Op 20-6-2012 5:34, Jerome Alet schreef:
Hi,
On Tue, Jun 19, 2012 at 08:35:38AM +0200, Seth Mos wrote:
Op 18-6-2012 23:26, Jerome Alet schreef:
So now that I'm trying to replicate the OpenBSD configuration on my
pfSense 2.1 boxes, I'm wondering if I really need 3 distinct IP
addresses on each vlan and what are the consequences of using only one
on the carp interface ?
For pfSense you definitely need 3 addresses per vlan.
Thanks for your answer.
No, maybe a stupid question... Is it mandatory that all three addresses
are in the same subnet, or is it possible to have the virtual one in a
different subnet than the two real ones (still all three would be on
the same vlan, but on different subnets) ?
Mandatory, how would the pfSense firewall itself reach the internet for
DNS and updates? It can't source everything from the CARP vip. Although
theoretically the traffic going through the firewall should be
unaffected. It's a crapshoot though that generally does not work too well.
We hope that the CARP overhaul that is included in FreeBSD9 will help us
in this case, but we can't guarantee that it will work this way either.
Regards,
Seth
___
List mailing list
List@lists.pfsense.org
http://lists.pfsense.org/mailman/listinfo/list