https://redmine.pfsense.org/https://redmine.pfsense.org/favicon.ico?16780521162012-03-12T05:11:40ZpfSense bugtrackerpfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=82222012-03-12T05:11:40ZSeth Mosseth.mos@dds.nl
<ul><li><strong>File</strong> <a href="/attachments/538">carp-a-8.3.pcap</a> <a class="icon-only icon-download" title="Download" href="/attachments/download/538/carp-a-8.3.pcap">carp-a-8.3.pcap</a> added</li><li><strong>File</strong> <a href="/attachments/539">carp-b-8.3.pcap</a> <a class="icon-only icon-download" title="Download" href="/attachments/download/539/carp-b-8.3.pcap">carp-b-8.3.pcap</a> added</li><li><strong>File</strong> <a href="/attachments/540">carp-a-8.3-b-8.1.pcap</a> <a class="icon-only icon-download" title="Download" href="/attachments/download/540/carp-a-8.3-b-8.1.pcap">carp-a-8.3-b-8.1.pcap</a> added</li><li><strong>File</strong> <a href="/attachments/541">carp-b-8.1.pcap</a> <a class="icon-only icon-download" title="Download" href="/attachments/download/541/carp-b-8.1.pcap">carp-b-8.1.pcap</a> added</li><li><strong>File</strong> <a href="/attachments/542">carp-a-8.1-b-8.1.pcap</a> <a class="icon-only icon-download" title="Download" href="/attachments/download/542/carp-a-8.1-b-8.1.pcap">carp-a-8.1-b-8.1.pcap</a> added</li></ul><p>I have attached 4 pcaps. The 1st 2 pcap files are both members running 8.3.</p>
<p>Pcap 3 and 4 is the master and backup node running a 8.1 snapshots from <a class="external" href="http://files.pfsense.org/jimp/ipv6/">http://files.pfsense.org/jimp/ipv6/</a><br />I'm using pfSense-Full-Update-2.1-DEVELOPMENT-i386-20111125-1741.tgz as this was the last "good" 8.1 snap.</p>
<p>As soon as the backup node is downgraded to a 8.1 snapshot it kicks into backup again.</p>
<p>The other way around makes no difference, if the primary is 8.1 and the backup is 8.3 they both will be master.</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=82252012-03-12T08:07:40ZSeth Mosseth.mos@dds.nl
<ul><li><strong>Assignee</strong> set to <i>Ermal Luçi</i></li></ul><p>Just tested with 2 clean FreeBSD 8.3-RC1 vms and there the IPv6 Carp backup and failover works correctly. That implies that it is related to our patches for 8.3.</p>
<p>Ermal can you debug this with the information provided here?</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=83542012-03-21T14:42:57ZChris Buechlercbuechler@gmail.com
<ul><li><strong>Target version</strong> changed from <i>8</i> to <i>2.1</i></li><li><strong>Affected Version</strong> changed from <i>2.1</i> to <i>2.1-IPv6</i></li></ul> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=84112012-03-22T18:07:31ZErmal Luçieri@pfsense.org
<ul></ul><p>Probably it will be related to the IPv6 patch there is in there.<br />Can you confirm that Seth?</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=84212012-03-26T10:53:59ZSeth Mosseth.mos@dds.nl
<ul><li><strong>Status</strong> changed from <i>New</i> to <i>Feedback</i></li></ul><p><del>Can not replicate with FreeBSD 8.3-RC2 snapshots from snapshots.pfsense.org. Possibly fixed between RC1 and RC2.</del></p>
<p><del>Possibly others can confirm.</del></p>
<p>Scratch that, the primary, which was RC1 still, was up for 46 days but seized all IPv6 comms to the vips. Even rebooting the master and backup did not allow comms to restore.<br />After downgrading to 8.1 snaps from Jim made on 25th november 2011 it all came back to live.</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=85402012-03-31T06:30:38ZChris Buechlercbuechler@gmail.com
<ul><li><strong>Status</strong> changed from <i>Feedback</i> to <i>New</i></li></ul> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=86842012-04-17T12:15:25ZPierre BLONDEAUpierre.blondeau@unicaen.fr
<ul></ul><p>I have a similar problem on 2.1-DEVELOPMENT (i386) built on Tue Apr 10 21:11:54 EDT 2012.</p>
<p>13 IPv4 carp OK<br />3 IPv6 are Master on both server.</p>
<p>Regards</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=86852012-04-17T14:48:42ZSeth Mosseth.mos@dds.nl
<ul></ul><p>The last good snapshot is from <a class="external" href="http://files.pfsense.org/jimp/ipv6/">http://files.pfsense.org/jimp/ipv6/</a></p>
<p>I'm still running the snapshots from Nov 25th on 3 carp clusters.</p>
<p>Another issue that I've managed to reproduce on another carp cluster is that FreeBSD 8.3 will stop responding to Neighbor Discovery requests and thus the CARP vips will wall from the internet, so if you have a static route pointing at a carp vip everything behind it, it will become unreachable.</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=87082012-04-18T06:07:41ZPierre BLONDEAUpierre.blondeau@unicaen.fr
<ul></ul><p>I have this problem, but only on one of my carp ipv6 addresses and only a few machines (not all).<br />I thought it was from my configuration, but it appears to be identical.</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=87102012-04-18T07:05:38ZSeth Mosseth.mos@dds.nl
<ul></ul><p>Can you check if the CARP vip address is in the NDP table of any of the other machines?</p>
<p>On linux <a class="external" href="http://tldp.org/HOWTO/Linux+IPv6-HOWTO/x1162.html">http://tldp.org/HOWTO/Linux+IPv6-HOWTO/x1162.html</a><br /><pre>
# ip -6 neigh show
</pre><br />That should show the CARP IPv6 vip in there.<br />On FreeBSD<br /><pre>
#ndp -a
</pre></p>
<p>if the IPv6 CARP vips do not show in the clients or servers then it means that FreeBSD is not responding to ND requests.</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=87112012-04-18T07:15:23ZPierre BLONDEAUpierre.blondeau@unicaen.fr
<ul></ul><p>on the one where it works : <br />ip -6 neigh show<br />2001:xxx:yyy::1 dev eth0 lladdr 00:00:5e:xx:xx:xx router DELAY<br />on the other :<br />ip -6 neigh show<br />2001:xxx:yyy::1 dev eth0 FAILED<br />I have 10 / 36 machines which can't join the router CARP Ipv6 ( All linux debian squeeze up to date).</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=87142012-04-18T09:28:42ZPierre BLONDEAUpierre.blondeau@unicaen.fr
<ul></ul><p>I have found the difference, it's the uptime of client. If I restart them all, IPv6 will not work on them.</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=87292012-04-19T08:15:04ZSeth Mosseth.mos@dds.nl
<ul></ul><p>Jim found a very descriptive similar issue on Open that appears to hit the exact same thing.<br /><a class="external" href="http://old.nabble.com/carp-ipv6-ndp-issue-td32201650.html">http://old.nabble.com/carp-ipv6-ndp-issue-td32201650.html</a></p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=87392012-04-19T14:42:45ZSeth Mosseth.mos@dds.nl
<ul><li><strong>Status</strong> changed from <i>New</i> to <i>Feedback</i></li></ul><p>The latest snapshot I ran off by hand seems to do the trick with the updated CARP patches.</p>
<p><a class="external" href="http://iserv.nl/files/pfsense/releng83/pfSense-Full-Update-2.1-DEVELOPMENT-i386-20120419-1059.tgz">http://iserv.nl/files/pfsense/releng83/pfSense-Full-Update-2.1-DEVELOPMENT-i386-20120419-1059.tgz</a></p>
<p>Pierre, can you verify this?</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=87672012-04-23T11:50:35ZPierre BLONDEAUpierre.blondeau@unicaen.fr
<ul></ul><p>Hy,<br />It's works for me ! Thank you very much !<br />Have you a idea of the date of integration in official image ?<br />Regards</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=89452012-05-22T03:50:52ZSeth Mosseth.mos@dds.nl
<ul></ul><p>Still hitting the double master issue in the Xs4all DC carp</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=89462012-05-22T03:51:39ZChris Buechlercbuechler@gmail.com
<ul><li><strong>Status</strong> changed from <i>Feedback</i> to <i>New</i></li></ul> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=89472012-05-22T03:54:14ZChris Buechlercbuechler@gmail.com
<ul></ul><p>Ermal - you can put the time to Coltex</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=90532012-06-01T17:10:19ZChris Buechlercbuechler@gmail.com
<ul><li><strong>Status</strong> changed from <i>New</i> to <i>Feedback</i></li><li><strong>Assignee</strong> deleted (<del><i>Ermal Luçi</i></del>)</li></ul><p>Andrew working on this</p> pfSense - Bug #2278: IPv6 Carp vip both master on FreeBSD 8.3https://redmine.pfsense.org/issues/2278?journal_id=94402012-07-05T18:31:30ZJim Pingle
<ul><li><strong>Status</strong> changed from <i>Feedback</i> to <i>Resolved</i></li></ul><p>This has been OK for a while now, several production carp clusters running and no dual master any more.</p>