold spare so it’s ready to go at short notice?
Any practical tips, workflows, or “gotchas” to watch out for would be really appreciated.
Thanks!
-
-
Never did this, but that's never stopped me before!
First, as long as you already have the second hardware, install, restore and see what happens. if it's offline, you'll have plenty of time to sort things out. Just get DHCP on the WAN from your existing pfS and make the LAN a second internal net. You can change the LAN at conosle later. Back it up, take notes.
Second, you could try editing out the Guest net parts in a backup config.xml, hand configure your interface drivers, etc., install, restore. More difficult IMO, and possible to muck things up.
If I think of anything else... I love benchracing! But I'm sure others smarter than me will respond.
-
-
@girkers said in Best way to set up and maintain a cold spare for pfSense 2.8.0 CE:
How do others handle maintaining a cold spare so it’s ready to go at short notice?
We use the exactly same hardware and keep this cold spare up-to-date.
In case of failure restore the last config or move the disk from the production system to the cold spare...