• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[SOLVED] Firewall rule on CARP interface keeps being deleted after sync

Scheduled Pinned Locked Moved HA/CARP/VIPs
34 Posts 5 Posters 21.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    podilarius
    last edited by Nov 2, 2011, 11:02 AM

    Forgot this was the second page :). Anyway, looking back at the screen shots it does look like on the master node that CARP was originally opt2 as one of your VPN interface took opt1. I can tell by the ordering of the tabs. This should not make a difference as they are named. Try this, on the master, add a description to the allow all CARP rule (ie CARP Allow All). Sync the settings, and see if that description show up on another interfaces rules.

    Are those other interfaces (RV,OVPNS1, OVPNC1,MGMT) VLANs?

    1 Reply Last reply Reply Quote 0
    • B
      bitadmin
      last edited by Nov 2, 2011, 2:00 PM Nov 2, 2011, 1:57 PM

      Yes. OVPNS1, OVPNC1, MGMT and RV are VLANs

      I tried adding a description to the CARP-interface rule on the master and started the sync. After that my rule on the backup FW is gone (as always) but the rule from the master does not show up on any other interface.

      Edit: I was wrong: the rule does show up (i had it not to replicate via "No XMLRPC Sync" option).
      It appears on the "MGMT" interface

      1 Reply Last reply Reply Quote 0
      • B
        bitadmin
        last edited by Nov 2, 2011, 2:04 PM

        Here are 2 screenshots for my interfaces:

        on master i got this:

        an on backup i got this:

        1 Reply Last reply Reply Quote 0
        • B
          bitadmin
          last edited by Nov 2, 2011, 2:13 PM Nov 2, 2011, 2:10 PM

          I even went further now and found out that the rules are synced on the wrong interfaces in several occasions:

          Master -> Backup
          OVPNS1 -> CARP
          CARP -> MGMT
          OVPNC1 -> RV
          -> OVPNS1
          -> OVPNC1

          With all that i am surprised that WAN and LAN aren't synced on the wrong interface as well ;)

          Edit: Looking at the screenshots i believe that the sync does not apply to the interface names but to their creation order.

          1 Reply Last reply Reply Quote 0
          • J
            jimp Rebel Alliance Developer Netgate
            last edited by Nov 2, 2011, 2:18 PM

            That's what I was going to suggest checking.

            The number and order of interfaces in carp cluster members must be the same. What you are seeing is the result of the interfaces not being assigned in the correct order on the slave.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • B
              bitadmin
              last edited by Nov 2, 2011, 2:43 PM

              Does that mean i have to remove and recreate my interfaces on the backup server to get the correct order?
              OR can i simply update some config file through the console to get the same result?

              The rules and settings for those interfaces should be synced automatically, shouldn't they?

              1 Reply Last reply Reply Quote 0
              • J
                jimp Rebel Alliance Developer Netgate
                last edited by Nov 2, 2011, 2:44 PM

                Yes, unless you want to hand edit the config to swap things around.

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • P
                  podilarius
                  last edited by Nov 2, 2011, 2:55 PM

                  sometimes hand editing is the easiest. especially if you have to replace a lot of IPs. But in this case, prolly easier to just redo the slave.

                  1 Reply Last reply Reply Quote 0
                  • B
                    bitadmin
                    last edited by Nov 2, 2011, 4:56 PM

                    Do you know which file i need to edit?

                    1 Reply Last reply Reply Quote 0
                    • J
                      jimp Rebel Alliance Developer Netgate
                      last edited by Nov 2, 2011, 4:57 PM

                      Diagnostics > Backup/Restore, make a backup file, edit the xml backup file, then restore it. If you aren't familiar with XML or can't find your way around it, you're probably better off making the changes in the GUI instead.

                      Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • B
                        bitadmin
                        last edited by Nov 2, 2011, 5:02 PM

                        Thank you.
                        I think i can handle the xml and will give it a try.
                        (What's the worst that can happen  ;D)

                        1 Reply Last reply Reply Quote 0
                        • B
                          bitadmin
                          last edited by Nov 2, 2011, 5:14 PM

                          It worked.

                          Was pretty easy. Just export only the part for interfaces (which results in a very small XML) and change the tags for the interfaces the way the are labeled on the master. Import it again and voilรก: chicken's done!

                          Thank you all for your help!!!!

                          Now: How do I mark this thread as resolved? No more loose ends left :)

                          1 Reply Last reply Reply Quote 1
                          • M
                            Metu69salemi
                            last edited by Nov 2, 2011, 8:10 PM

                            edit your first post subject with [SOLVED]

                            1 Reply Last reply Reply Quote 0
                            31 out of 34
                            • First post
                              31/34
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              This community forum collects and processes your personal information.
                              consent.not_received