Re: [pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-16 Thread Vick Khera
On Tue, Apr 16, 2013 at 8:48 AM, James Bensley jwbens...@gmail.com wrote: Does anyone have any ideas about some sort of no preempt option for CARP so that if the master fails, and everything switches over to the You would need to adjust the advskew on the old master to be higher than that of

Re: [pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-16 Thread Vick Khera
Theo Schlossnagle has started a new project to manage shared IP addresses, but the one thing it doesn't have is moving all IPs as a group. ie, if LAN goes down, it wouldn't move WAN also. however, I'm sure that kind of feature could be added in. i don't know if it is suitable to be adding node.js

Re: [pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-15 Thread Vick Khera
On Sat, Apr 13, 2013 at 3:58 PM, James Bensley jwbens...@gmail.com wrote: If I am connect to a LAN host from outside using SSH for example, and I pull out the master, my SSH sessions stops working. Do the boxes not sync NAT tables and states etc? I loose any active TCP connections. I had

Re: [pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-15 Thread Chris Buechler
On Mon, Apr 15, 2013 at 7:23 AM, Vick Khera vi...@khera.org wrote: On Sat, Apr 13, 2013 at 3:58 PM, James Bensley jwbens...@gmail.com wrote: If I am connect to a LAN host from outside using SSH for example, and I pull out the master, my SSH sessions stops working. Do the boxes not sync NAT

Re: [pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-15 Thread James Bensley
On 15 April 2013 15:29, James Bensley jwbens...@gmail.com wrote: Although my tests aren' proving successful so far. I meant to say; I am pulling a file via SCP from a host in the LAN to a host on the WAN. If I disable CARP on the master to force a fail over to the backup, there is a pause, and

[pfSense] CARP / VIP Failover Queries (NAT sessions and no preempt?)

2013-04-13 Thread James Bensley
Hi all, I have two pfSense 2.0.2 firewalls using CARP for active / passive fail-over with virtual IPs. This is working fine; Pinging the WAN or LAN shared IP and pulling the power plug on the master causes a short delay, then the ping's resume as the backup firewall has promoted its self to