Тёмный

Configuring HA for a pFSense Firewall 

VMNerd
Подписаться 3,2 тыс.
Просмотров 23 тыс.
50% 1

The purpose of this video is to provide a tutorial video on configuring HA for a pFSense Firewall. If you are following along make sure you watch our Installing a Routing Firewall with pFSense on ESX • Installing Routing Fir... . These video's will work with both virtual and physical pFSense firewalls as long as you pay attention to the interfaces. Let me know what you think about my video.
Check out our website at www.vmnerd.com

Наука

Опубликовано:

 

19 сен 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 43   
@DJjamiejvmasta
@DJjamiejvmasta 6 лет назад
I'm struggling for a few days with CARP / pfsync and this video is very informative and straightforward. Sub from me.
@simonjones3224
@simonjones3224 6 лет назад
Very well detailed and tested to demo all features - Great Vid!
@VMNerd
@VMNerd 6 лет назад
Thank You for your feedback ...
@GeorgeMiamiUSA
@GeorgeMiamiUSA 7 лет назад
Very well detailed, congratulations helped me a lot in clarifying some doubts
@VMNerd
@VMNerd 7 лет назад
Thank You for the feedback ... I am glad I can provide clarity.
@residuevideos
@residuevideos 5 лет назад
I wish you used simpler IP addresses for this. It is very distracting. But thumbs up, very detailed video. Thank you.
@VMNerd
@VMNerd 5 лет назад
Thank You for the feedback.
@evlarette
@evlarette 4 года назад
Thank you so much,, its help me a lot, I just get stuck when de WAN CARP status is Master and Backup, but the LAN CARP status is Master on both
@VMNerd
@VMNerd 4 года назад
Honestly I am not sure when I see master master I reboot the secondary.
@LalGebi
@LalGebi 5 лет назад
Thanks... But what if I want to configure HA for two ISP ? Where to configure WAN1 and WAN2 virtual CARP IP
@VMNerd
@VMNerd 5 лет назад
Yes, this is possible; However "the dreaded words" you would need a couple of things: 1. Your own ASN "Autonomous System Number" and IP block. 2. Your ISP(s) would have to agree to let you route your IP block from there network.
@VMNerd
@VMNerd 5 лет назад
Are you trying to get the external outside users to connect to CARP or is this for internal users to NAT outbound. Can you provide a little more on your use case "scenario".
@jimstowe8994
@jimstowe8994 6 лет назад
Great Video this really helped me set up my two old machines - (Intel pentiums and 2G Ram) I also bought used Intel Nics for each and the setup works really well. My question is about packages. If I wish to use squid do I need to install and configure the package on each machine. I presume the answer is yes, and if so does that apply to all other packages. Once again thanks for a great training session.
@VMNerd
@VMNerd 6 лет назад
Technically you can install on both firewalls and CARP should sync them. You will need to load the package on each firewall.
@RealLaughingMan101
@RealLaughingMan101 6 лет назад
you should see if you can get a pi cluster working as a pf router
@VMNerd
@VMNerd 6 лет назад
That would be interesting It would probably be a good video if I could pull it off. Thank You for the feedback.
@lontownsend3012
@lontownsend3012 6 лет назад
I have never done this before, but I am assuming that we have one internet connection being split between two firewalls for failover? Does each FW have to have a certain number of NICs in order to work? One for WAN, one for LAN, and one for HA, shared between the FWs?
@VMNerd
@VMNerd 6 лет назад
Yes - for this to work you would need 3 internet usable IP addresses that the WAN interfaces can use. You will need 3 private IP addresses for the LAN. 2 ip addresses for the HA. The other interfaces can be RFC1918/Private IP Addresses that will hide behind the usable IP addresses. Each firewall will get an IP address for the interfaces WAN, LAN and HA. The WAN and LAN will each have a shared IP address also known as a VIP
@lontownsend3012
@lontownsend3012 6 лет назад
so I built this and put it into our office production, afterhours. For some reason the client couldnt ping google. dhcp and dns are handled by another onsite server, not pfsense. outbound nat is using my carp wan. port forward might be an issue b/c dest. addresses are pointed at different public ip aliases.
@nigelivey5067
@nigelivey5067 8 лет назад
Am I right in thinking "states" are not persistent once failover kicks in, ie: the state table isn't syncd??
@VMNerd
@VMNerd 8 лет назад
The states of the firewalls should be in sync. when in HA mode. The first option in the HA Availability Sync screen enables that communication. You also need to make sure that the users are using the VIP for the trusted interface and the VIP for the Internet interface is defined as the NAT IP for the users and localhost.
@MhNetSecurity
@MhNetSecurity 6 лет назад
Thank you for the video , I have question please : As far as I understand the only way for the second pfsense to be active is the complete dead of the master pfsense.What if there is issue with only WAN Interface ( cable disconnected or something) and the LAN is still working or WAN is ok but LAN is disconnected , Is there any way to switch to the second firewall?
@VMNerd
@VMNerd 6 лет назад
Let me lab this scenario and I will post my results .. you should failover but cannot say 100% .. I do know there is an option to manually failover under the CARP diagnostics area.
@MhNetSecurity
@MhNetSecurity 6 лет назад
Thank you for your reply , I'll wait
@Spoonuk666
@Spoonuk666 6 лет назад
Can you configure pfsense to use both WAN links at the same time i.e. active/active as opposed to failover? I would like to setup two hardware appliances with 1 WAN each and actively load balance between the two..
@VMNerd
@VMNerd 6 лет назад
Yes, you can select the balancing to round robin or other options. This might be a cool one to make a video on ...
@dugbarteysappor6312
@dugbarteysappor6312 6 лет назад
Thanks for the video. I have a question for you. Can this setup be implemented with a multi home WAN connection with /30 mask from different ISPs?
@VMNerd
@VMNerd 6 лет назад
I would say technically yes this would work you just need to make sure that you NAT both outbound interfaces and let the load balancing happen within the pfsense software.
@dugbarteysappor6312
@dugbarteysappor6312 6 лет назад
VMNerd Okay. Thanks. Will give it a try
@ferdericole8661
@ferdericole8661 6 лет назад
Thanks alot for the detailed video. I'm doing basically exactly the same setup as you did in the vid except i use physical machines and everything is working fine so far, except DHCP doesnt work at all. I've been looking around for solutions on the internet for a while now, maybe you or someone else can help. I have configured it correctly on both machines (rather on one and it synced to the slave as intended), the dhcp service is up and running, but the one client i attached to the LAN to test DHCP doesn't receive an IP Address/Gateway/DNS at all. In the DHCP service log it says "DHCPDISCOVER from "max-address of the client" via LAN1: peer holds all free leases" - this message pops up on BOTH pfsense-machienes at exactly the same times (times are synced ofc) did the client you use for the tests/example in the video have a static IP? oder did it receive one via dhcp? any kind of help is much appreciated
@VMNerd
@VMNerd 6 лет назад
I will need to replicate in my LAB. If you have a facebook account message me.
@abdraoufx
@abdraoufx 7 лет назад
the second box (backup) is only connected to the master right!? the backup is not connected to the network! how the connection path through the powered off master!? is it the fact that the network card still working!!? just curious
@VMNerd
@VMNerd 7 лет назад
For CARP to work correctly you need to have a dedicated carp interface that both firewalls that can talk to each other on. Also you should only need to enable CARP on one side and the other will automatically pull all the CARP enabled items. Each firewall master and slave will need it's own IP's and matching interfaces that have there own dedicated ip addresses. The VIP's are the ones that will be synced to each other.
@abdraoufx
@abdraoufx 7 лет назад
+VMNerd in other words, the backup only connected the master by the Ha interface. the backup is not connected to the network it's only connected through the master, so what physically make the backup path through to network when the master is powered off.
@VMNerd
@VMNerd 7 лет назад
Sorry both systems need to be connected to the network. Each system will have it's own dedicated management IP address for each interface you are assigning. The CARP IP addresses will fail between them when one of the two devices go offline at least it should.
@skawashkar
@skawashkar 7 лет назад
So will the slave take all the ip address of the master interfaces exactly during the failover?
@VMNerd
@VMNerd 7 лет назад
As long as the communication exists between the firewalls. PFSense secondary will take over all CARP interfaces if the primary becomes on unavailable or the primary is put into maint. mode. The client should be pointed to a CARP interface for gateway and outbound NAT. Hope this help points you in the right direction.
@skawashkar
@skawashkar 7 лет назад
Yes partly. because apart from the allow any to any rule for both the CARP interface I don't see see the outbound NAT rule configured anywhere. I can't see it in any docs though.
@VMNerd
@VMNerd 7 лет назад
This NAT configuration should be under the firewall menu as an item labeled NAT. Check for outbound and then set it to manual. Inside the NAT configuration you will have to specify the outbound subnet your client is coming from and define the CARP VIP as the gateway IP. Hope this helps !!
@skawashkar
@skawashkar 7 лет назад
My LAN side CARP vip is doing it's job fine. I am only having one usable static IP address from my ISP. How can I make that static IP switch between the primary and secondary as carp VIP?
@VMNerd
@VMNerd 7 лет назад
You will need 3 IP addresses because the VIP is floating your device will need a static and a gateway assigned to each wan gateway.
@gabrielepizzigati8797
@gabrielepizzigati8797 7 лет назад
very bad video quality. can you provide hd video quality?
@VMNerd
@VMNerd 7 лет назад
All videos have an HD option click on the setting icon in the video select the quality option and you should see as high as 1080p. Hope this helps point you in the right direction.
Далее
How To Setup ACME SSL with HAProxy on PFSense
37:18
Просмотров 25 тыс.
Inside Star Citizen: Alpha 4.0 - Engineering
16:38
Просмотров 89 тыс.
How To Configure A Transparent Proxy Using PFSense
18:49
Всё, Nintendo Switch 2 СЛИЛИ
11:01
Просмотров 31 тыс.
... #android #smartphone #error
0:16
Просмотров 503 тыс.
Всё, Nintendo Switch 2 СЛИЛИ
11:01
Просмотров 31 тыс.
ИГРОВЫЕ НОУТБУКИ ОПАСНЫ? 😮
0:45