OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Profile of WaffleIron »
  • Show Posts »
  • Messages
  • Profile Info
    • Summary
    • Show Stats
    • Show Posts...
      • Messages
      • Topics
      • Attachments

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

  • Messages
  • Topics
  • Attachments

Messages - WaffleIron

Pages: 1 [2]
16
High availability / Re: HA: with one WAN address possible
« on: December 28, 2022, 01:31:13 am »
Hi Grefabu,
Your question isn't necessarily about HA but rather CARP.  CARP is essentially the FreeBSD version of VRRP/HSRP and all of these protocols require three IP addresses to be used.  The unique IP assigned to each device is used to send keepalives to the other and negotiate who the master of the CARP VIP should be.  Specifically, each device will use their unique IP to send out a multicast message (224.0.0.18) with CARP related information (priority/skew, VIP, etc) and each box negotiates from there.

To do what you are asking, the opnsense team would need to completely reconfigure how HA works for the platform.  I'm not familiar with how Sophos works but to relate it to other...larger companies...HA would need to be re-tooled to function more like VSS/VPC where both boxes act logically as one unit instead of one box doing a "config sync" to the other.


17
High availability / HA and FRR
« on: December 24, 2022, 01:39:36 am »
Hello,
Looking for guidance on an issue I'm running into regarding HA sync and running FRR.

I have two opnsense boxes running in HA and both are running FRR (specifically BGP).  They are NOT running CARP.

From a design/functionality standpoint everything is working as expected.  However, when the XMLRPC sync occurs it forces a restart of the FRR services on the backup/slave which causes BGP sessions to drop and re-establish.  The master's FRR service continues to run fine.

How can I stop this from happening?  I even tried removing FRR from XMLRPC sync but the service restart still occurs.

Pages: 1 [2]
OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2