HA issue with 2 virtual opnsense on the same ESXi

Started by hoangthanhnt, August 05, 2025, 03:57:04 AM

Previous topic - Next topic
I am configuring HA with 2 virtual opnsense running on the same Vmware ESXi 8
2 Opnsense seems to be configured correctly, I tried to disconnect the LAN (or WAN) interface on the Primary Node and saw the status of the Secondary node changed to Master, the Primary node changed to Backup status, when restoring the LAN/WAN interface, the Primary node was restored to Master status (of course, at this time the Secondary node changed to Backup status. Moreover, I can synchronize the configuration from the Primary node to the Secondary node successfully.
However, I have problems accessing from client machines in the LAN (all clients have gateways set as LAN VIP), the abnormal signs are as follows:
- If pinging 8.8.8.8 from the client, the client will receive duplicate responses (x2)
- I found that internet traffic is generated on both the Primary node and the Secondary node, as I understand it, both the Primary node and the Secondary node are performing LAN VIP and WAN reception VIP.
On ESXi I have configured Accept for the options: Promiscuous mode, MAC Address changes and Forged transmits