Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Query on HA and VIP

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    4 Posts 3 Posters 316 Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      siil-it
      last edited by

      We are looking to purchase a pair of 8300's and set them up in HA mode.

      There are two WAN connections
      One is a static internet with a /28 public IP range
      One is a business broadband connection that gets it's IP via DHCP from the ISP's device

      There will also be a DMZ switch attached to one of the 10G ports on each PFSense and the LAN connections will also us a 10G port.

      What is the best way to configure the public and internal VIP's for the HA. Should we be using an intermediary switch?

      SteveITSS N 2 Replies Last reply Reply Quote 0
      • SteveITSS Offline
        SteveITS Rebel Alliance @siil-it
        last edited by

        @siil-it Typically there’s a switch between the routers and ISP. I haven’t tried without but if you say used two ports on the ISP router it would need to allow the shared IP to move ports.

        WAN2 is not static? I don’t know you can have a shared IP there…one normally needs at least one static IP. Does that ISP also NAT? (Here Comcast cable does)

        To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
        Only install packages for your version of pfSense.
        Upvote 👍 helpful posts!

        1 Reply Last reply Reply Quote 0
        • N Offline
          netblues @siil-it
          last edited by

          @siil-it The /28 can failover with a normal carp vip. And you need a switch in front of the two 8300
          Obviously the switch AND the isp equipment is SPOF's

          For the business broadband, what ip does it get? A public one or from private range
          If it is for the latter, use static and do the same.

          If not, then you can't really have carp failover without 3 ip's in the same subnet.

          SteveITSS 1 Reply Last reply Reply Quote 0
          • SteveITSS Offline
            SteveITS Rebel Alliance @netblues
            last edited by

            @netblues

            you can't really have carp failover without 3 ip's in the same subnet

            Depends, which is why I asked about it. We’ve set it up on Comcast/Xfinity using one shared static public IP and set the WAN IP on both routers in the default 10.1.10.x range. That works well.

            Docs cover only one IP but there’s no connectivity until failover:
            https://docs.netgate.com/pfsense/en/latest/highavailability/index.html#ip-address-requirements-for-carp

            If WAN2 is really only DHCP though then I don’t think there can be a shared IP.

            To upgrade, select your branch in System/Update/Update Settings. When upgrading, allow 10-15 minutes to reboot, or more depending on packages, CPU, and/or disk speed.
            Only install packages for your version of pfSense.
            Upvote 👍 helpful posts!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.