OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • Bridge + CARP + High Availability
« previous next »
  • Print
Pages: [1]

Author Topic: Bridge + CARP + High Availability  (Read 2647 times)

mitra7

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Bridge + CARP + High Availability
« on: September 26, 2018, 05:09:55 pm »
I have two OPNSense installations in High Availability.
I setup CARP on the Master Server in a Bridged interface. Both machines have the bridge interface which is br0.
When both machines synchronize the backup server loses the Interface on CARP. Is this a new problem?
I have a second CARP using regular interfaces and it synchronizes fine.

Server 1 (Master)


Server 2 (Backup)
« Last Edit: September 26, 2018, 06:37:41 pm by mitra7 »
Logged

mitra7

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: Bridge + CARP + High Availability
« Reply #1 on: September 28, 2018, 11:39:25 am »
Do I need to open an issue on Github? Is there any more information that I should provide?
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6340
  • Karma: 436
    • View Profile
Re: Bridge + CARP + High Availability
« Reply #2 on: September 28, 2018, 11:43:14 am »
Never used CARP and Bridge, do you use a dedicated Uplink for Sync and PF stats? Screenshots of both CARP status? Anything related in the system.log?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

mitra7

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: Bridge + CARP + High Availability
« Reply #3 on: September 28, 2018, 11:50:21 am »
I get this notice:
"09-26-18 22:22:32 [ Interface specified for the virtual IP address 192.168.XX.250 does not exist. Skipping this VIP. ]"
However if I disable Virtual IPs Synchronization and I assigned the interface manually on the Backup server (Virtual IP/Carp Settings) it works just fine.

bridge0 (Master Server)
Quote
bridge0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500
   ether 02:e5:3e:f9:7c:00
   inet 192.168.XX.254 netmask 0xffffff00 broadcast 192.168.XX.255
   inet 192.168.XX.250 netmask 0xffffff00 broadcast 192.168.XX.255 vhid 1
   nd6 options=1<PERFORMNUD>
   carp: MASTER vhid 1 advbase 1 advskew 0
   groups: bridge
   id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15
   maxage 20 holdcnt 6 proto rstp maxaddr 2000 timeout 1200
   root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0
   member: ovpns3 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
           ifmaxaddr 0 port 12 priority 128 path cost 2000000
   member: vtnet1 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
           ifmaxaddr 0 port 2 priority 128 path cost 2000


bridge0 (Backup Server)
Quote
bridge0: flags=8943<UP,BROADCAST,RUNNING,PROMISC,SIMPLEX,MULTICAST> metric 0 mtu 1500
   ether 02:a7:7b:d3:48:00
   inet 192.168.XX.251 netmask 0xffffff00 broadcast 192.168.XX.255
   inet 192.168.XX.250 netmask 0xffffff00 broadcast 192.168.XX.255 vhid 1
   nd6 options=1<PERFORMNUD>
   carp: BACKUP vhid 1 advbase 1 advskew 100
   groups: bridge
   id 00:00:00:00:00:00 priority 32768 hellotime 2 fwddelay 15
   maxage 20 holdcnt 6 proto rstp maxaddr 2000 timeout 1200
   root id 00:00:00:00:00:00 priority 32768 ifcost 0 port 0
   member: ovpns3 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
           ifmaxaddr 0 port 10 priority 128 path cost 2000000
   member: vtnet1 flags=143<LEARNING,DISCOVER,AUTOEDGE,AUTOPTP>
           ifmaxaddr 0 port 2 priority 128 path cost 2000

« Last Edit: September 28, 2018, 11:54:26 am by mitra7 »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6340
  • Karma: 436
    • View Profile
Re: Bridge + CARP + High Availability
« Reply #4 on: September 28, 2018, 11:55:09 am »
What about the rest of the questions?
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

mitra7

  • Newbie
  • *
  • Posts: 13
  • Karma: 0
    • View Profile
Re: Bridge + CARP + High Availability
« Reply #5 on: September 28, 2018, 11:59:01 am »
I don't use a dedicated uplink for SYNC but I can create. For SYNC I am using the same interface (Bridge0).
It might be due to ovpns3 on the Backup Server is down because it is a Site-To-Site TAP VPN, I can't have both servers connected at the same time to the VPN Server.
I just don't understand why because if I assign manually the interface on the backup server it stays there.
I was checking and the same interface is not assigned on the Gateways section if it was updated through sync, manually works.
« Last Edit: September 28, 2018, 12:21:27 pm by mitra7 »
Logged

mimugmail

  • Hero Member
  • *****
  • Posts: 6340
  • Karma: 436
    • View Profile
Re: Bridge + CARP + High Availability
« Reply #6 on: September 28, 2018, 01:27:02 pm »
Sorry, I'm out here, I never used OpenVPN to bridge LANs, and I have no idea how this would break in a HA screnario and what happens on a failover. This is a ver rare untypical setup.
Logged
Twitter: mimu_muc
WWW: www.routerperformance.net
Support plans: https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German): https://opnsense.max-it.de/

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 18.7 Legacy Series »
  • Bridge + CARP + High Availability
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2