documentation:examples:pf_and_carp_lab
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| documentation:examples:pf_and_carp_lab [2021/11/25 13:54] – [Backup Firewall (VM3)] olivier | documentation:examples:pf_and_carp_lab [2021/11/25 14:04] (current) – [pf synchronisation] olivier | ||
|---|---|---|---|
| Line 87: | Line 87: | ||
| sysrc pflog_enable=YES | sysrc pflog_enable=YES | ||
| sysrc pfsync_syncdev=vtnet1 | sysrc pfsync_syncdev=vtnet1 | ||
| - | mount -uw / | + | sysrc kld_list="carp" |
| - | echo " | + | |
| - | mount -ur / | + | |
| echo " | echo " | ||
| Line 139: | Line 137: | ||
| sysrc pflog_enable=YES | sysrc pflog_enable=YES | ||
| sysrc pfsync_syncdev=vtnet1 | sysrc pfsync_syncdev=vtnet1 | ||
| - | mount -uw / | + | sysrc kld_list="carp" |
| - | echo " | + | |
| - | mount -ur / | + | |
| echo " | echo " | ||
| Line 200: | Line 196: | ||
| < | < | ||
| [root@VM2]~# | [root@VM2]~# | ||
| - | vtnet3: flags=8943< | + | vtnet3: flags=8863< |
| options=80028< | options=80028< | ||
| ether 58: | ether 58: | ||
| Line 206: | Line 202: | ||
| inet 192.168.10.254 netmask 0xffffffff broadcast 192.168.10.254 vhid 1 | inet 192.168.10.254 netmask 0xffffffff broadcast 192.168.10.254 vhid 1 | ||
| inet6 fe80:: | inet6 fe80:: | ||
| - | | + | |
| - | media: Ethernet 10Gbase-T < | + | |
| - | | + | |
| carp: MASTER vhid 1 advbase 1 advskew 100 | carp: MASTER vhid 1 advbase 1 advskew 100 | ||
| + | carp: MASTER vhid 2 advbase 1 advskew 100 | ||
| + | media: Ethernet autoselect (10Gbase-T < | ||
| + | status: active | ||
| + | nd6 options=21< | ||
| [root@VM2]~# | [root@VM2]~# | ||
| - | vtnet4: flags=8943< | + | vtnet4: flags=8863< |
| options=80028< | options=80028< | ||
| ether 58: | ether 58: | ||
| - | inet 10.0.0.2 netmask 0xffffff00 broadcast | + | inet 2.2.2.2 netmask 0xffffff00 broadcast |
| - | inet 10.0.0.254 netmask 0xffffffff broadcast | + | inet 2.2.2.254 netmask 0xffffffff broadcast |
| inet6 fe80:: | inet6 fe80:: | ||
| + | inet6 2001: | ||
| + | inet6 2001: | ||
| + | carp: MASTER vhid 3 advbase 1 advskew 100 | ||
| + | carp: MASTER vhid 4 advbase 1 advskew 100 | ||
| + | media: Ethernet autoselect (10Gbase-T < | ||
| + | status: active | ||
| nd6 options=21< | nd6 options=21< | ||
| - | media: Ethernet 10Gbase-T < | ||
| - | status: active | ||
| - | carp: MASTER vhid 2 advbase 1 advskew 100 | ||
| </ | </ | ||
| Line 227: | Line 229: | ||
| < | < | ||
| [root@VM3]~# | [root@VM3]~# | ||
| - | vtnet3: flags=8943< | + | vtnet3: flags=8863< |
| options=80028< | options=80028< | ||
| ether 58: | ether 58: | ||
| Line 233: | Line 235: | ||
| inet 192.168.10.254 netmask 0xffffffff broadcast 192.168.10.254 vhid 1 | inet 192.168.10.254 netmask 0xffffffff broadcast 192.168.10.254 vhid 1 | ||
| inet6 fe80:: | inet6 fe80:: | ||
| + | inet6 2001: | ||
| + | inet6 2001: | ||
| + | carp: BACKUP vhid 1 advbase 1 advskew 200 | ||
| + | carp: BACKUP vhid 2 advbase 1 advskew 200 | ||
| + | media: Ethernet autoselect (10Gbase-T < | ||
| + | status: active | ||
| nd6 options=21< | nd6 options=21< | ||
| - | media: Ethernet 10Gbase-T < | ||
| - | status: active | ||
| - | carp: BACKUP vhid 1 advbase 1 advskew 200 | ||
| [root@VM3]~# | [root@VM3]~# | ||
| - | vtnet4: flags=8943< | + | vtnet4: flags=8863< |
| options=80028< | options=80028< | ||
| ether 58: | ether 58: | ||
| - | inet 10.0.0.3 netmask 0xffffff00 broadcast | + | inet 2.2.2.3 netmask 0xffffff00 broadcast |
| - | inet 10.0.0.254 netmask 0xffffffff broadcast | + | inet 2.2.2.254 netmask 0xffffffff broadcast |
| inet6 fe80:: | inet6 fe80:: | ||
| + | inet6 2001: | ||
| + | inet6 2001: | ||
| + | carp: BACKUP vhid 3 advbase 1 advskew 200 | ||
| + | carp: BACKUP vhid 4 advbase 1 advskew 200 | ||
| + | media: Ethernet autoselect (10Gbase-T < | ||
| + | status: active | ||
| nd6 options=21< | nd6 options=21< | ||
| - | media: Ethernet 10Gbase-T < | ||
| - | status: active | ||
| - | carp: BACKUP vhid 2 advbase 1 advskew 200 | ||
| </ | </ | ||
| ==== pf state ==== | ==== pf state ==== | ||
| Line 273: | Line 281: | ||
| Open a tmux session on R1 and generate 2 flows: | Open a tmux session on R1 and generate 2 flows: | ||
| - | - A continous ping: ping 10.0.0.4 | + | - A continous ping: ping 2.2.2.4 |
| - | - A echo session: telnet | + | - A echo session: telnet |
| ==== pf synchronisation ==== | ==== pf synchronisation ==== | ||
| Line 281: | Line 289: | ||
| < | < | ||
| - | [root@VM3]~# pfctl -ss | + | [root@VM2]~# pfctl -ss |
| - | all icmp 10.0.0.4:267 <- 192.168.10.1:267 0:0 | + | all carp fe80:: |
| - | all icmp 192.168.10.1:267 -> 10.0.0.4:267 | + | all carp 2.2.2.2 -> 224.0.0.18 |
| - | all tcp 10.0.0.4:7 <- 192.168.10.1: | + | all carp 192.168.10.2 -> 224.0.0.18 |
| - | all tcp 192.168.10.1: | + | all pfsync |
| - | all carp 224.0.0.18 <- 192.168.10.2 | + | all icmp 2.2.2.4:13399 <- 192.168.10.1: |
| - | all carp 224.0.0.18 <- 10.0.0.2 | + | all icmp 192.168.10.1: |
| - | all pfsync 224.0.0.240 <- 192.168.23.2 | + | all tcp 2.2.2.4:7 <- 192.168.10.1: |
| + | all tcp 192.168.10.1:11636 -> 2.2.2.4:7 | ||
| </ | </ | ||
| Line 295: | Line 304: | ||
| < | < | ||
| [root@VM3]~# | [root@VM3]~# | ||
| - | all icmp 10.0.0.4: | ||
| - | all icmp 192.168.10.1: | ||
| - | all tcp 10.0.0.4:22 <- 192.168.10.1: | ||
| - | all tcp 192.168.10.1: | ||
| - | all carp 224.0.0.18 <- 10.0.0.2 | ||
| all carp 224.0.0.18 <- 192.168.10.2 | all carp 224.0.0.18 <- 192.168.10.2 | ||
| + | all carp 224.0.0.18 <- 2.2.2.2 | ||
| + | all carp ff02::12 <- fe80:: | ||
| + | all pfsync 192.168.23.3 -> 224.0.0.240 | ||
| all pfsync 224.0.0.240 <- 192.168.23.2 | all pfsync 224.0.0.240 <- 192.168.23.2 | ||
| + | all icmp 2.2.2.4: | ||
| + | all icmp 192.168.10.1: | ||
| + | all tcp 2.2.2.4:7 <- 192.168.10.1: | ||
| + | all tcp 192.168.10.1: | ||
| </ | </ | ||
documentation/examples/pf_and_carp_lab.1637844859.txt.gz · Last modified: 2021/11/25 13:54 by olivier
