OPNsense Forum

Archive => 24.1, 24.4 Legacy Series => Topic started by: opns-newb on March 21, 2024, 03:54:22 PM

Title: CARP Issue
Post by: opns-newb on March 21, 2024, 03:54:22 PM
Hello,

We have a setup of two opns firewalls (DEC4040's running opns-business 23.10.2) in a HA configuration. They are connected with direct pfsync interface and each have two WAN connections. We have five (5) CARP interfaces and a WAN Gateway Group configured on each.

The CARP interfaces are for our three internal subnets and our two WAN connections. We're experiencing an issue whereby if any of the WAN modems fails, all CARP interfaces are switching from the primary firewall (Master) to the backup firewall. Also, when the WAN modem comes back up, the CARP interfaces aren't automatically switching back to the primary firewall.

I've attached a diagram of our setup as a reference.

Any insight as to why this behavior is occurring would be greatly appreciated.

Thanks!
Title: Re: CARP Issue
Post by: opns-newb on March 21, 2024, 03:58:41 PM
Mods - can you please move this to the HA forum? Thank you!
Title: Re: CARP Issue
Post by: mimugmail on March 21, 2024, 10:25:18 PM
Screenshot of System : HA : Settings of both please
Title: Re: CARP Issue
Post by: opns-newb on March 21, 2024, 10:36:20 PM
opns-01 (primary firewall) HA settings are attached here.
Title: Re: CARP Issue
Post by: opns-newb on March 21, 2024, 10:36:47 PM
opns-02 (backup) is attached here.
Title: Re: CARP Issue
Post by: mimugmail on March 22, 2024, 08:26:27 AM
Looks good, then screenshot of Interfaces : Virtualisierung IPs : Status when backup didnt switch back
Title: Re: CARP Issue
Post by: opns-newb on March 22, 2024, 02:16:19 PM
Here's opns-01 (primary) CARP status page.
Title: Re: CARP Issue
Post by: opns-newb on March 22, 2024, 02:16:40 PM
Here's opns-02 (backup) CARP status page.
Title: Re: CARP Issue
Post by: mimugmail on March 22, 2024, 02:29:01 PM
Screenshots of this situation "Also, when the WAN modem comes back up, the CARP interfaces aren't automatically switching back to the primary firewall."
Title: Re: CARP Issue
Post by: opns-newb on March 22, 2024, 02:31:58 PM
I can't force the issue to happen now and take a screenshot since it's a production network.

But what does happen is that opns-02 (backup FW) becomes a Master on all CARP interfaces. The only way to get it to relinquish Master status is by temporarily disabling CARP on it to force it to switch back over to opns-01.