OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • HA CARP with x.x.x.x/28 WAN Subnet
« previous next »
  • Print
Pages: [1]

Author Topic: HA CARP with x.x.x.x/28 WAN Subnet  (Read 3290 times)

mestafin

  • Newbie
  • *
  • Posts: 45
  • Karma: 2
    • View Profile
HA CARP with x.x.x.x/28 WAN Subnet
« on: January 19, 2018, 07:46:53 pm »
Gents,

I need some help please with 2 x OPNsense fw units in a HA CARP setup.

I have configured the HA CARP correctly and it works 100% with vlans and an IPsec Site-tot-Site link to our other site. Each fw has it's own public ip and then one public CARP VIP. The IPsec link also works with the CARP VIP defined on the WAN subnet.

We plan to use some of the other public WAN ip's with 1:1 NAT and vm's as mail and web servers, each with his own dedicated public IP from the WAN subnet. (This is how we had it previously on our HA Cisco ASA firewalls)

What is not clear to me, is how do I "CARP" the other public wan ip's?

Do I need 3 public ip's for each vm now - one per fw and one CARP VIP assigned to the vm?

Surely that can't be right?


Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6332
  • Karma: 435
    • View Profile
Re: HA CARP with x.x.x.x/28 WAN Subnet
« Reply #1 on: January 19, 2018, 08:32:16 pm »
You should be able to add IP alias to your existing VIP
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

mestafin

  • Newbie
  • *
  • Posts: 45
  • Karma: 2
    • View Profile
Re: HA CARP with x.x.x.x/28 WAN Subnet
« Reply #2 on: January 20, 2018, 01:46:44 am »
Quote from: mimugmail on January 19, 2018, 08:32:16 pm
You should be able to add IP alias to your existing VIP

Can you explain or expand this answer please?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6332
  • Karma: 435
    • View Profile
Re: HA CARP with x.x.x.x/28 WAN Subnet
« Reply #3 on: January 20, 2018, 06:35:08 am »
Firewall - Virtual IPs - Settings
Mode IP Alias

There you put in your IP address und below is the dropdown field for your VHID (the number you choosed when adding the VIP).

Thats it :)
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

mestafin

  • Newbie
  • *
  • Posts: 45
  • Karma: 2
    • View Profile
Re: HA CARP with x.x.x.x/28 WAN Subnet
« Reply #4 on: January 20, 2018, 10:11:30 am »
Thanks, now I am starting to get it.

One more question, when I define the CARP VIP or the VIP Alias, do I specify the netmask as /32 (single IP) or do I use the WAN subnet netmask /28 (the whole WAN subnet) ?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6332
  • Karma: 435
    • View Profile
Re: HA CARP with x.x.x.x/28 WAN Subnet
« Reply #5 on: January 20, 2018, 10:21:22 am »
I'd say /28
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 17.7 Legacy Series »
  • HA CARP with x.x.x.x/28 WAN Subnet
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2