Home
Help
Search
Login
Register
OPNsense Forum
»
English Forums
»
High availability
»
HA Configuration not syncing to backup server
« previous
next »
Print
Pages: [
1
]
2
Author
Topic: HA Configuration not syncing to backup server (Read 2017 times)
cdsane
Newbie
Posts: 27
Karma: 1
HA Configuration not syncing to backup server
«
on:
July 30, 2024, 08:41:44 pm »
I have configured my OPNsense HA on to servers master and backup, both firewalls indicate master and backup as it is suppose to be but the issue is that when I try to perform a sync to the backup firewall I get an error message saying backup firewall is not configured but I have. What could be the possible issue for this error also the master firewall was existing before I added the backup firewall but the CARP configuration was configured the same day.
Logged
Patrick M. Hausen
Hero Member
Posts: 6810
Karma: 572
Re: HA Configuration not syncing to backup server
«
Reply #1 on:
July 30, 2024, 08:44:47 pm »
Do you have a decicated sync interface? What are the firewall rules on that one? Did you change the "listen interfaces" for the UI? The primary needs to login to the UI/API of the standby ...
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
cdsane
Newbie
Posts: 27
Karma: 1
Re: HA Configuration not syncing to backup server
«
Reply #2 on:
July 30, 2024, 11:19:09 pm »
Yes the interface for the sync i have named pfsync with IP 10.0.0.1 for master and 10.0.0.2 for backup.
The rule I have for the pfsync on the master is the PASS rule pushing all traffic out.
By "listen Interface" do you mean the Virtual IPs ?
The primary needs to login to the UI/API of the standby ...
I don't get this last part can you breakdown the question for me please
Logged
Patrick M. Hausen
Hero Member
Posts: 6810
Karma: 572
Re: HA Configuration not syncing to backup server
«
Reply #3 on:
July 30, 2024, 11:29:02 pm »
The UI must listen on the HA interface. And the HA interface should have an "allow * * in" rule.
For the UI: System > Settings > Administration > Listen interfaces. Leave at "All (recommended).
How do you think the primary syncs the config to the secondary? It literally logs in as root via HTTP ...
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
cdsane
Newbie
Posts: 27
Karma: 1
Re: HA Configuration not syncing to backup server
«
Reply #4 on:
July 31, 2024, 11:10:30 am »
1. The UI must listen on the HA interface. And the HA interface should have an "allow * * in" rule. : Yes that is what I have
2.For the UI: System > Settings > Administration > Listen interfaces. Leave at "All (recommended). : I have the same in my system
3. How do you think the primary syncs the config to the secondary? It literally logs in as root via HTTP
I don't understand this : Yes that is what I have done
Logged
Patrick M. Hausen
Hero Member
Posts: 6810
Karma: 572
Re: HA Configuration not syncing to backup server
«
Reply #5 on:
July 31, 2024, 11:29:59 am »
So ...
- The UI is listening on the HA interface on the standby? Check with `netstat -na|grep LISTEN`
- The standby has got an "allow all" rule on the HA interface?
- On the primary you entered 10.0.0.2, root, and the root password of the standby in System > High Availability > Settings?
Then it should work. If it doesn't:
- Can you ping the standby from the primary on the HA interface?
- Run tcpdump on the standby, HA interface, UI port, to watch if the primary tries to connect at all ...
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
cdsane
Newbie
Posts: 27
Karma: 1
Re: HA Configuration not syncing to backup server
«
Reply #6 on:
July 31, 2024, 12:07:30 pm »
Yes i am able to ping
and also I can see logs when I run tcpdump command on my backup opnsense firewalls shell
I get
94 packets captured
96 packets received by filter
0 packets dropped by kernel
Logged
Patrick M. Hausen
Hero Member
Posts: 6810
Karma: 572
Re: HA Configuration not syncing to backup server
«
Reply #7 on:
July 31, 2024, 12:13:38 pm »
Please post screenshots of
- the HA interface configuration of both firewalls
- the HA settings on the primary
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
cdsane
Newbie
Posts: 27
Karma: 1
Re: HA Configuration not syncing to backup server
«
Reply #8 on:
July 31, 2024, 12:46:12 pm »
Black interfaces Primary
White Interfaces backup
Logged
cdsane
Newbie
Posts: 27
Karma: 1
Re: HA Configuration not syncing to backup server
«
Reply #9 on:
July 31, 2024, 12:47:43 pm »
same as above
dark interface Primary
white backup
Logged
cdsane
Newbie
Posts: 27
Karma: 1
Re: HA Configuration not syncing to backup server
«
Reply #10 on:
July 31, 2024, 12:48:45 pm »
same as above
dark interface Primary
white backup
Logged
Patrick M. Hausen
Hero Member
Posts: 6810
Karma: 572
Re: HA Configuration not syncing to backup server
«
Reply #11 on:
July 31, 2024, 12:54:26 pm »
NAT and virtual IPs are not relevant at the moment.
pfsync interface settings of the standby are missing.
HA
settings
(not status!) of the primary are missing. System > High Availability > Settings
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
cdsane
Newbie
Posts: 27
Karma: 1
Re: HA Configuration not syncing to backup server
«
Reply #12 on:
July 31, 2024, 01:00:19 pm »
HA settings for primary
Logged
Patrick M. Hausen
Hero Member
Posts: 6810
Karma: 572
Re: HA Configuration not syncing to backup server
«
Reply #13 on:
July 31, 2024, 01:02:41 pm »
Leave "synchroinze peer IP" at 224.0.0.240 - no need to change that. Rest looks good assuming the root password is correct for the standby.
Can you show the firewall rules on the pfsync interface of the standby, please?
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do.
(Isaac Asimov)
cdsane
Newbie
Posts: 27
Karma: 1
Re: HA Configuration not syncing to backup server
«
Reply #14 on:
July 31, 2024, 01:06:21 pm »
i have attached the rule for the pfsync for the backup
Logged
Print
Pages: [
1
]
2
« previous
next »
OPNsense Forum
»
English Forums
»
High availability
»
HA Configuration not syncing to backup server