OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 20.1 Legacy Series »
  • Trouble with Virtual IP's
« previous next »
  • Print
Pages: [1]

Author Topic: Trouble with Virtual IP's  (Read 2189 times)

wmeter

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
Trouble with Virtual IP's
« on: July 24, 2020, 03:26:52 pm »

Hi,

I have a fixed public IP I receive from my ISP over DHCP. They have me 'linked' to a given MAC that I set as
hardware address and I receive w/o any problem my single fixed-IP address.

I asked them for a small subnet (/29) for 5 extra public IP's. I added these 5 additional IP's as aliases to the same DHCP - WAN interface. I tried both 'IP Alias' (as per the doc of OPNsense) and also CARP with a single node.

When I use 'IP Alias' everything works fine and with good performance for appox. 5 minutes, then it's like the IP address becomes 'unknown' and it stops working. When I open a shell on the box and type a ifconfig -a the aliases are still visible.

When I use CARP as virtual IP protocol the connection remains accessible, but with very bad performance and a lot of packet loss.

Any suggestions ?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Trouble with Virtual IP's
« Reply #1 on: July 24, 2020, 04:27:23 pm »
Quote from: wmeter on July 24, 2020, 03:26:52 pm

When I use 'IP Alias' everything works fine and with good performance for appox. 5 minutes, then it's like the IP address becomes 'unknown' and it stops working. When I open a shell on the box and type a ifconfig -a the aliases are still visible.


Can you give an example how you see that it becomes unknown? IP Alias should be the way to go.
Keep in mind you only need to add IP Alias if you want to bind local services to IP. If it's just port forwarding you can enter the IP in the rule and you are good.
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

wmeter

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
Re: Trouble with Virtual IP's
« Reply #2 on: July 24, 2020, 04:42:24 pm »
Ah, so I actually don't need the VIP if I just want an inbound NAT to e.g. propose a web-server or mail-server and just citing 'an IP' will do in the rule as long as ISP-wise I have that IP / subnet ?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6767
  • Karma: 494
    • View Profile
Re: Trouble with Virtual IP's
« Reply #3 on: July 24, 2020, 04:58:36 pm »
Correct
Logged
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

wmeter

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
Re: Trouble with Virtual IP's
« Reply #4 on: July 25, 2020, 09:32:26 am »
Worked a dream, many thanks for your help !

Issue with the only shortly working alias IP‘s was that I migrated from a virtual machine to a physical device and as always the problem was between the keyboard and the screen, using the same IP on two devices on the same VLAN is never a good idea if it’s not governed by CARP or something else ;-)

Thx !
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 20.1 Legacy Series »
  • Trouble with Virtual IP's
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2