OPNsense Forum

Archive => 17.7 Legacy Series => Topic started by: Tigger on October 04, 2017, 10:54:29 pm

Title: 17.7.4 - no web proxy config replication in HA mode
Post by: Tigger on October 04, 2017, 10:54:29 pm
Hi guys.

Installed two 17.7.4 boxes in HA mode and had encountered strange behavior. When i change some settings (fw rules, nat rules, gw settings, etc.) on main box it replicates to backup box instantly except one thing: web proxy. When i change web proxy settings on main box, they keep unchanged on the backup box until reboot, or even do not replicate at all. Is that a bug, or maybe i have forgotten to do something ?
Title: Re: 17.7.4 - no web proxy config replication in HA mode
Post by: franco on October 05, 2017, 08:57:25 am
Hi Tigger,

The setting for "web proxy" sync is there, which could mean only one thing:

The sync is not always executed on web proxy settings changes.

Furthermore, I don't believe the proxy is being restarted automatically as originally the HA sync was for the essential firewall part of the network. But that is something that may be able to change in the future.

Does that help to make more sense in your case?


Cheers,
Franco
Title: Re: 17.7.4 - no web proxy config replication in HA mode
Post by: Tigger on October 05, 2017, 03:21:35 pm
The sync is not always executed on web proxy settings changes.
But why ?

Furthermore, I don't believe the proxy is being restarted automatically
Squid service restart doesn't do the trick, only the full reboot. And even this doesn't help every time.
Title: Re: 17.7.4 - no web proxy config replication in HA mode
Post by: franco on October 09, 2017, 11:16:18 pm
Organic growth of components can do that. We could also name it oversight, out of scope or sloppiness... either way we rely on issue reports and feature requests to advance, so yay for new stuff to write and ship. :)

Can you please add a ticket for this on GitHub?

https://github.com/opnsense/core


Thanks,
Franco
Title: Re: 17.7.4 - no web proxy config replication in HA mode
Post by: Kali on November 14, 2017, 07:42:48 pm
anyway for user side is not really clear
i have also noticed saving and apply a firewall rule (even without a change) do the synchronization

i guess this should apply for all or most of the service, could be clearer and easier to handle an apply button which sync conf and restart the service in both appliance?