Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    1:1 NAT and CARP or VIP?

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    7 Posts 2 Posters 3.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mevans336
      last edited by

      I currently have two pfSense 2.0.3 boxes running CARP. Everything works great, but I noticed VIPs don't replicate over to the standby member. I'm thinking they need to be CARP IPs?

      Here is my situation, I have a /27 of public IPs from my co-lo provider. I use 1:1 NAT and I set each address up as a VIP on the primary firewall. (The WAN/LAN/DMZ addresses are CARP.)

      Should I just manually enter the VIPs onto the standby member or should I re-configure the VIPs on the primary member as CARP addresses?

      If I need to reconfigure as CARP, will it affect my existing 1:1 NAT mappings and/or firewall rules?

      Thanks!

      1 Reply Last reply Reply Quote 0
      • jimpJ Offline
        jimp Rebel Alliance Developer Netgate
        last edited by

        Is the /27 given to you just your WAN subnet?
        Or is your WAN subnet a separate subnet and the /27 routed to you?

        If the /27 is your WAN subnet, you will need to make all of those VIPs be CARP VIPs (or aliases using the CARP VIP as their interface).

        If the /27 is routed to you, then you don't need VIPs at all or you could use 'other' type VIPs or IP alias VIPs bound to localhost as their interface.

        Your 1:1 NAT entries shouldn't need to change at all.

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • M Offline
          mevans336
          last edited by

          @jimp:

          Is the /27 given to you just your WAN subnet?
          Or is your WAN subnet a separate subnet and the /27 routed to you?

          If the /27 is your WAN subnet, you will need to make all of those VIPs be CARP VIPs (or aliases using the CARP VIP as their interface).

          If the /27 is routed to you, then you don't need VIPs at all or you could use 'other' type VIPs or IP alias VIPs bound to localhost as their interface.

          Your 1:1 NAT entries shouldn't need to change at all.

          Hi Jim,

          I'm not sure I understand the distinction being being routed or not.

          Here is how we are set up:

          Let's say my /27 is 192.168.1.0/27.

          192.168.1.1 is a gateway provided by my co-lo facility. They also take .2, .3 for their devices. I have .4 configured as a CARP with the WAN being a parent. .4 and .5 are the static IP assignment on the WAN interface of each pfSense device. .1 is my WAN interface gateway.

          1 Reply Last reply Reply Quote 0
          • jimpJ Offline
            jimp Rebel Alliance Developer Netgate
            last edited by

            So it's your WAN subnet, and needs VIPs.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • M Offline
              mevans336
              last edited by

              @jimp:

              So it's your WAN subnet, and needs VIPs.

              Can I just change the type from IP Alias to CARP and set the password/skew/vhid appropriately?

              1 Reply Last reply Reply Quote 0
              • jimpJ Offline
                jimp Rebel Alliance Developer Netgate
                last edited by

                Yes.

                Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • M Offline
                  mevans336
                  last edited by

                  @jimp:

                  Yes.

                  Perfecto! Thanks Jim!

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.