OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 20.1 Legacy Series »
  • ha sync - firewall rule sync after upgrade not working
« previous next »
  • Print
Pages: [1]

Author Topic: ha sync - firewall rule sync after upgrade not working  (Read 3205 times)

spark5

  • Newbie
  • *
  • Posts: 18
  • Karma: 1
    • View Profile
ha sync - firewall rule sync after upgrade not working
« on: March 03, 2020, 02:09:46 pm »
hi guys,
we are new with opnsense, came from pfsense,
i setup an ha cluster with 2 nodes and 2 wan links, wan failover.

everything is running fine.
now i upgraded to the last version 20.X.
after that the sync via xmlrpc is not running automatically. i change somethin on the master and nothing happens.
if i restart configd.py, the changes are done on the other node, so this is generally working.

i can see nothing in the logfiles:
 Mar 3 10:32:46 vm-prod-firewall-01.vlan.r-m.de configd.py: [76fdc2a3-da19-46e8-b1ff-a27bc1a73996] request osfp
 Mar 3 10:32:46 vm-prod-firewall-01.vlan.r-m.de configd.py: [7e095e9a-4908-4006-b84d-5931b87b3011] Syncing firewall load
 Mar 3 10:32:46 vm-prod-firewall-01.vlan.r-m.de configd.py: [cea7058c-fe31-4d75-ba58-5bd7f717c5e9] request pf rules

also tcpdump does not show any traffic.

the only warning in the log is see is:
configd.py: encode idna: unable to decode XXX, return source
XXX are a group of alias. these are working and i saw this message also on 19.X.

can you please help me, where i can have a look. feeling blind :)

thanks,
ronny
Logged

spark5

  • Newbie
  • *
  • Posts: 18
  • Karma: 1
    • View Profile
Re: ha sync - firewall rule sync after upgrade not working
« Reply #1 on: March 03, 2020, 02:28:37 pm »
hi, i found: https://forum.opnsense.org/index.php?topic=15906.msg72837#msg72837 is auto sync not working anymore?
Logged

spark5

  • Newbie
  • *
  • Posts: 18
  • Karma: 1
    • View Profile
Re: ha sync - firewall rule sync after upgrade not working
« Reply #2 on: March 03, 2020, 02:54:01 pm »
https://opnsense.org/about/road-map/
 HASync only on command (legacy cleanup)

really?
Logged

AdSchellevis

  • Administrator
  • Hero Member
  • *****
  • Posts: 907
  • Karma: 184
    • View Profile
Re: ha sync - firewall rule sync after upgrade not working
« Reply #3 on: March 03, 2020, 02:57:24 pm »
yes, as usual, you can find more background about choices we have made in the past on GitHub https://github.com/opnsense/core/issues/3635

Best regards,

Ad
Logged

spark5

  • Newbie
  • *
  • Posts: 18
  • Karma: 1
    • View Profile
Re: ha sync - firewall rule sync after upgrade not working
« Reply #4 on: March 03, 2020, 03:16:52 pm »
ok, you should put this into the release note

thanks
Logged

AdSchellevis

  • Administrator
  • Hero Member
  • *****
  • Posts: 907
  • Karma: 184
    • View Profile
Re: ha sync - firewall rule sync after upgrade not working
« Reply #5 on: March 03, 2020, 03:49:01 pm »
yes, we should and we did.... https://github.com/opnsense/changelog/blob/master/doc/20.1/20.1.r1#L29
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 20.1 Legacy Series »
  • ha sync - firewall rule sync after upgrade not working
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2