OPNsense Forum

English Forums => High availability => Topic started by: Zugschlus on November 06, 2025, 12:03:17 PM

Title: Red Square in /ui/core/hasync_status on OpenVPN instances but sync seems fine
Post by: Zugschlus on November 06, 2025, 12:03:17 PM
Hi,
I have a cluster of two OPNsense machines running 25.1.10 (I know, later). I have two OpenVPN instances configured. The OpenVPN instances seem to sync fine, so do the associated certificates seem to sync just fine. But in /ui/core/hasync_status, the two OpenVPN instances show a red square where all other services have a green arrow:
2025-11-06_12-02.png
That doesn't look nice. What is going on here and how can I make those two pieces of red vanish?
Greetings
Marc Haber
Title: Re: Red Square in /ui/core/hasync_status on OpenVPN instances but sync seems fine
Post by: Patrick M. Hausen on November 06, 2025, 12:31:24 PM
Did you explicitly specify the bind address for the instance as the CARP address on WAN? In that case the service cannot start on the standby until a failover happens. That's what the UI is telling you. Not "broken", just "stopped".

If you leave the bind address empty, everything should be green.

The HA implementation is pretty straightforward and does in general not mess with e.g. reconfiguring services on failover. The upside is it is really robust and easy to understand and debug.

Services should generally listen to INADDR_ANY (0.0.0.0) for robust binding to a socket and leave it to firewall rules to control accessability on various interfaces.

If that bothers you, I suggest binding OpenVPN to 127.0.0.1 and using NAT port forwarding from the WAN CARP address to that one.
Title: Re: Red Square in /ui/core/hasync_status on OpenVPN instances but sync seems fine
Post by: Zugschlus on November 06, 2025, 01:32:32 PM
Quote from: Patrick M. Hausen on Today at 12:31:24 PMDid you explicitly specify the bind address for the instance as the CARP address on WAN?

I first though "of course, Idiot Me", but I didn't.

2025-11-06_13-30.png

Any other ideas?

By the way, your additional input that I didn't quote was wildly helpful for me to understand OPNsense's philosophy. Appreciated.

Greetings
Marc
Title: Re: Red Square in /ui/core/hasync_status on OpenVPN instances but sync seems fine
Post by: Patrick M. Hausen on November 06, 2025, 01:36:38 PM
And if you click on the obvious "start" button, nothing changes?

Then it's time to check the logs on the standby, I guess, for why the services fail to start.