<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[2 of 3 CARP VIP&#x27;s work]]></title><description><![CDATA[<p dir="auto">Hi, folks,</p>
<p dir="auto">I have pfSense setup with 3 VIP's, one for WAN (public IP), one for LAN (10.0.), and one for DMZ (OPT1) (172.16.).  OPT2 (192.168.) handles the CARP traffic.  Synchronization to the failover device works fabulously.</p>
<p dir="auto">The VIP's for LAN and WAN work exactly as they should, advanced outbound NAT works fine.  However, the DMZ machines aren't reachable, and I can't ping the DMZ interface.  The only thing in the log that I see is:</p>
<p dir="auto">Feb 23 11:28:01  kernel: arplookup 172.16.0.1 failed: could not allocate llinfo<br />
Feb 23 11:28:01  kernel: arpresolve: can't allocate route for 172.16.0.1</p>
<p dir="auto">Searching the board for these errors, folks point to a "don't worry about it" FAQ entry, so I'm not sure if it's meaningful or a red herring.</p>
<p dir="auto">Both devices work fine with the non-VIP config on them.</p>
<p dir="auto">Any suggestions as to where to look next?</p>
]]></description><link>https://forum.netgate.com/topic/3558/2-of-3-carp-vip-s-work</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 16:59:41 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/3558.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 23 Feb 2007 17:07:00 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 2 of 3 CARP VIP&#x27;s work on Mon, 26 Feb 2007 11:20:20 GMT]]></title><description><![CDATA[<p dir="auto">Correc t, you need first a virtual IP to add 1:1 mappings (at least if we are not talking abou the real wan interface IP). On top of that you need firewallrules to let the desired traffic pass of course.</p>
]]></description><link>https://forum.netgate.com/post/149940</link><guid isPermaLink="true">https://forum.netgate.com/post/149940</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Mon, 26 Feb 2007 11:20:20 GMT</pubDate></item><item><title><![CDATA[Reply to 2 of 3 CARP VIP&#x27;s work on Mon, 26 Feb 2007 05:48:01 GMT]]></title><description><![CDATA[<p dir="auto">OK, so the theory of operation would be to create CARP VIP's on the WAN interface - and then leave the 1:1 NAT as is for linking the WAN and DMZ addresses?</p>
]]></description><link>https://forum.netgate.com/post/149931</link><guid isPermaLink="true">https://forum.netgate.com/post/149931</guid><dc:creator><![CDATA[bill_mcgonigle]]></dc:creator><pubDate>Mon, 26 Feb 2007 05:48:01 GMT</pubDate></item><item><title><![CDATA[Reply to 2 of 3 CARP VIP&#x27;s work on Mon, 26 Feb 2007 03:21:01 GMT]]></title><description><![CDATA[<p dir="auto">You have proxyArp entries as well? This is a problem. ProxyARP IPs can't be shared between two systems so both systems will try to actively use them. Either disable VIP syncing and manually create the needed items or move everything to CARP. I would move everything to CARP.</p>
]]></description><link>https://forum.netgate.com/post/149926</link><guid isPermaLink="true">https://forum.netgate.com/post/149926</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Mon, 26 Feb 2007 03:21:01 GMT</pubDate></item><item><title><![CDATA[Reply to 2 of 3 CARP VIP&#x27;s work on Mon, 26 Feb 2007 02:13:46 GMT]]></title><description><![CDATA[<p dir="auto">OK, I just tried this again. I have two systems, named pfsense and pfsense2.</p>
<p dir="auto">If I look under CARP Status, on pfsense (the one I intend to be master), I see all three VIP's listed as MASTER.</p>
<p dir="auto">On pfsense2, I see the LAN VIP as BACKUP and the WAN and DMZ VIP as MASTER.  The pfSync nodes list (13 entries) matches on both.</p>
<p dir="auto">I've checked the VHID on both in the GUI and in an XML backup file.  Also compared the passwords for each VIP in the XML backup file, they match.  The advskew on pfsense2 was automatically set to 100 on the backup VIP's.</p>
<p dir="auto">The synchronization of rules and such is still working fine.</p>
<p dir="auto">Now, here's something that that makes me go 'hmmm': the XML backup for pfsense2 has the proxy arp entries for my DMZ machines listed simply as &lt;vip&gt;(one for each of 10 entries).  The XML backup for pfsense (the master) has the proxy arp entries fully detailed.  I notice I have 10 proxy arp's and 3 VIP's and 13 pfSync nodes - not a coincidence?</p>
<p dir="auto">What's odd is some traffic works OK - I can ssh in to a DMZ machine from the Internet, for instance.  But any DNS queries, pings, telnets, I'm guessing all outgoing traffic (initiated from the DMZ), from a DMZ machine to the Internet fail.  Also pinging the DMZ VIP from within the DMZ still fails.</p>
<p dir="auto">pfsense 1.0.1 on both machines.</p>
<p dir="auto">Thanks for any insight.&lt;/vip&gt;</p>
]]></description><link>https://forum.netgate.com/post/149924</link><guid isPermaLink="true">https://forum.netgate.com/post/149924</guid><dc:creator><![CDATA[bill_mcgonigle]]></dc:creator><pubDate>Mon, 26 Feb 2007 02:13:46 GMT</pubDate></item><item><title><![CDATA[Reply to 2 of 3 CARP VIP&#x27;s work on Fri, 23 Feb 2007 17:16:14 GMT]]></title><description><![CDATA[<p dir="auto">Ah! Thanks, I'll schedule a new window to try again and look there.</p>
]]></description><link>https://forum.netgate.com/post/149822</link><guid isPermaLink="true">https://forum.netgate.com/post/149822</guid><dc:creator><![CDATA[bill_mcgonigle]]></dc:creator><pubDate>Fri, 23 Feb 2007 17:16:14 GMT</pubDate></item><item><title><![CDATA[Reply to 2 of 3 CARP VIP&#x27;s work on Fri, 23 Feb 2007 17:09:45 GMT]]></title><description><![CDATA[<p dir="auto">What dies status&gt;carp report for the 3rd non working VIP?</p>
]]></description><link>https://forum.netgate.com/post/149821</link><guid isPermaLink="true">https://forum.netgate.com/post/149821</guid><dc:creator><![CDATA[hoba]]></dc:creator><pubDate>Fri, 23 Feb 2007 17:09:45 GMT</pubDate></item></channel></rss>