OPNexus Deutsch Install

← Back to home

Managing and monitoring OPNsense HA clusters with CARP

An HA pair protects against failures – but only if both nodes really are configured identically and healthy. This guide explains what typically goes wrong with CARP clusters and how to keep an eye on it day to day.

What can go wrong with a CARP pair

Roles and history at a glance

The cluster view in OPNexus shows the CARP role of both nodes side by side, plus the history of role changes. The state is polled at fixed intervals (every five minutes by default, adjustable), so very short changes in between can go unnoticed.

Alerts for split-brain and a missing master

OPNexus reports critical CARP states – both nodes master or no master at all – by webhook or email and clears the alert once the state is fixed. Differences between the nodes are reported too, for example a port forward that exists on one node only.

Maintenance mode with a fall-back timer

For maintenance work a node can be put into maintenance mode on purpose. Optionally you set a fall-back timer (1 to 1440 minutes): if nobody switches back manually, OPNexus restores the previous role itself. A forgotten maintenance mode does not stay in place overnight.

Comparing both nodes' configuration

Under “Network › Compare”, OPNexus compares interfaces, VLANs, virtual IPs, gateways, routes and DNS and DHCP entries of the nodes. Addresses, CARP advskew and the currently active default gateway may differ and are not compared. A newly created object can be transferred to the partner with one click – with its own preview and its own backup; the backup node comes first.

Updates in the right order

The Update Center knows the HA membership and maintenance mode and plans firmware updates accordingly – including major upgrades. A configuration backup is taken before an update.

What OPNexus does not replace

OPNexus replaces neither OPNsense's configuration synchronisation nor pfsync. Both remain necessary and are set up there. OPNexus adds overview, alerts and ordered changes on top of the pair.

Frequently asked questions

Does OPNexus replace OPNsense's configuration synchronisation?

No. It remains necessary. OPNexus shows where the nodes drift apart anyway and helps to make changes on both sides in an orderly way.

How quickly does OPNexus notice a failover?

The state is polled every five minutes by default (minimum one minute, adjustable). A lasting state such as a split-brain is reported; a very short switch between two polls can go unnoticed.

Can OPNexus create CARP addresses?

Yes: virtual IPs, including mode CARP, can be managed per firewall. They are not synchronised to the partner automatically; that is what the one-click transfer and the comparison are for.

Try OPNexus

Free, self-hosted, source available. Installed in a few minutes.

Go to installation