• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

No internet when failing over to second firewall [SOLVED]

Scheduled Pinned Locked Moved HA/CARP/VIPs
10 Posts 3 Posters 3.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A Offline
    anthonyg
    last edited by Jan 4, 2011, 1:42 AM Dec 28, 2010, 9:17 PM

    I have resolved all my prior issues with setting up CARP. I am finally able to NAT out with the CARP IP on the primary firewall. However when I flop over to the secondary, internet stops working. When I pull the plug on the primary firewall, CARP switches to master on the secondary. I am actually able to resolve DNS via command prompt, but unable to ping anything. I also can get to ftp sites sites with their domain name. Firewall logs dont show any type of blocking going on. Anybody have any ideas what the problem is?

    1 Reply Last reply Reply Quote 0
    • ? This user is from outside of this forum
      Guest
      last edited by Dec 28, 2010, 9:29 PM

      Confirm that your LAN devices are using the shared CARP IP on your LAN IP as their gateway and not the physical IP of the primary firewall.  Beyond that, you'll need to post many more details and perform the basic network troubleshooting tasks necessary to run down a connectivity problem.

      1 Reply Last reply Reply Quote 0
      • S Offline
        Skar
        last edited by Dec 29, 2010, 3:28 PM

        Did all VIPs switch to the backup Pfsense?

        In my test setup this isn't the case.

        If i unplug the WAN cable from the master following happens:

        WAN VIP switches active on backup pfsense.
        But on LAN Site the VIP gateway ip stays on the master pfsense.

        Isn't there any kind of carp group configurable?

        As shown in:
        http://www.openbsd.org/faq/pf/carp.html#forcefail

        1 Reply Last reply Reply Quote 0
        • A Offline
          anthonyg
          last edited by Dec 29, 2010, 3:58 PM

          All LAN devices are using the LAN CARP IP which is 10.1.1.250/24. LAN of Primary is 10.1.1.251/24 and LAN of secondary is 10.1.1.252/24.

          1 Reply Last reply Reply Quote 0
          • A Offline
            anthonyg
            last edited by Dec 29, 2010, 4:31 PM

            Some further diagnostics. I am able to ping google.com on the WAN interface of both firewalls. I am able to ping google.com on the LAN interface of firewall1, but not firewall2. Could this be the cause of my problems?

            1 Reply Last reply Reply Quote 0
            • S Offline
              Skar
              last edited by Dec 30, 2010, 11:28 AM

              If you have outbound NAT enabled for all traffic from LAN this is normal.

              Ping source is the CARP Wan ip which is only active on your master firewall.

              But again under Status -> Carp    LAN and WAN must be master on the same machine.

              pfsense 1 both master LAN and WAN or pfsense 2 both master.

              Are thy if you unplug the pfsense1 WAN caple?

              1 Reply Last reply Reply Quote 0
              • A Offline
                anthonyg
                last edited by Dec 30, 2010, 2:18 PM Dec 30, 2010, 2:09 PM

                After unplugging the WAN from firewall1, firewall2's CARP status changed to master on all VIP's. Firewall1's status on the WAN changed to INIT and LAN to BACKUP.

                Also while firewall2 is in master mode, I still cannot ping out the LAN.

                1 Reply Last reply Reply Quote 0
                • A Offline
                  anthonyg
                  last edited by Dec 30, 2010, 2:51 PM

                  The problem seems to be a NAT issue. When I fail over to the second firewall, if I go into my NAT rules and adjust it to go out of the interface instead of the CARP IP, internet works just fine. However as soon as I set it to my CARP IP it will stop working. This only does this on the secondary firewall. On the primary it NAT's out just fine. Could this also mean that CARP is not failing over properly?

                  1 Reply Last reply Reply Quote 0
                  • A Offline
                    anthonyg
                    last edited by Dec 30, 2010, 7:49 PM

                    After further diagnosis, it appears that my ISP may be the trouble. I am using Comcast with a range of static addresses. As soon as i plugged in my T1 and changed all the addresses, failover worked completely fine. Anyone ever heard of this before? Do you think I need to powercycle my modem during non-business hours?

                    1 Reply Last reply Reply Quote 0
                    • A Offline
                      anthonyg
                      last edited by Jan 3, 2011, 4:55 PM

                      I have resolved this issue. It appears the comcast modem just needed to be rebooted.

                      1 Reply Last reply Reply Quote 0
                      10 out of 10
                      • First post
                        10/10
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                        This community forum collects and processes your personal information.
                        consent.not_received