Guide
Troubleshooting CARP Failover When Secondary Stays in BACKUP State on pfSense
Learn why a pfSense CARP secondary stays in BACKUP when the primary is offline and how to diagnose and fix the issue.
Published by Tasadduq Burney
07 Jul 2026, 18:23 UTC
4 min119.9K views0

Recognizable Condition
The secondary pfSense unit remains in the BACKUP state while the primary is powered off, disconnected, or otherwise unreachable. The CARP virtual IP (VIP) is not answered by either node, causing loss of the HA address.
Cause / Diagnostic Overview
| Possible Cause | What to Look For |
|---|---|
| CARP traffic blocked by firewall rules | Logs show dropped protocol 112 packets |
| Interface link down or missing IP | ifconfig shows no carrier or missing IP address |
| Mismatched VHID or password | CARP status shows authentication errors or different VHID |
| pfsync misconfiguration | pfsync interface errors or no SYNC state |
| Incorrect advskew/advbase | Secondary has equal or lower advskew than primary |
Ordered Checks
- View CARP status:
ifconfig carp0or Status → CARP in the web GUI. Look for state BACKUP and note advskew values. - Verify the physical interface:
ifconfig igb0(replace igb0 with your CARP‑enabled interface). Ensurestatus: activeand an IP address is present. - Check firewall logs for blocked CARP:
grep carp /var/log/filter.logor Diagnostics → System Logs → Firewall. Look for protocol 112 drops. - Confirm VHID and shared secret: System → High Avail. Sync → CARP Settings on both nodes. The VHID number and Password must be identical.
- Inspect pfsync:
ifconfig pfsync0(or the interface you use for pfsync). Look forstatus: activeandpeerfsyncmessages. In the GUI, Status → pfSync shows SYNC.
Fixes Tied to Findings
- Allow CARP traffic: Add a firewall rule on each interface (LAN, WAN, SYNC, etc.) that passes protocol 112. Example CLI snippet:
Apply via Firewall → Rules, select the interface, Action Pass, Protocol CARP, Source any, Destination any, then Save and Apply Changes.pass in quick on $LAN proto carp from any to any label \"Allow CARP\" pass out quick on $LAN proto carp from any to any label \"Allow CARP\" - Repair link: Replace faulty NIC, cable, or SFP module. After fixing, run
ifconfig igb0and verifymedia: Ethernet autoselect (1000baseT )andstatus: active. - Align VHID and password: On both firewalls, set the same VHID (e.g., 1) and identical shared secret under CARP Virtual IP settings. Changing these will cause a brief state flip; perform during a maintenance window.
- Re‑initialize pfsync: If the pfsync interface shows errors, disable then re‑enable it: System → High Avail. Sync → pfsync Settings → Disable, Save, then Enable again. Or via CLI:
ifconfig pfsync0 downfollowed byifconfig pfsync0 up. - Adjust advskew/advbase: Ensure the primary has a lower advskew (higher priority). For example, set Primary advskew = 0, Secondary advskew = 100. advbase should be identical (default 1). Change under CARP Virtual IP → Advanced.
Escalation Criteria
- If the secondary still shows BACKUP after applying the above fixes, check system logs for repeated CARP or pfsync errors (
grep carp /var/log/system.log). - Verify hardware health: check NIC LEDs, replace the unit, or test with a spare firewall.
- Consider updating to the latest stable pfSense version (e.g., 2.7.x) if a known bug is suspected.
- Gather a configuration backup (
/conf/config.xml) and recent logs, then open a support ticket with Netgate.
Verification
- Force a failover: either power off the primary firewall or disable its CARP interface (
ifconfig carp0 down). - Watch the secondary:
ifconfig carp0should now show state MASTER and the VHID. - From an external host, ping the CARP VIP (e.g.,
ping 10.0.0.1) and confirm continuous replies. - Check that pfsync reports SYNC and that a configuration change made on the new primary replicates to the former secondary.
Limitations
- This guide assumes CARP is configured with a single VIP. Multi‑VIP setups require repeating the checks per VHID.
- If the primary is suffering a catastrophic hardware failure (e.g., motherboard), the secondary may never become MASTER until the primary is fully removed from the network.
- Virtualized environments may need to ensure promiscuous mode is enabled on the virtual switch for CARP traffic.
Rollback (if you changed firewall rules or CARP settings)
- To revert a firewall rule, delete the rule you added or set its action to Block, then Apply Changes.
- To revert VHID or password changes, restore the previous values from your configuration backup or re‑enter the original shared secret and VHID.
- After rollback, repeat the verification steps to confirm the cluster returns to its original state.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.