HA syncing issue

Started by fearz, October 27, 2025, 07:49:23 PM

Previous topic - Next topic
October 27, 2025, 07:49:23 PM Last Edit: October 27, 2025, 08:42:05 PM by fearz
Hi,

Using latest opnsense 25.7.6 on both boxes with dedicated pfsync interface, i have 6 other identical interfaces on both boxes (same identifier, same name), in HA options i selected Firwall rules, virtual ips (and other stuff) on primary when i manually sync or even via cron (every 5 min.), i have this in logs:

opnsense/usr/local/etc/rc.filter_synchronize: Filter sync successfully completed with https://10.0.0.2:9443/xmlrpc.php.

on secondary:

2025-10-27T22:33:55Noticesyslog-ngConfiguration reload finished;
2025-10-27T22:33:55Noticesyslog-ngConfiguration reload request received, reloading configuration;
2025-10-27T22:33:54Warningopnsense/xmlrpc.php: warning: ignoring missing default tunable request: hw.ibrs_disable
2025-10-27T22:33:54Warningopnsense/xmlrpc.php: warning: ignoring missing default tunable request: vm.pmap.pti
2025-10-27T22:33:53Noticeroot/usr/local/etc/rc.d/suricata: WARNING: failed to start suricata
2025-10-27T22:33:51Noticeopnsense/xmlrpc.php: plugins_configure monitor (execute task : dpinger_configure_do(,null))
2025-10-27T22:33:51Noticeopnsense/xmlrpc.php: plugins_configure monitor (,null)

My problem is that I don't think anything is syncing, not the firewall rules or virtual ips or anything, i just noticed it recently, when i created a new interface on both boxes, allowed any any to carp even ipv4 any any, i created some rules, and none of them were created on the backup box, same interface identifier, same name.

How can I investigate the issue?



Some of message are similar in my cluster. Tried to delete a disabled firewall rule on LAN and synchronize the cluster. The slave remains the same.

So, there are  some syncing issue after some of last upgrades.