Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
General Discussion
»
Swapping master and slave (CARP pfsync)
« previous
next »
Print
Pages: [
1
]
Author
Topic: Swapping master and slave (CARP pfsync) (Read 372 times)
uucico
Newbie
Posts: 3
Karma: 0
Swapping master and slave (CARP pfsync)
«
on:
March 26, 2024, 02:21:57 am »
Hi,
I have two pfsync'd CARP routers and unfortunately it happend that I made the instance on a virutalisation environment labelled "SECONDARY" the master (and thus, the backup on "PRIMARY") and this heavily confuses people (trying to configure on the backup device).
Do I understand correctly that the configuration changes are applied directly on the backup device, so that I can simply swap the side who has the pfsync IP of the other side? Or are there traps I should watch out for?
Thanks for reading and any hints appreciated!
«
Last Edit: March 26, 2024, 02:23:52 am by uucico
»
Logged
Monviech (Cedrik)
Global Moderator
Hero Member
Posts: 1593
Karma: 176
Re: Swapping master and slave (CARP pfsync)
«
Reply #1 on:
March 28, 2024, 03:57:35 pm »
The configurations of master and backup firewalls are seperate.
That means, if somebody adds new configurations to the backup firewall, they are stored on it, but they won't be present on the master firewall.
Though there are sections of the config that get auto generated to be different on the backup firewall than on the master firewall. For example the CARP VIPs, which have different advskew values (these determine which of these IPs become master or backup).
If Syncing back, you should only include sections in the XMLRPC sync that don't have this automatic behavior, like firewall rules, nat rules, etc...
Or, you export the backup firewall config, and import it on the master firewall with only the sections selected you know have changed.
Then afterwards, if both firewalls are completely the same, it might be worth a shot (maybe make snapshots beforehand if you can, or backups) to export the configuration of both firewalls, and then import the master configuration on the firewall which should become the new master, and the backup configuration on the new backup firewall.
«
Last Edit: March 28, 2024, 04:08:11 pm by Monviech
»
Logged
Hardware:
DEC740
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
General Discussion
»
Swapping master and slave (CARP pfsync)