Quote from: EricPerl on February 02, 2025, 09:24:11 PMThe symptoms of "not working" are not particularly clear, in particular this:QuoteOther devices on the VLAN just created can't reach the firewall, and only the firewall.
My understanding is that HA with a pair is a hack (no quorum).
Have you tried without (in case sync is introducing some weirdness)?
Hej Eric. Not working means not receiving an IP from the DHCP server on that interface. Or, if I set a static IP address, not reaching the firewall with a ping (and yes, the rule for ICMP is there).
Yes, I am aware HA is not perfect. You really need to know how to navigate the potential pitfalls. IPsec will only transfer after DPD kicks in, for example. But it does the job acceptably well. For me it is mostly to be able to apply updates with minimal disruption, and handle hardware breakdown. As I mentioned in my OP, was a pfSense customer before, and was hit by the Intel Atom C2000 issue. It allowed me to keep business going, and replace the hardware at my convenience.