Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
High availability
»
Opnsense HA - Master loses connection to slave
« previous
next »
Print
Pages: [
1
]
Author
Topic: Opnsense HA - Master loses connection to slave (Read 971 times)
volrath87
Newbie
Posts: 7
Karma: 0
Opnsense HA - Master loses connection to slave
«
on:
February 20, 2024, 02:16:28 pm »
Hello,
i ve setup HA between 2 Firewalls on Interface1. FW01 and FW02 are connected directly via CrossOverCable.
ofc i ve configured rules on interface1 which allows traffic from fw01 to fw02 and vice versa.
The problem is after synchronisation the rule on fw02 (slave) dissappears and master (fw01) is not able to process any further syncronisation (because it is copied from master). I also tried to put the rule on master but it didn't help. I guess opnsense first removes the rule from slave and after then it is not able to synchronize anything.
How do you manage this?
BR
Logged
lshantz
Full Member
Posts: 109
Karma: 3
Re: Opnsense HA - Master loses connection to slave
«
Reply #1 on:
February 20, 2024, 11:42:49 pm »
I don't quite get what is happening, but perhaps you could flesh out the problem a little more? Even screen shots. Are you able to see got to System/Hi availability/status and see the data there? What do you see in the Dashboard etc.
Logged
volrath87
Newbie
Posts: 7
Karma: 0
Re: Opnsense HA - Master loses connection to slave
«
Reply #2 on:
February 21, 2024, 04:39:16 am »
ok let me describe it in another way
FW02 (slave) has a rule which allows traffic from FW01 on the "Synchronize Interface". Without that rule everything from FW01 is denied (default)
When FW01 synchronizes configurations to FW02 (System -> HA -> Settings -> Perform synchronization) that rule is removed and then connection between FW01 and FW02 is down.
I ve to say that i didn't setup carp for now. Maybe this is the issue?
«
Last Edit: February 21, 2024, 05:03:16 am by volrath87
»
Logged
volrath87
Newbie
Posts: 7
Karma: 0
Re: Opnsense HA - Master loses connection to slave
«
Reply #3 on:
February 21, 2024, 04:45:11 am »
Maybe there is a problem matching the interfaces of FW01 and FW02 ?
How does the synchronisation map firewall rules/interfaces from FW01 to the correct corresponding interface on FW02 ? By name? Or is there a mapping table?
Logged
lshantz
Full Member
Posts: 109
Karma: 3
Re: Opnsense HA - Master loses connection to slave
«
Reply #4 on:
February 21, 2024, 06:51:56 pm »
So we are talking the PFSYNC interface correct? I wonder if somehow the sync is causing the IP to be the same instead of .1 and .2. WAG at this poitnt
Logged
volrath87
Newbie
Posts: 7
Karma: 0
Re: Opnsense HA - Master loses connection to slave
«
Reply #5 on:
February 24, 2024, 04:21:29 am »
After setting up CARP VIP the synchronisation works.
Thanks for your feedback
Logged
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
High availability
»
Opnsense HA - Master loses connection to slave