OPNsense Forum

Archive => 18.1 Legacy Series => Topic started by: johjoh on March 13, 2018, 03:24:27 pm

Title: [SOLVED] Problem with VIP CARP MASTER redundancy
Post by: johjoh on March 13, 2018, 03:24:27 pm
Hello, I have two firewall with CARP VIP configured like the attached images.
On fw1 all IP are Master.
On fw2 3 IPs remain Master this 3 IPs simultaneously and I don't understand why?
If on fw1 I enter in CARP Maintenance Mode the fw2 becomes the Master on all IPs correctly.

Any help appreciated
Title: Re: Problem with VIP CARP MASTER redundancy
Post by: johjoh on March 27, 2018, 09:07:36 am
Anyone can help me?
Title: Re: Problem with VIP CARP redundancy
Post by: doug.dimick on March 27, 2018, 10:17:57 pm
Are you running OPNsense under VMware? If so, you may find this post (https://forum.opnsense.org/index.php?topic=7206.msg32304#msg32304) helpful.
Title: Re: Problem with VIP CARP MASTER redundancy
Post by: johjoh on March 28, 2018, 01:19:04 pm
No, two identical hardware with OPNsense installed bare metal
Title: Re: Problem with VIP CARP redundancy
Post by: 5q on March 29, 2018, 02:19:15 pm
hi johjoh,
sadly I cannot help, but I see the same behaviour in my setup. I am in the early stages -non-production- and followed the CARP setup guide closely. Still I often see "Master" on both nodes. Some manual intervention from the GUI fixes that, but this is not the way I would expect.
regards martin
Title: Re: Problem with VIP CARP MASTER redundancy
Post by: johjoh on March 29, 2018, 06:17:07 pm
The other problem is that the connection speed slow down because both want to be the master.
Problem with OpenVPN, both reply on WAN.
If you shutdown, for example, the backup firewall, the connection speed drastically increase.
Title: [SOLVED] Re: Problem with VIP CARP MASTER redundancy
Post by: johjoh on April 27, 2018, 04:10:38 pm
The problem was the switch installed on WAN
Extreme Network X430
https://www.extremenetworks.com/product/x430-series/ (https://www.extremenetworks.com/product/x430-series/)

Changed with another and the problem was gone, I think is IGMP Snooping problem like this post
https://doc.pfsense.org/index.php/CARP_Configuration_Troubleshooting#Switch.2FLayer_2_Issues (https://doc.pfsense.org/index.php/CARP_Configuration_Troubleshooting#Switch.2FLayer_2_Issues)