Project

General

Profile

Actions

Bug #4439

closed

CARP does not Sync IP Alais to Backup firewall

Added by Glen Arason about 9 years ago. Updated about 9 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
02/18/2015
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:

Description

I have a working 2 FW CARP setup with pfSense 2.2 and a /28 subnet of available ip addresses.

The Virtual IP Aliases are not syncing to the backup firewall when additions or changes are made.
In the High Availability Section, "Synchronize Virtual IPs" is checked.

Contrary to what I have read about similar issue, adding and editing other rules does not add or update the virtual IPs on the backup.
Performing a reboot on the Primary and Backup also does not update the backup Virtual IPs.

Manually adding the Virtual IPs to the backup works fine and are retained through reboots and other additions and updates.

The major concern is when you later add an IP Alias and forget to you also have to add it to the backup you will have issues in failover mode.

I posted this issue in the forums but have not received any feedback:
[[https://forum.pfsense.org/index.php?topic=88781.0]]

Glen

Actions #1

Updated by Jim Pingle about 9 years ago

  • Status changed from New to Rejected

The VIP types that are supposed to sync work properly: CARP VIPs, IP Aliases using a CARP VIP as their parent interface, and IP Aliases using Localhost as their parent interface. Plain IP Alias type VIPs do not sync and should not sync as it creates an IP conflict. Please provide more detail about your configuration on the forum thread and wait for confirmation before opening a bug report.

Actions

Also available in: Atom PDF