WAN / Hardware Failover without CARP but Routing Groups an Virtual IP
-
Following setting:
Goal: WAN and Hardware Failover using Routing Groups and Virtual IP
Setup:
PFSENSE1:
- 1 x WAN
- 1 x LAN - IP: 192.168.1.1 / 24
- 1 x DIRECT - IP: 192.168.2.1 / 24
- 1 x VIRTUAL IP: 192.168.1.254
PFSENSE2:
- 1 x WAN
- 1 x LAN - IP: 192.168.1.2 / 24
- 1 x DIRECT - IP: 192.168.2.2 / 24
- 1 x VIRTUAL IP: 192.168.1.254
Network Clients use the 192.168.1.254 as default gateway.
I have setup a routing group at each pfsense with 2 gateways. Gateway1 is WAN1 / WAN2 and gateway2 is the DIRECT IP of the other pfsense.
The clients have two LAN connections using LAGG connected to both switches.
I have already done some testing and the only "problem" I could see was the loss of some pakets when I connect / disconnect any of the WAN or LAN interfaces.
Is this a setting I can use for a reliable failover?
A possible modification I see is not to use a direct connection between both pfsenses but a 2 line LAGG connection of each pfsense to both switches.
EDIT: OK, I found one problem. If one of the routers loses WAN and DIRECT at the same time and the LAN still accepts pakets it will fail. Solution: Adding a third gateway to the gateway group using the LAN IP of the other pfsense.