Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Two separate pfsense clusters on same layer 2 and subnet

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    4 Posts 3 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      paulm
      last edited by

      Hi

      We are currently running a pfsense cluster in one DC using CARP. In another DC, which has an L2 link between them, we need to setup a separate pfsense cluster on the same subnet/L2 to be a secondary gateway. We are basically getting some transit in from another provider into this new DC and migrating some services over to it, however both clusters need to remain online with the L2 in place.

      Are there any issues with doing this? Do I just need to ensure that the VHIDs and passwords are different?

      Thanks, Paul.

      1 Reply Last reply Reply Quote 0
      • P
        paulm
        last edited by

        Can anyone assist please? Thanks

        1 Reply Last reply Reply Quote 0
        • P
          podilarius
          last edited by

          I have not personally attempted this, but know a little about CARP, I think you are correct.
          As long as the VHIDs are different, you should be able have the pfSense machines with CARP in the same L2 switch (even if linked by distance).

          We did do a similar move, but since I was moving the equipment, we just used a single firewall for a few days at the new site until the equipment moved over.
          After which, we just restored an updated config on each of the cluster members that contained the new IPs.

          1 Reply Last reply Reply Quote 0
          • awebsterA
            awebster
            last edited by

            I have 3 clusters of pfSense running on a nework and they all co-exist well.
            You absolutely need to ensure that the VHID is different between each cluster set, and also that it does not overlap any other CARP or VRRP instances running on the same L2.
            If you are using IPv4 and IPv6, you also need different VHID for each protocol.

            –A.

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.