From owner-freebsd-pf@FreeBSD.ORG Tue Feb 6 17:57:14 2007 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id B199716A405 for ; Tue, 6 Feb 2007 17:57:13 +0000 (UTC) (envelope-from mksmith@adhost.com) Received: from mail-defer01.adhost.com (mail-defer01.adhost.com [216.211.128.150]) by mx1.freebsd.org (Postfix) with ESMTP id 8DF2A13C494 for ; Tue, 6 Feb 2007 17:57:13 +0000 (UTC) (envelope-from mksmith@adhost.com) Received: from mail-in07.adhost.com (mail-in07.adhost.com [10.211.128.140]) by mail-defer01.adhost.com (Postfix) with ESMTP id 709ABECCAF for ; Tue, 6 Feb 2007 09:30:41 -0800 (PST) (envelope-from mksmith@adhost.com) Received: from ad-exh01.adhost.lan (unknown [216.211.143.69]) by mail-in07.adhost.com (Postfix) with ESMTP id E4F2B1B5092 for ; Tue, 6 Feb 2007 09:30:40 -0800 (PST) (envelope-from mksmith@adhost.com) Content-class: urn:content-classes:message MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable X-MimeOLE: Produced By Microsoft Exchange V6.5 Date: Tue, 6 Feb 2007 09:30:28 -0800 Message-ID: <17838240D9A5544AAA5FF95F8D52031601A8BD24@ad-exh01.adhost.lan> X-MS-Has-Attach: X-MS-TNEF-Correlator: Thread-Topic: PFSync Not Working Correctly thread-index: AcdKFH44nmfXG62oSESitobwvzTS7Q== From: "Michael K. Smith - Adhost" To: Subject: PFSync Not Working Correctly X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 06 Feb 2007 17:57:14 -0000 Hello All: I have two 6.2 RELEASE servers working in failover mode as PF Load Balancers. When the MASTER box is failed (through reboot or interface shutdown, etc.) the BACKUP box becomes MASTER as expected, but connections that existed through the MASTER before the failover do not transfer as expected to the new MASTER. New connections work immediately. When I issue a 'pfctl -vvss' the established connection shows up correctly in the state tables on both machines, so I would expect the established connection to work immediately upon failover. =20 If anyone has any insights I'd be grateful. I can also post any relevent output or config snippets if someone thinks they would help. Regards, Mike