Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
High availability
»
am I using CARP incorrectly?
« previous
next »
Print
Pages: [
1
]
Author
Topic: am I using CARP incorrectly? (Read 2370 times)
c-mu
Full Member
Posts: 210
Karma: 5
am I using CARP incorrectly?
«
on:
September 07, 2022, 10:52:38 am »
Hello,
I've been wondering for a while if I've been using CARP incorrectly for years and if I can't do better.
I have a lot of VLANs, currently around 80-100 I guess, mostly /29 networks for customer environments for security purposes.
Now I have also configured a CARP address for each VLAN, but is that really necessary?
Isn't it enough if I set up CARP only in the main network, for example, and set up a Virtual IP for all other interfaces/VLANs? As soon as a problem is detected in the main network, the master moves to the slave and with it all virtual IPs.
How would you do it?
Thank you!
Logged
coatmaker618
Newbie
Posts: 11
Karma: 0
Re: am I using CARP incorrectly?
«
Reply #1 on:
September 13, 2022, 06:38:52 pm »
I hope so! I'm looking to do something similar (with less VLANs) but I don't see how else you do it unless you can change state of all VLANs/networks on change of CARP state (after all, OPNSense is aware of the state of all networks)?
Logged
bimbar
Sr. Member
Posts: 435
Karma: 25
Re: am I using CARP incorrectly?
«
Reply #2 on:
September 14, 2022, 12:20:59 pm »
That is indeed the right way - CARP works, much like VRRP and HSRP, at layer 3.
Logged
meschmesch
Full Member
Posts: 184
Karma: 5
Re: am I using CARP incorrectly?
«
Reply #3 on:
October 01, 2022, 10:50:54 pm »
Does it harm to use only carp addresses instead of virtual IPs for the other VLANs? That's what I use currently and it works...
Logged
Patrick M. Hausen
Hero Member
Posts: 6810
Karma: 572
Re: am I using CARP incorrectly?
«
Reply #4 on:
October 04, 2022, 03:31:26 pm »
The expected setup is to use CARP on all interfaces. Why wouldn't you?
If it was Cisco IOS instead of OPNsense you would have HSRP or VRRP on all interfaces, too.
I honestly did not know that virtual addresses would switch nodes in case of a failover.
In fact: do they? Did anyone ever try?
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
Print
Pages: [
1
]
« previous
next »
OPNsense Forum
»
English Forums
»
High availability
»
am I using CARP incorrectly?