Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Help please. i suspect something to do with carp but unsure

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    5 Posts 2 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      alphaz18
      last edited by

      Hi,
      i'm not sure if this is normal behavior or if carp is doing something odd.
      i'm running 2.0.3.
      and have 2 firewalls carped.
      my issue is everytime I make any changes to the firewall.. ie.. nat.. or IPsec disable / re-enable or anything really I press apply changes..
      then maybe 10-15 seconds later all the connections seem to drop for like 20-30 seconds.
      its like everything just goes down..

      did anyone ever run into this?
      i'm checking the system logs and theres nothing in particular.. going on .

      Thanks

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        Check that you don't have a gateway showing down on the primary or secondary.

        Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • A Offline
          alphaz18
          last edited by

          gesus you're good. just from these vague symptoms you could tell right away :|
          now i just gotta figure out why its down… i guess it was never up lol.
          thanks!

          Edit: i checked all the connections.. and they're good. and the lights are blinking on the wan interface but i cant seem to ping anything from the secondary... ??

          1 Reply Last reply Reply Quote 0
          • A Offline
            alphaz18
            last edited by

            jimp, hi,
            i think i found the problem, though not quite sure how to fix it….
            i think it has to do with manual outbound nat...
            so the secondary has a manual rule thats basically saying go out through carp ip.
            but the master has the carp ip. so when you ping out the ping basically always goes back to master instead of slave?

            1 Reply Last reply Reply Quote 0
            • jimpJ Offline
              jimp Rebel Alliance Developer Netgate
              last edited by

              Your NAT rules should not apply NAT to traffic originating from the firewall itself. (e.g. you do NOT want a source of "any" on NAT rules, but the LAN subnet or an alias of your internal subnets)

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.