Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFense Failover inboud

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    9 Posts 3 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stanthewizard
      last edited by

      Hello

      I've clustered 2 pfsenses with VIP

      Wan VIP 192.168.1.200
      LAN VIP 192.168.0.1

      No issue four the outbound traffic (nat outbound manuel WAN 2 translate to VIP 192.168.0.200)

      BUT

      The WAN is behind my ISP box (NATED) the DMZ is set to the real IP of the first PFsense not the VIP.

      As soon as I change the DMZ to 192.168.0.200; I'm unable to access the servers on the LAN.

      Do I need to create a inbound rule or something ?

      Thanks for help

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        You seem to have the same subnet on WAN and LAN.
        Unless you are bridging this will not work. (And if you bridge, you don't need the VIP anymore).

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • S
          stanthewizard
          last edited by

          oups sorry sorry

          192.168.1.200

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            You write that as soon as you change the inbound NAT on the ISP provided box you can't access your server(s) anymore.
            You already have a rule in place to forward traffic from your primary IP to your server(s).
            Did you adjust this NAT and firewall rules on the pfSense to reflect the change from primary IP to VIP?

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • S
              stanthewizard
              last edited by

              The master firewall was a standalone one. Everything was fine.

              The Slave firewall got the same rules propagated from the master.

              The master got the "hard" IP 192.168.1.249 (slave 192.168.1.248)
              The VIP is 192.168.0.200

              When the DMZ is set on 249. Everything works for inbound.
              When the DMZ is set on 248. Everything works for inbound.

              When the DMZ is set on 200 (the VIP). No service outside of the LAN.

              Is it clearer ?  :)

              1 Reply Last reply Reply Quote 0
              • P
                podilarius
                last edited by

                Okay, what is the sunet mask used on the CARP interface? It should match the real interfaces. It is not like ProxyARP where you use just a /32. If WAN ips are /24, then so should the CARP VIP. Same for IP Alias.

                1 Reply Last reply Reply Quote 0
                • S
                  stanthewizard
                  last edited by

                  Everything is fine on the subnet front
                  /24
                  Everywhere

                  The wan is /24 end to end

                  1 Reply Last reply Reply Quote 0
                  • P
                    podilarius
                    last edited by

                    Just making sure because CARP VIP defaults to /32 and most forget to change that to match the WAN subnet. It still sounds like something is wrong with the CARP VIP setup, can you go into it and screen shot that? Also just noticed that the CARP VIP is not in the same subnet as the WAN. This cannot be. It must be in the same subnet as the WAN address. Perhaps a typo?
                    Also, did you setup manual outbound NAT to use the CARP VIP and not the WAN interface address?

                    1 Reply Last reply Reply Quote 0
                    • S
                      stanthewizard
                      last edited by

                      Nailed IT

                      I forgot something … the WAN vSwitch in my ESXI wasn't set to properli for the carp.
                      Promiscuous mode accepted

                      (but was correctly set for the LAN)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.