IP alias on CARP will end up as both master

Started by tryhard, April 24, 2020, 03:07:19 PM

Previous topic - Next topic
Hi,
regarding to

QuoteAdding multiple CARP IPs
If your provider offers you a subnet of public IP addresses and you want to expose them for NAT or different services running on your Firewall, you will also have to add them to your HA setup. Since adding a VHID for every IP would make the CARP traffic very noisy, you can also add a new IP Alias and choose the correct VHID where the first CARP IP is configured.

Note

IP Alias is not synchronized to slave, be sure to also add it to your second machine.

from https://wiki.opnsense.org/manual/how-tos/carp.html

I tried that, found that "IP Alias" will now also be synced to the slave firewall - so it looks like the note in the docs isn't up to date.

But on my setup it will mess the CARP IP with the shared VHID.

1. CARP VHID 50 works fine (State is Master/ Backup)
2. adding an IP Alias with  new IP in the same subnet of the carp using the same network mask
3. Syncing (IP Alias is showing on slave)
4. CARP VHID 50 will end up as Master/ Master

other CARPs with different VHID will continue to work fine.

Is there anything I should test /double check?
Or fill in a bug report ?

Regards

Hi!
Same situation for me too!
🙋🏻‍♂️