Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
High availability
»
Public or Private IP on the WAN side?
« previous
next »
Print
Pages: [
1
]
Author
Topic: Public or Private IP on the WAN side? (Read 4260 times)
geo
Newbie
Posts: 11
Karma: 0
Public or Private IP on the WAN side?
«
on:
May 13, 2021, 11:11:50 pm »
Hello,
A bit about me so you know where I'm coming from
I'm a home networking enthusiast and have been running OPNsense for several years now and want to learn about and deploy HA.
I'm just starting my education on this topic and I've looked at the OPNsense CARP documentation and also documentation from PF project and I see a disconnect on the WAN side of the firewall cluster.
The OPNsense documentation (see attached image) shows private IP address 172.18.x.x, while documentation from the other project shows public IP addresses 198.51.100.200-202 (see attached image).
I'm trying to rationalize the discrepancy between the documentation. Are 3 real IPs needed or can private IPs be used? In orther words, can HA be achived with one (1) ISP-assigned IP address via DHCP fed to a switch that then splits that into private IPs as shown in the OPNsense documentation?
Thank you for any advise and insight
Logged
bartjsmit
Hero Member
Posts: 2018
Karma: 194
Re: Public or Private IP on the WAN side?
«
Reply #1 on:
May 14, 2021, 07:59:54 am »
OPNsense doesn't care about the RFC 1918 status of subnets other than optionally blocking them on the WAN side. If you don't need to route packets on the internet, you can use RFC 1918 ranges for them.
CARP traffic is almost certainly private, WAN less so
Bart...
Logged
clarknova
Full Member
Posts: 101
Karma: 6
Re: Public or Private IP on the WAN side?
«
Reply #2 on:
June 17, 2021, 11:54:30 pm »
Quote
Are 3 real IPs needed or can private IPs be used?
You must use 3 IPs that are valid on the subnet you are trying to communicate with. So if that's a public network, then you need 3 IP addresses in that subnet. If it's on a public network, then you need 3 IPs in that subnet.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
High availability
»
Public or Private IP on the WAN side?