{"id":1415,"date":"2020-02-04T19:05:29","date_gmt":"2020-02-04T19:05:29","guid":{"rendered":"http:\/\/general.sio57.info\/wp\/?p=1415"},"modified":"2023-10-10T18:24:53","modified_gmt":"2023-10-10T18:24:53","slug":"pfsense-redondance-carp-sur-hyper-v","status":"publish","type":"post","link":"https:\/\/general.sio57.info\/wp\/?p=1415","title":{"rendered":"PfSense- Redondance CARP sur Hyper-V"},"content":{"rendered":"\n<p>On trouve beaucoup de tutos sur le net, mais la redondance sur hyper-v avec carp demande quelques ajustements : <\/p>\n\n\n\n<p>Pour mettre en place le load balcing avec CARP, on commence par cr\u00e9er deux pfsenses (avec des noms diff\u00e9rents, c&rsquo;est mieux). On leur met des IP sur le m\u00eame r\u00e9seau via leur interface LAN.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>On leur met aussi deux interfaces \u00ab\u00a0CARP\u00a0\u00bb dans un commutateur priv\u00e9 avec un adressage diff\u00e9rent du LAN en \/30. Ces deux interfaces servent pour la synchronisation des deux pfsenses. Attention a bien aller activer ces interfaces via le menu du m\u00eame nom.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/innterf-carp-1024x359.png\" alt=\"\" class=\"wp-image-1418\" width=\"552\" height=\"193\" srcset=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/innterf-carp-1024x359.png 1024w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/innterf-carp-300x105.png 300w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/innterf-carp-768x269.png 768w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/innterf-carp.png 1072w\" sizes=\"auto, (max-width: 552px) 100vw, 552px\" \/><\/figure>\n\n\n\n<p> Ensuite dans Syst\u00e8me, il faut aller dans le menu \u00ab\u00a0Synchronisation de haute disponibilit\u00e9\u00a0\u00bb ou Load Balancing. (A faire sur les 2)<\/p>\n\n\n\n<p>Choisir sur les 2 les interfaces CARP. Dans IP de synchronisation et Synchroniser avec IP donnez l&rsquo;adresse du pair (de l&rsquo;autre pfsense).<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/hd-avec-carp.png\" alt=\"\" class=\"wp-image-1417\" width=\"373\" height=\"287\" srcset=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/hd-avec-carp.png 729w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/hd-avec-carp-300x232.png 300w\" sizes=\"auto, (max-width: 373px) 100vw, 373px\" \/><\/figure>\n\n\n\n<p>En bas de la page choisir les options \u00e0 synchroniser.<\/p>\n\n\n\n<p>Aller ensuite dans le menu Pare-Feu\/ Firewall Adresse IP Virtuelle. Ajouter sur les 2 pare-feu la m\u00eame IP virtuelle qui servira de passerelle sur le LAN.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"447\" src=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/vid-1024x447.png\" alt=\"\" class=\"wp-image-1419\" srcset=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/vid-1024x447.png 1024w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/vid-300x131.png 300w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/vid-768x335.png 768w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/vid.png 1184w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Le biais sert \u00e0 mettre une priorit\u00e9 entre les deux machines. La plus petite mesure sera le Master.<\/p>\n\n\n\n<p>Dans le menu Pare-feu il faut aussi cr\u00e9er une regle pour autoriser le trafic entre les cartes \u00ab\u00a0CARP\u00a0\u00bb sur chacun des pare-feu :<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/regle-1024x307.png\" alt=\"\" class=\"wp-image-1421\" width=\"510\" height=\"152\" srcset=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/regle-1024x307.png 1024w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/regle-300x90.png 300w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/regle-768x230.png 768w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/regle.png 1132w\" sizes=\"auto, (max-width: 510px) 100vw, 510px\" \/><\/figure>\n\n\n\n<p>Attention, lors de l&rsquo;utilisation d&rsquo;une adresse IP virtuelle pour plusieurs machines les cartes r\u00e9seaux doivent usurper l&rsquo;adresse MAC :   dans Hyper-v  il faut activer l&rsquo;usurpation d&rsquo;adresse MAC  pour les interfaces LAN  des 2 pfsenses dans le menu param\u00e8tres de chaque VM :<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"676\" height=\"414\" src=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/hyper-v-pfsense.png\" alt=\"\" class=\"wp-image-1420\" srcset=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/hyper-v-pfsense.png 676w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/hyper-v-pfsense-300x184.png 300w\" sizes=\"auto, (max-width: 676px) 100vw, 676px\" \/><\/figure>\n\n\n\n<p>A partir de la \u00e7a devrait fonctionner.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"541\" height=\"161\" src=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/hyper-v.png\" alt=\"\" class=\"wp-image-1422\" srcset=\"https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/hyper-v.png 541w, https:\/\/general.sio57.info\/wp\/wp-content\/uploads\/2020\/02\/hyper-v-300x89.png 300w\" sizes=\"auto, (max-width: 541px) 100vw, 541px\" \/><\/figure>\n\n\n\n<p>Tester l&rsquo;obtention d&rsquo;un bail DHCP, (attention, il faut activer le service sur les 2 et donner \u00e0 chaque firewall  l&rsquo;IP de l&rsquo;autre dans la case IP Failover !). Il faut aussi donner comme passerelle l&rsquo;adresse virtuelle.<\/p>\n\n\n\n\n\n<p>Maintenant couper un des serveurs et vv\u00e9rifier que vous pouvez avoir quand meme internet depuis un client. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>On trouve beaucoup de tutos sur le net, mais la redondance sur hyper-v avec carp demande quelques ajustements : Pour mettre en place le load balcing avec CARP, on commence par cr\u00e9er deux pfsenses (avec des noms diff\u00e9rents, c&rsquo;est mieux). On leur met des IP sur le m\u00eame r\u00e9seau via leur interface LAN.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56,69,59,71,181,182,183,6,44,99],"tags":[175,63,176,91,135,53],"class_list":["post-1415","post","type-post","status-publish","format-standard","hentry","category-2-liaison","category-3-reseau-routeur","category-7-application","category-7-application-supervision","category-b1","category-b2","category-b3","category-securite","category-sisr5","category-virtualisation","tag-carp","tag-firewall","tag-haute-disponibilte","tag-hyper-v","tag-pfsense","tag-redondances"],"_links":{"self":[{"href":"https:\/\/general.sio57.info\/wp\/index.php?rest_route=\/wp\/v2\/posts\/1415","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/general.sio57.info\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/general.sio57.info\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/general.sio57.info\/wp\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/general.sio57.info\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1415"}],"version-history":[{"count":2,"href":"https:\/\/general.sio57.info\/wp\/index.php?rest_route=\/wp\/v2\/posts\/1415\/revisions"}],"predecessor-version":[{"id":1424,"href":"https:\/\/general.sio57.info\/wp\/index.php?rest_route=\/wp\/v2\/posts\/1415\/revisions\/1424"}],"wp:attachment":[{"href":"https:\/\/general.sio57.info\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1415"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/general.sio57.info\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1415"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/general.sio57.info\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1415"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}