WAN / Hardware Failover without CARP but Routing Groups an Virtual IP



  • Following setting:

    Goal: WAN and Hardware Failover using Routing Groups and Virtual IP

    Setup:

    PFSENSE1:

    • 1 x WAN
    • 1 x LAN - IP: 192.168.1.1 / 24
    • 1 x DIRECT - IP: 192.168.2.1 / 24
    • 1 x VIRTUAL IP: 192.168.1.254

    PFSENSE2:

    • 1 x WAN
    • 1 x LAN - IP: 192.168.1.2 / 24
    • 1 x DIRECT - IP: 192.168.2.2 / 24
    • 1 x VIRTUAL IP: 192.168.1.254

    Network Clients use the 192.168.1.254 as default gateway.

    I have setup a routing group at each pfsense with 2 gateways. Gateway1 is WAN1 / WAN2 and gateway2 is the DIRECT IP of the other pfsense.

    The clients have two LAN connections using LAGG connected to both switches.

    I have already done some testing and the only "problem" I could see was the loss of some pakets when I connect / disconnect any of the WAN or LAN interfaces.

    Is this a setting I can use for a reliable failover?

    A possible modification I see is not to use a direct connection between both pfsenses but a 2 line LAGG connection of each pfsense to both switches.

    EDIT: OK, I found one problem. If one of the routers loses WAN and DIRECT at the same time and the LAN still accepts pakets it will fail. Solution: Adding a third gateway to the gateway group using the LAN IP of the other pfsense.


Log in to reply