Configuring pfSense High Availability with CARP for Firewall Failover
Step‑by‑step guide to configure pfSense HA with CARP, including prerequisites, VIP configuration, XMLRPC sync, verification, and failover recovery.
ReadMeFeed / Community knowledge
Real questions. Useful conversations. Find the people who know your stack.
Step‑by‑step guide to configure pfSense HA with CARP, including prerequisites, VIP configuration, XMLRPC sync, verification, and failover recovery.
When extending a corporate network with pfSense, choosing the right VPN backend—WireGuard, OpenVPN, or IPsec—depends on performance, client support, and regulatory constraints. This guide compares features, trade‑offs, and walks through a WireGuard setup between pfSense and an Ubuntu client.
Stop managing dozens of identical firewall rules. Learn how to use pfSense Aliases to group IPs, ports, and networks into scalable, easy-to-audit configurations.
A practical pfSense OpenVPN remote-access build: certificate setup, UDP server settings that avoid subnet conflicts, scoped firewall rules on the OpenVPN interface, and clean client exports.
I'm specifically looking for a definition of what the following mean: TCP:RA, TCP:FA ,TCP:PA, TCP:S, TCP:SEC The context is that I'm looking at some pfSense logs which are showing rejected packets by the default deny rule. My understanding is that this can happen from asymmetric network traffic where perhaps a connection is closed before a packet acknowledgi
Background In pfSense 2.6.0 the global time‑zone setting under System > General Setup drives the OS clock and all local timestamps in the web interface and syslog. The NTP client synchronizes the clock, but the zone is applied only after boot; during an NTP adjustment logs may temporarily show UTC‑like timestamps until the zone is reloaded. Current Ambigu
Goal: Retrieve complete datasets from pfSense REST API endpoints (e.g., firewall rules) using the limit and offset parameters without losing records due to unexpected empty responses. Uncertainty: In pfSense versions 2.6.0‑2.7.2, combining a very large offset (e.g., >100,000) with a small limit can cause the API to return an empty array instead of adjusti
Goal: Select a site‑to‑site VPN mechanism for two pfSense 2.7.x firewalls that must operate on a CPU with limited AES‑NI support while also needing to traverse existing NAT devices without manual port forwarding. IPsec benefits from hardware‑accelerated encryption, reducing per‑Mbps CPU load, but its default configuration struggles with symmetric NAT and oft
My network setup involves two firewalls in a Common Address Redundancy Protocol (CARP) group, each connected to an MLAG (Multi-Chassis Link Aggregation) configuration of Mikrotik switches. Onward ports on the switches are bonded using LACP. VIP (WAN) | ------------------------- | | | | ------------ pfSync ------------ | Firewall 1 | <---------> | Firew