OPNsense Forum

English Forums => High availability => Topic started by: GreenMatter on March 23, 2026, 08:42:34 PM

Title: Duplicated data flow
Post by: GreenMatter on March 23, 2026, 08:42:34 PM
With your assistance in previous topics, I got HA in working condition, but...

To describe my setup:

In order to change above configuration and (trying to) test my issue, I created additional LAN bridge for backup instance and instead of having them (2x opnsense) connected over single linux bridge - within proxmox, I connected them over physical switch.
This of course requires second downlink:

But problem I'm facing is duplicated communication/data flow to and from both VMs; both instances have same looking graphs in proxmox webgui - network flow and also cpu. Despite they don't change their master/backup status (no flapping at carp status) I have something similar to split brain situation, for example if I communicate with opnsense webgui or ssh on carp vip interface, reply comes either from one of those two and toggles every few seconds. If I ping them, reply is duplicated ("DUP!"). Communication to other hosts and WAN is ok.  I have already set Mac filter to "no" in proxmox VM's firewall options (pve firewall is disabled). I tried ovs and Linux bridges with same results.

To me, it is something related to MAC and network switches; is it possible to set it up correctly?

Title: Re: Duplicated data flow
Post by: GreenMatter on March 25, 2026, 08:47:21 AM
One more thing to add is when I reach my LAN over VPN (either Wireguard or OpenVPN) I can't communicate with backup instance (its physical interface addresses) at all while FW rules allow them to send requests to any hosts...
Title: Re: Duplicated data flow
Post by: GreenMatter on April 10, 2026, 03:34:31 PM
So, for those who may experience similar issues: