Public virtual address not working

Started by danbet, April 09, 2024, 04:11:13 PM

Previous topic - Next topic
When setting up the HA cluster, I followed the manual: https://docs.opnsense.org/manual/how-tos/carp.html, but I have a small problem that prevents me from putting the cluster into operation.

I cannot reach the public virtual address. However, if I have a VPN active for the IP address of one of the two devices, I can reach the virtual address of the LAN interface. When I am on site in the internal network, I can reach both the virtual address from the LAN and the one with the public IP address.

By reach I mean, on the one hand, pinging and, on the other hand, logging into the system via SSH.

I don't have any physical devices, both OPNsense's are implemented as VMs under VMware ESXi. The security settings MAC address changes and Forged transmits are allowed on the vSwitch.

What did I forget to configure?

I find the solution for VMware ESXi: I had to enable the promiscuous mode for all the interfaces. For this I created port groups to use only for the VM's with OPNsense.