[pfSense Support] CARP - battle of the firewalls

2006-07-14 Thread Alastair Stevens
Title: CARP - battle of the firewalls Hi again We're gradually getting closer to our desired setup: 2 pfSense boxes with CARP failover, each with multiple LAN interfaces and load-balanced dual WANs.  This is obviously quite a complex setup, and getting it all working at once seems elusive -

RE: [pfSense Support] CARP - battle of the firewalls

2006-07-14 Thread Holger Bauer
model and vendor? Holger -Original Message- From: Alastair Stevens [mailto:[EMAIL PROTECTED] Sent: Friday, July 14, 2006 12:44 PM To: support@pfsense.com Subject: [pfSense Support] CARP - battle of the firewalls Hi again We're gradually getting closer to our desired setup: 2 pfSense

Re: [pfSense Support] CARP - battle of the firewalls

2006-07-14 Thread Royce Mitchell III
Alastair Stevens wrote: Hi again We're gradually getting closer to our desired setup: 2 pfSense boxes with CARP failover, each with multiple LAN interfaces and load-balanced dual WANs. This is obviously quite a complex setup, and getting it all working at once seems elusive - but we're almo

Re: [pfSense Support] CARP - battle of the firewalls

2006-07-14 Thread Bill Marquette
Spanning tree port lockout will nail you pretty hard with CARP. Make sure your switch ports (if managed switches) are in port fast. Also, make sure that you haven't inadvertantly turned on port security and limited the port to a single MAC (each CARP VHID uses a MAC along with the physical inter

Re: [pfSense Support] CARP - battle of the firewalls

2006-07-14 Thread Royce Mitchell III
Bill Marquette wrote: Spanning tree port lockout will nail you pretty hard with CARP. Make sure your switch ports (if managed switches) are in port fast. Also, make sure that you haven't inadvertantly turned on port security and limited the port to a single MAC (each CARP VHID uses a MAC along

Re: [pfSense Support] CARP - battle of the firewalls

2006-07-14 Thread Bill Marquette
On 7/14/06, Royce Mitchell III <[EMAIL PROTECTED]> wrote: ever see any of the packets in question ), would it be advisable to give each carp interface a dedicated switch, or is it safe for example, to hook both LAN interfaces to the aforementioned D-Link, which is a 24-port gigabit unmanaged swit

Re: [pfSense Support] CARP - battle of the firewalls

2006-07-14 Thread Royce Mitchell III
Bill Marquette wrote: On 7/14/06, Royce Mitchell III <[EMAIL PROTECTED]> wrote: ever see any of the packets in question ), would it be advisable to give each carp interface a dedicated switch, or is it safe for example, to hook both LAN interfaces to the aforementioned D-Link, which is a 24-po

RE: [pfSense Support] CARP - battle of the firewalls

2006-07-17 Thread Alastair Stevens
Title: RE: [pfSense Support] CARP - battle of the firewalls Hi - well this sounds interesting, though not very encouraging!  The whole thing is set up on a test bench at the moment, and as it happens, we are using *different* types of switches on different interfaces.  The LANs are using 24

Re: [pfSense Support] CARP - battle of the firewalls

2006-07-17 Thread Bill Marquette
On 7/17/06, Alastair Stevens <[EMAIL PROTECTED]> wrote: Hi - well this sounds interesting, though not very encouraging! The whole thing is set up on a test bench at the moment, and as it happens, we are using *different* types of switches on different interfaces. The LANs are using 24-port Net