Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Trouble with VIP

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    6 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dan34
      last edited by

      I created a VIP with a second public IP. I used type "IP Alias" and addef firewall rules to allow it to respond to pings. I am able to ping the address, but I get packet loss of more than 60%. The VIP is in the same subnet as the primary IP. The plan is to use the VIP to forward ports to an internal system, but at this point it's pretty unusable.

      I've done some searching, but haven't found a similar problem. Does anyone have suggestions for fixing this?

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Anything in your System log?  I have 13 public IP addresses, and I use pfSense WAN for one and 12 VIPs for the others.  Works like a charm.  You're sure you don't have an IP conflict somewhere for that 60% lossy IP address?

        1 Reply Last reply Reply Quote 0
        • D
          dan34
          last edited by

          I'm pretty sure I tried to ping the address before I added it as a VIP and got no replies. I'll check that again.

          A mis-configuration on the ISP's part could cause something like this as well, right?

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            A mis-configuration on the ISP's part could cause something like this as well, right?

            Unlikely.  More likely is a bad cable, hardware or misconfiguration on your end.

            1 Reply Last reply Reply Quote 0
            • D
              dan34
              last edited by

              Well, hardware would be the same as for the WAN IP and that works just fine. So that leaves some configuration problem.

              I just did some packet captures. At the WAN interface of pfSense I see the echo requests arriving and the replies going back. However at my end (where I'm pinging from) I see all the requests going out, but most of the replies are missing. So the replies are leaving pfSense, but not reaching me. I don't see how that could be a config problem in the pfSense box, but I may be missing something

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                Plz detail your network configuration.  Maybe there is a clue there.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.