No remote syslog when binding to CARP interface?
Running pfSense: 2.2.2-RELEASE (amd64)
Remote Logging Options
Source Address (LAN-CARP)
When tcpdumping port 514 on my syslog server I dont see anything coming in from my pfSense host.
If I switch pfSense Source Address to normal LAN I see logs starts dropping in instantly.
Is this by design or should I file a bug report?
Just realized this probably fit better under the CARP/VIPs forum.
Could a moderator please move it?
I would think you would want all cluster members logging and would want to be able to tell which member the log entry came from anyway.
I would think your logic is flawed.
I use CARP for failover purposes and send my logs to an ELK stack to visualize firewall entries.
Why would I want logs from the secondary host when its in Backup state and not being actively used? And even then, I could just configure the other hosts to use their LAN IP as source? And keep primary as CARP.