Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't add new CARP VIP with pfSense 2.1

    HA/CARP/VIPs
    3
    5
    2.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      surfdude
      last edited by

      Hi

      I've recently upgraded to pfSense 2.1. I have a CARP / NAT failover setup. Back on pfSense 1.2, I could create a new CARP VIP for each public IP Adress without problems.

      Now, if I try to create a new Entry, I get the error:

      "The /31 and /32 subnet mask are invalid for CARP IPs."

      Settings are: "Type: CARP, Interface WAN, IP-Adresse 195.X.X.X / 32"

      I also can't change the prev entrys. I used to create a seperate entry for every host. Why I can't do this anymore?

      SurfDuDe

      1 Reply Last reply Reply Quote 0
      • N
        nothing
        last edited by

        Well which part isn't clear exactly? :)

        You can't use subnet with less than 3 usable IPs in it - Node1, Node2, VirtuapIP. Also the virtual IP should have subnet mask the same as the interface itself.

        1 Reply Last reply Reply Quote 0
        • S
          surfdude
          last edited by

          So, how can I add a carp single host address?

          1 Reply Last reply Reply Quote 0
          • N
            nothing
            last edited by

            CARP is the way the virtual IP address sharing between two hosts works. If you don't have two hosts - you can't have CARP. Which means subnet with at least 3 available IPs is required.

            1 Reply Last reply Reply Quote 0
            • jimpJ
              jimp Rebel Alliance Developer Netgate
              last edited by

              CARP VIPs are always single host addresses. The subnet mask on a CARP VIP must match the parent subnet. So if you WAN is x.x.x.a/28, then your CARP VIP must be (for example) x.x.x.b/28 – it's still just one IP. It's not like proxy ARP where it makes a bunch of IPs if you pick a larger mask.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.