No NAT for Backup FW's webUI?



  • I've got CARP setup pretty successfully and have just one last thing left to fix: the backup firewall is unable to check for updates or download package lists/files.

    The backup firewall is however able to ping external IPs (8.8.8.8 etc) using the webUI Diagnostics->Ping page, as well as via ssh/console.

    Outbound NAT setup screenshot: http://www.fr3d.org/ss/lando/clipping_58076.png
    (You can see I've tried adding a few extra rules, with no success).

    VIPs:
    WAN: 192.168.1.10 /24 (yes, it's double-NAT'd :( )
    LAN: 10.10.0.1 /24
    WIFI: 172.16.0.1 /24

    FW1:
    WAN: 192.168.1.201 /24
    LAN: 10.10.0.201 /24
    WIFI: 172.16.0.201 /24

    FW2:
    WAN: 192.168.1.202 /24
    LAN: 10.10.0.202 /24
    WIFI: 172.16.0.202 /24

    If I disable CARP on the master - therefore making the backup FW the new master - update checks and package installs work just fine.

    Any ideas?

    Thanks in advance :)



  • generally that's because you're NATing the secondary firewall's Internet traffic to a CARP IP. Not clear from that screenshot which rule would be doing that given I'm not sure what the WAN IP is, but just make sure you're not NATing traffic sourced from either firewall's WAN IP.


Locked