ixl3: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=6000a8<VLAN_MTU,JUMBO_MTU,VLAN_HWCSUM,RXCSUM_IPV6,TXCSUM_IPV6> ether 48:8e:ef:d8:c5:7f hwaddr 48:8e:ef:d8:c5:7f inet6 fe80::4a8e:efff:fed8:c57f%ixl3 prefixlen 64 scopeid 0x4 nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> media: Ethernet autoselect (1000baseT <full-duplex>) status: activelo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384 options=600003<RXCSUM,TXCSUM,RXCSUM_IPV6,TXCSUM_IPV6> inet6 ::1 prefixlen 128 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x5 inet 127.0.0.1 netmask 0xff000000 nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> groups: loenc0: flags=0<> metric 0 mtu 1536 nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> groups: encpflog0: flags=100<PROMISC> metric 0 mtu 33160 groups: pflogpfsync0: flags=0<> metric 0 mtu 1500 groups: pfsync syncpeer: 224.0.0.240 maxupd: 128 defer: offixl3_vlan220: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 ether 48:8e:ef:d8:c5:7f inet6 fe80::4a8e:efff:fed8:c57f%ixl3_vlan220 prefixlen 64 scopeid 0x9 inet 192.168.220.12 netmask 0xffffff00 broadcast 192.168.220.255 inet 192.168.220.1 netmask 0xffffff00 broadcast 192.168.220.255 vhid 2 nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> media: Ethernet autoselect (1000baseT <full-duplex>) status: active vlan: 220 vlanpcp: 0 parent interface: ixl3 carp: BACKUP vhid 2 advbase 1 advskew 100 groups: vlanixl3_vlan221: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 ether 48:8e:ef:d8:c5:7f inet6 fe80::4a8e:efff:fed8:c57f%ixl3_vlan221 prefixlen 64 scopeid 0xa inet 192.168.221.12 netmask 0xffffff00 broadcast 192.168.221.255 inet 192.168.221.1 netmask 0xffffff00 broadcast 192.168.221.255 vhid 1 nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> media: Ethernet autoselect (1000baseT <full-duplex>) status: active vlan: 221 vlanpcp: 0 parent interface: ixl3 carp: BACKUP vhid 1 advbase 1 advskew 100 groups: vlanixl3_vlan123: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 ether 48:8e:ef:d8:c5:7f inet6 fe80::4a8e:efff:fed8:c57f%ixl3_vlan123 prefixlen 64 scopeid 0xb inet 192.168.123.12 netmask 0xffffff00 broadcast 192.168.123.255 inet 192.168.123.1 netmask 0xffffff00 broadcast 192.168.123.255 vhid 4 nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> media: Ethernet autoselect (1000baseT <full-duplex>) status: active vlan: 123 vlanpcp: 0 parent interface: ixl3 carp: MASTER vhid 4 advbase 1 advskew 100 groups: vlanixl3_vlan222: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500 ether 48:8e:ef:d8:c5:7f inet6 fe80::4a8e:efff:fed8:c57f%ixl3_vlan222 prefixlen 64 scopeid 0xc inet 10.0.1.12 netmask 0xffffff00 broadcast 10.0.1.255 inet 10.0.1.10 netmask 0xffffff00 broadcast 10.0.1.255 vhid 3 nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL> media: Ethernet autoselect (1000baseT <full-duplex>) status: active vlan: 222 vlanpcp: 0 parent interface: ixl3 carp: MASTER vhid 3 advbase 1 advskew 100
igb1: link state changed to DOWNcarp: 3@igb1_vlan221: MASTER -> INIT (hardware interface down)carp: demoted by 240 to 240 (interface down)igb1_vlan221: link state changed to DOWNcarp: 1@igb1_vlan220: MASTER -> INIT (hardware interface down)carp: demoted by 240 to 480 (interface down)igb1_vlan220: link state changed to DOWNcarp: 4@igb1_vlan222: MASTER -> INIT (hardware interface down)carp: demoted by 240 to 720 (interface down)igb1_vlan222: link state changed to DOWNcarp: 2@igb1_vlan230: MASTER -> INIT (hardware interface down)carp: demoted by 240 to 960 (interface down)igb1_vlan230: link state changed to DOWNigb1: link state changed to UPcarp: 3@igb1_vlan221: INIT -> BACKUP (initialization complete)carp: demoted by -240 to 720 (interface up)igb1_vlan221: link state changed to UPcarp: 1@igb1_vlan220: INIT -> BACKUP (initialization complete)carp: demoted by -240 to 480 (interface up)igb1_vlan220: link state changed to UPcarp: 4@igb1_vlan222: INIT -> BACKUP (initialization complete)carp: demoted by -240 to 240 (interface up)igb1_vlan222: link state changed to UPcarp: 2@igb1_vlan230: INIT -> BACKUP (initialization complete)carp: demoted by -240 to 0 (interface up)igb1_vlan230: link state changed to UPifa_maintain_loopback_route: deletion failed for interface igb1_vlan221: 3ifa_maintain_loopback_route: deletion failed for interface igb1_vlan221: 3carp: 3@igb1_vlan221: BACKUP -> INIT (hardware interface up)igb1_vlan221: promiscuous mode disabledcarp: 2@igb1_vlan230: BACKUP -> MASTER (master timed out)ifa_maintain_loopback_route: insertion failed for interface igb1_vlan230: 17carp: 4@igb1_vlan222: BACKUP -> MASTER (master timed out)ifa_maintain_loopback_route: insertion failed for interface igb1_vlan222: 17carp: 1@igb1_vlan220: BACKUP -> MASTER (master timed out)ifa_maintain_loopback_route: insertion failed for interface igb1_vlan220: 17carp: demoted by 240 to 240 (pfsync bulk start)carp: demoted by -240 to 0 (pfsync bulk done)ifa_maintain_loopback_route: deletion failed for interface igb1_vlan220: 3ifa_maintain_loopback_route: deletion failed for interface igb1_vlan220: 3carp: 1@igb1_vlan220: MASTER -> INIT (hardware interface up)igb1_vlan220: promiscuous mode disabledcarp: demoted by 240 to 240 (pfsync bulk start)carp: 4@igb1_vlan222: MASTER -> BACKUP (more frequent advertisement received)ifa_maintain_loopback_route: deletion failed for interface igb1_vlan222: 3carp: 2@igb1_vlan230: MASTER -> BACKUP (more frequent advertisement received)ifa_maintain_loopback_route: deletion failed for interface igb1_vlan230: 3ifa_maintain_loopback_route: deletion failed for interface igb1_vlan222: 3ifa_maintain_loopback_route: deletion failed for interface igb1_vlan222: 3ifa_maintain_loopback_route: deletion failed for interface igb1_vlan222: 3carp: 4@igb1_vlan222: BACKUP -> INIT (hardware interface up)igb1_vlan222: promiscuous mode disabledcarp: demoted by -240 to 0 (pfsync bulk done)carp: 2@igb1_vlan230: BACKUP -> MASTER (preempting a slower master)ifa_maintain_loopback_route: deletion failed for interface igb1_vlan230: 3ifa_maintain_loopback_route: deletion failed for interface igb1_vlan230: 3carp: 2@igb1_vlan230: MASTER -> INIT (hardware interface up)igb1: promiscuous mode disabledigb1_vlan230: promiscuous mode disabledcarp: demoted by 240 to 240 (pfsync bulk start)carp: demoted by -240 to 0 (pfsync bulk done)
Code: [Select] carp: BACKUP vhid 2 advbase 1 advskew 100 carp: BACKUP vhid 1 advbase 1 advskew 100 carp: MASTER vhid 4 advbase 1 advskew 100 carp: MASTER vhid 3 advbase 1 advskew 100
carp: BACKUP vhid 2 advbase 1 advskew 100 carp: BACKUP vhid 1 advbase 1 advskew 100 carp: MASTER vhid 4 advbase 1 advskew 100 carp: MASTER vhid 3 advbase 1 advskew 100
It is preferable that one firewall handle the forwarding of all the traffic, therefore the advskew on the backup firewall's carp(4) vhids should be set to something higher than the primary's.
advskew 0 is an optional parameter specifying how much to skew the advbase when sending CARP advertisements. The default value of advbase is one(1) which equates to sending a CARP advertisement 1/256 of a second. If the advskew is zero(0) then the advbase plus advskew still equals one; CARP advertisements will be sent out one per second. By manipulating advskew, the master CARP host can be chosen or forced. The lower the advskew value, the MORE preferred the host will be when choosing a master. The default is 0. Acceptable values are from 0 to 254. Notice the advskew on the master is 0 and the advskew on the backup is 100. If the BACKUP firewall (fw1) ever becomes the master the CARP advertisements will be sent out once every 1.391 seconds (advbase of 1 plus skew of 100/256 seconds).