1
Hardware and Performance / Dual WAN/Dual router
« on: May 15, 2023, 09:13:10 pm »
tl;dr: How do you setup CARP where each router has its own modem, but under normal operation the modems are setup for load balancing.
Background: At my work data center, I configured CARP with two routers sharing a fixed /29 WAN block. It works great.
At home, I currently have a single router with dual WAN. My residential WAN providers use DHCP (cable) and PPPoE (DSL). Currently I use two gateway groups: one with cable in Tier 1 and DSL in Tier 2, the other gateway group with the Tiers reversed. Then I have firewall rules that pick the gateway group based on the traffic type, so that I can prioritize traffic on the different gateways.
Now I want to add a second opnsense router for high availability at home. Unless I'm missing something, I see no good way for me to setup CARP VIP for the WAN. What I'd like to do is connect each modem to a single router and setup a CARP VIP only for the LAN. And to handle the load balancing and WAN failover, I would setup opnsense2 as a second gateway for opnsense1, and vice versa, perhaps using a dedicated interface/LAN. Any further suggestions would be appreciated.
Background: At my work data center, I configured CARP with two routers sharing a fixed /29 WAN block. It works great.
At home, I currently have a single router with dual WAN. My residential WAN providers use DHCP (cable) and PPPoE (DSL). Currently I use two gateway groups: one with cable in Tier 1 and DSL in Tier 2, the other gateway group with the Tiers reversed. Then I have firewall rules that pick the gateway group based on the traffic type, so that I can prioritize traffic on the different gateways.
Now I want to add a second opnsense router for high availability at home. Unless I'm missing something, I see no good way for me to setup CARP VIP for the WAN. What I'd like to do is connect each modem to a single router and setup a CARP VIP only for the LAN. And to handle the load balancing and WAN failover, I would setup opnsense2 as a second gateway for opnsense1, and vice versa, perhaps using a dedicated interface/LAN. Any further suggestions would be appreciated.