• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Best way to add a large block of public IPs

Scheduled Pinned Locked Moved HA/CARP/VIPs
6 Posts 3 Posters 2.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    Gob
    last edited by Jan 12, 2012, 12:39 PM

    Hi

    I need to configure a pfSense box to replace an old firewall on one of our sites. They have a /29 and a /24 block of public IPs.
    one of the /29 IPs is allocated to their WAN and I need to add the /24 (256 IP addresses) as virtual IPs to the firewall, primarily for forwarding port 80 to lots of web servers.

    I tried to do this a few years ago using an early BETA of v2.0 but when I added the /24 range as a Proxy Arp network, only 8 IP addresses appeared in the NAT Destination selection list. This problem seems to have been resolved in the latest stable release but I wondered if there are any performance issues with using PArp over Carp or IP Alias?

    Any comments welcomed.

    Cheers
    Gordon

    If I fix one more thing than I break in a day, it's a good day!

    1 Reply Last reply Reply Quote 0
    • M
      marcelloc
      last edited by Jan 12, 2012, 1:13 PM

      I suggest you to configure all these ips using carp and also configure a second pfsense to get a full redundant firewall.

      Treinamentos de Elite: http://sys-squad.com

      Help a community developer! ;D

      1 Reply Last reply Reply Quote 0
      • G
        Gob
        last edited by Jan 12, 2012, 1:18 PM

        thanks for your reply Marcelloc
        I understand your thinking, that if there are a lot of web servers then this should really be a redundant setup.
        However the web servers are all development / staging boxes and HA isn't really a requirement for the public facing access.

        So is there a benefit using CARP over PARP if we are not using redundant boxes?

        If I fix one more thing than I break in a day, it's a good day!

        1 Reply Last reply Reply Quote 0
        • M
          marcelloc
          last edited by Jan 12, 2012, 1:33 PM

          This way you can use ip alias or Parp. Carp are most used for redundant setup

          Treinamentos de Elite: http://sys-squad.com

          Help a community developer! ;D

          1 Reply Last reply Reply Quote 0
          • G
            Gob
            last edited by Jan 12, 2012, 1:37 PM

            OK, thanks

            With IP Alias, I would have to enter each IP manually so I guess ProxyARP is the simplest to go for.

            If I fix one more thing than I break in a day, it's a good day!

            1 Reply Last reply Reply Quote 0
            • C
              cmb
              last edited by Feb 1, 2012, 2:43 AM

              Performance isn't relevant to VIPs. It's best to have the bigger subnet routed to an IP in your smaller subnet, but VIPs generally fine too, though that gives you less flexibility on using the second subnet.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received