Re: [pfSense] massive CARP Failover

2017-06-08 Thread Espen Johansen
If you want more help with this then you need to provide a network diagram and some details. Are your switches linked? If not then that is your problem. Did you disable mac spoofing on your switches? What make and model are your switches. Did you do any LACP bonding between switches? Since your

Re: [pfSense] massive CARP Failover

2017-06-08 Thread Daniel
https://www.dropbox.com/s/pq953p0wbsfseu7/Screenshot%202017-06-08%2011.19.07.png?dl=0 Yes i am sure ;) -- Grüsse Daniel Am 08.06.17, 01:12 schrieb "List im Auftrag von Espen Johansen" : Are you sure you disabled IGMP

Re: [pfSense] massive CARP Failover

2017-06-07 Thread Espen Johansen
Are you sure you disabled IGMP completely? On Wed, Jun 7, 2017, 16:44 Mark Wiater wrote: > > > On 6/7/2017 10:10 AM, Daniel wrote: > > Hi, > > > > the Sync interface is connected directly without a Switch. > > But Carp is running WAN/LAB for example. > > Let's go back

Re: [pfSense] massive CARP Failover

2017-06-07 Thread Mark Wiater
On 6/7/2017 10:10 AM, Daniel wrote: > Hi, > > the Sync interface is connected directly without a Switch. > But Carp is running WAN/LAB for example. Let's go back to your original email, this behavior can be duplicated with different software, it's not a pfSense issue. Is that right? Both Sophos

Re: [pfSense] massive CARP Failover

2017-06-07 Thread Daniel
Hi, the Sync interface is connected directly without a Switch. But Carp is running WAN/LAB for example. -- Grüsse Daniel Am 07.06.17, 16:04 schrieb "List im Auftrag von Espen Johansen" : I assume you did a pfsync (HA)

Re: [pfSense] massive CARP Failover

2017-06-07 Thread Espen Johansen
I assume you did a pfsync (HA) interface on each firewall? If so did you connect this directly without going thru the switch? A direct connection is prefered for the sync interface. Also make sure that if you do direct connection then use a 6ft cable first to connect them. Some interfaces have

Re: [pfSense] massive CARP Failover

2017-06-07 Thread Ivo Tonev
Can tou send network diagram? Why 2 switches? How they are connected? There are any feature like Cisco's arp inspection? Em 7 de jun de 2017 10:45, "Daniel" escreveu: > Both are Physical. > > -- > Grüsse > > Daniel > > Am 07.06.17, 14:34 schrieb "List im Auftrag von Ivo

Re: [pfSense] massive CARP Failover

2017-06-07 Thread Daniel
Both are Physical. -- Grüsse Daniel Am 07.06.17, 14:34 schrieb "List im Auftrag von Ivo Tonev" : Firewalls are virtual or physical servers? On Wed, Jun 7, 2017 at 9:12 AM, Daniel wrote:

Re: [pfSense] massive CARP Failover

2017-06-07 Thread Ivo Tonev
Firewalls are virtual or physical servers? On Wed, Jun 7, 2017 at 9:12 AM, Daniel wrote: > Hi, > > Firewall on the Switch is the latest installed. > The Switch is just simple installed. No VLANS actually just IGMP disabled. > Carp has for sure 3 IPs. 2 Dedicated for each

Re: [pfSense] massive CARP Failover

2017-06-07 Thread Daniel
Hi, Firewall on the Switch is the latest installed. The Switch is just simple installed. No VLANS actually just IGMP disabled. Carp has for sure 3 IPs. 2 Dedicated for each Server and one CARP (Virtual Failover per Subnet) -- Grüsse Daniel Am 06.06.17, 00:04 schrieb "List im Auftrag von

Re: [pfSense] massive CARP Failover

2017-06-05 Thread WebDawg
On Fri, Jun 2, 2017 at 8:13 AM, Daniel wrote: > Hi there, > > i run 2 pfsense Firewalls. I tried to use CARP but it will turn over every > 1-2-3 hours. > Sometimes it is so fast the pf1 is master and pf2 has the routes. In this > case I need to reboot the both Servers. > >

Re: [pfSense] massive CARP Failover

2017-06-05 Thread Ugo Bellavance
On 2017-06-02 08:13 AM, Daniel wrote: Hi there, i run 2 pfsense Firewalls. I tried to use CARP but it will turn over every 1-2-3 hours. Sometimes it is so fast the pf1 is master and pf2 has the routes. In this case I need to reboot the both Servers. After I tried a lot id ont find any

[pfSense] massive CARP Failover

2017-06-02 Thread Daniel
Hi there, i run 2 pfsense Firewalls. I tried to use CARP but it will turn over every 1-2-3 hours. Sometimes it is so fast the pf1 is master and pf2 has the routes. In this case I need to reboot the both Servers. After I tried a lot id ont find any solutions. I took a different brand (Sophos