Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    CARP over wifi Bridge and 2 floors

    HA/CARP/VIPs
    2
    2
    571
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      AxSD last edited by

      I would like to know if it's possible to set up a two Pfsense routers to communicate with each other (pfSync) for failover, when they're on two different floors, connected by a wireless bridge.

      Additional info: Top floor has 2 internet connections going into one pfsense router. Physical servers and NAS are on the top floor. A separate router on the top floor configured to be an Access-Point be connected to a router on the bottom floor, configured as a Bridge so that networking on the top and bottom floored are unified. The bottom floor will have the second Pfsense router, connected to a separate internet connection. Please refer to the diagram attached.

      Questions:

      1. Can pfSync be configured between these two pfsense routers if a wireless bridge is involved, so that if one pfsense router fail, the other will completely take over?
      2. Is it possible for all clients on the top floor to have internet connection if the the physical internet line on the top floor goes out? Essentially top floor using getting internet from the line on the bottom floor. (Keep in mind the wifi Bridge is on the bottom floor)

      http://screencast.com/t/kpqrfOhGvnNJ


      1 Reply Last reply Reply Quote 0
      • jimp
        jimp Rebel Alliance Developer Netgate last edited by

        There are several problems with that:

        • HA nodes with CARP must have identical interface setups. You can't have three different ISPs across two nodes and have it work properly.
        • Failover signaling happens via CARP VIPs not the sync interface and those VIPs decide to fail over based on multicast heartbeats on each segment with a CARP VIP (e.g. LAN)
        • Using HA for "Multi-WAN" is not viable. There is no way to signal node failover based on a WAN failure.

        For proper HA, all nodes must be connected to all the same ISPs, though that isn't always possible, without that you can't have a setup that will cover both HA and WAN failover.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post

        Products

        • Platform Overview
        • TNSR
        • pfSense Plus
        • Appliances

        Services

        • Training
        • Professional Services

        Support

        • Subscription Plans
        • Contact Support
        • Product Lifecycle
        • Documentation

        News

        • Media Coverage
        • Press
        • Events

        Resources

        • Blog
        • FAQ
        • Find a Partner
        • Resource Library
        • Security Information

        Company

        • About Us
        • Careers
        • Partners
        • Contact Us
        • Legal
        Our Mission

        We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

        Subscribe to our Newsletter

        Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

        © 2021 Rubicon Communications, LLC | Privacy Policy