Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - niei

#1
Hi Everyone,

After upgrading my secondary firewall to 26.7 I noticed that the default gateway switching no longer works automatically.
I have two gateways configured, the WAN Router and the HA Interface IP of the Primary Firewall. The Idea is as long as the WAN Router is reachable (so, as long as the firewall has the virtual ip of the wan interface) it uses that as the default gateway. But as soon as the WAN Router is no longer reachable it should use the HA IP of the Primary Firewall (which in turn then has the virutal ip to talk to the WAN Router) as the default gateway and so access the Internet over the HA Link.

To explain; This whole setup is to only use one IP Address in the WAN Network, so that when I finally get fiber Internet and can scrap my Provider Router, I can use only singluar IP and don't have to buy a whole /29 Subnet or somthing like that.

However, after the upgrade of my secondary Firewall I noticed that it couldn't check for updates. I switched to mirror and still, no connectivity. So I tried pinging 8.8.8.8 and behold: Doesn't work.

I checked to Routing table (routing-table.png) and I see that it still has the IP Address of the WAN Router (192.168.1.1) as the default Gateway. Even though the Gateway Configuration Page (gw-conf.png) states correctly that the WAN Router is down and that the HA IP of the primary Firewall should be the active default gateway. And yes, I checked, the HA IP Gateway is a default gateway candidate (ha_ip-conf.png) and default gateway switching is enabled in the system settings (system-settings.png).

The only way it switches to the HA IP as the default gateway is when I manually disable the WAN Router in the Gateway configuration. Even then, It doesn't switch back to the WAN Router when the secondary firewall gets the Virtual IP and I have to now manually disable the HA IP Gateway.

And yes, I rebooted the secondary firewall manually after the update to see if that would fix the issue. It didnt.

What gives?

FYI, on my Primary Firewall, running 26.1.11_6, the behaivour is as expected. So I think it must have something todo with the 26.7 Update.
#2
Hi Everyone,

I noticed that when my firewalls fail over for a update or when I force a CARP failover my RDP Session disconnects.
I have configured the State Sync on both Firewalls (see attached fw01-hasettings.png and fw02-hasettings.png) but the state counts on the secondary do not match the primary by a long shot! Around 70'000 states on the primary and around 30 states on the secondary.
The Firewalls Rules should be in place to allow the state sync.
  On both Firewalls -> Allow IPv4 PFSYNC Any Source Any Port to Any Dest Any Port

FYI; My secondary Firewall (fw02) is master of the CARP IPs at the moment, i don't know why, but the state sync problem occured before this problem. The state sync also has never worked previsously I think.
FYI2; The firewalls are connected via a direct lagg with 5 1g copper cables.

Best Regards,
niei
#3
Hi Patrick

Thank you very much for your Help!
That solved it! i added HA to the listen Interfaces. =)

I wonder how it worked before, when i initially set up the synchronization.

Anyways, have a nice rest of the weekend.

Best Regards,
niei
#4
Hi everyone,

I am having a problem with my HA Setup between two Sophos XG210 running OPNSense 24.7.9_1-amd64.
The CARP failover and configuration works great. However the Config/State Sync between the two firewall doesn't seem to work. When I try to "Perform synchronization" in System -> High Availability -> Settings, the page loads for about ~75 seconds and then displays the message "The backup firewall is not accessible or not configured.
" even though i can see traffic being allowed on the second firewall and the configuration (ip addresses and password) being correct.

Anyone experiencing the same strangeness?

See attached fw02-logs.png, fw01-config.png and fw02-config.png and fw02-rules.png

Regards,
niei