Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
16.7 Legacy Series
»
Update HA pair
« previous
next »
Print
Pages: [
1
]
Author
Topic: Update HA pair (Read 9881 times)
yomeyo
Newbie
Posts: 8
Karma: 0
Update HA pair
«
on:
November 15, 2016, 04:44:53 pm »
Hi,
I currently run 2 OPNsense 16.7.0 instances in active/standby using CARP and pfSync. There are updates available. Is there any best practices method available for updating a HA setup of OPNsense?
«
Last Edit: November 15, 2016, 04:55:12 pm by yomeyo
»
Logged
yomeyo
Newbie
Posts: 8
Karma: 0
Re: Update HA pair
«
Reply #1 on:
January 18, 2017, 02:15:18 pm »
Does anyone have experience with this? Thanks.
Logged
andresmeliann
Newbie
Posts: 4
Karma: 0
Re: Update HA pair
«
Reply #2 on:
January 18, 2017, 02:57:26 pm »
Hi, Im sorry I bother you, but as you are more advanced than I into HA using OPNSENSE 16.7, Im having some issues to making works HA, because I do it like the documentation and it doesnt work fine, apparently it synchronize well but secundary firewall saw Virtual IP via another interface, even it have conectivity between all interfaces inter firewall. If you could give the configuration you use or a guide I will be very gracefull.
Thanks for you help
Logged
bartjsmit
Hero Member
Posts: 2014
Karma: 194
Re: Update HA pair
«
Reply #3 on:
January 18, 2017, 07:13:55 pm »
Active/passive cluster patching follows a common set of steps:
1. Negotiate a short downtime with your users
2. Patch your passive node
3. Fail over the cluster
4. Fail back if any issues
5. Patch the remaining node
Be wary of version anxiety; make sure the updates fix issues or vulnerabilities that apply to you.
Bart...
Logged
yomeyo
Newbie
Posts: 8
Karma: 0
Re: Update HA pair
«
Reply #4 on:
January 20, 2017, 04:10:22 pm »
Hi Bart, thanks for the reply. Do you know how to failover to the other device other than unplugging or shutting down the active node?
Thanks.
Logged
bartjsmit
Hero Member
Posts: 2014
Karma: 194
Re: Update HA pair
«
Reply #5 on:
January 21, 2017, 03:48:44 pm »
Those are the recommended actions for fail-over. Unplugging the LAN is quicker to revert than shutting down but harder to do remotely ;-)
Bart...
Logged
yomeyo
Newbie
Posts: 8
Karma: 0
Re: Update HA pair
«
Reply #6 on:
January 23, 2017, 09:44:15 am »
Yes, but how to update if the LAN is unplugged? If I replug the LAN it will switch back to being the active node.
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
Archive
»
16.7 Legacy Series
»
Update HA pair