Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    CARPS/VIPS Failover Issue

    HA/CARP/VIPs
    2
    4
    2.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mypal
      last edited by

      I have a setup that has the same setup as the carp cluster example. Each firewall has 4 interfaces, public, DMZ, sync and private. I have set up the carp cluster as mentioned in the example. When I power down the primary firewall, I am able to browse internet without any issue. The strange thing is the folks using public internet are not able to connect to my web server located at the DMZ subnet when the primary firewall is shutdown. If I bring up the primary firewall, everything start to work as normal again. Has anybody try out the incoming traffic to DMZ using carp failover?

      Note: Both my firewall public interfaces and router are connected to the same switch.

      1 Reply Last reply Reply Quote 0
      • S
        sullrich
        last edited by

        See http://doc.pfsense.org/index.php/Setting_up_CARP_with_pfSense

        1 Reply Last reply Reply Quote 0
        • M
          mypal
          last edited by

          I have followed the example given. I have the proxy-arp enabled for the WAN interface to pass traffic to the DMZ server. However, when the primary firewall is shut down, outsiders can't connect to the web server in DMZ. The user in the LAN can browse internet without any issue. I am wondering whether the primary and secondary firewall can both do proxy-arp for the same set of public address at the same time. When the primary fails, how do the secondary firewall takes over the proxy-arp role?

          1 Reply Last reply Reply Quote 0
          • S
            sullrich
            last edited by

            Proxyarp is not used for failover.  CARP is.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.