To start, on your 1st pfSense machine, go to: Firewall -> Rules.
Go to the "PFSYNC" tab (which corresponds to the name of the logical interface (default: OPT1) added and renamed previously), then click on: Add.
Note: 2 rules + 1 optional must be created for synchronization via pfSync to work correctly.
To get started, enable configuration synchronization by configuring these options:
For the rest, configure:
Click Save.
The 1st firewall rule was created for your "PFSYNC" logical interface.
Click again on: Add.
This time, you must allow network traffic using the "PFSYNC" protocol for state synchronization (master/slave) to work correctly.
Then, configure this:
Click Save.
Your 2nd firewall rule has been created for your logical network interface "PFSYNC".
To be able to easily test the network connection via this interface, you can add a 3rd firewall rule (but which is optional).
To do this, click again on: Add.
For this 3rd rule (optional), indicate this:
Then, configure this:
Click Save.
Your 3rd firewall rule has been created.
For your PFSYNC interface, you should therefore see these 3 rules in the pfSense firewall.
On your 2nd pfSense machine, create the same 3 rules in the firewall for the "PFSYNC" interface.
Which will give you this.
To get started, on your 1st pfSense machine, go to: System -> High Avail. Sync.
In the "State Synchronization Settings (pfsync)" section, configure only these settings for now:
Then, at the bottom of the page, click Save.
Then, on your 2nd pfSense machine also go to "System -> High Avail. Sync" and configure these first 3 settings as well.
Warning : in this case, the IP address to indicate for the "pfsync Synchronize Peer IP" parameter corresponds to the IP address of the "PFSYNC" interface of your first pfSense machine.
In our case, the 1st machine has the IP address "172.16.1.2" for PFSYNC.
Then, click "Save" at the bottom of the page.
Important : only on your 1st pfSense machine (master), configure the settings in the "Configuration Synchronization Settings (XMLRPC Sync)" section.
Select the items you want to automatically sync from the master pfSense machine to the slave pfSense machine.
To select everything, simply click "Toggle All" at the bottom of the "Select options to sync" option.
Then, click Save.
If you go to your 2nd pfSense machine, you will see that the desired configurations have been replicated there.
Warning : no longer modify configuration options on the 2nd pfSense machine which are replicated from the 1st pfSense machine.
Indeed, the modifications made on the 2nd pfSense machine would be lost when the 1st pfSense machine replicates its settings again to the 2nd pfSense machine.
Firewall 6/11/2025
Firewall 8/6/2025
Firewall 8/20/2025
Firewall 7/23/2025
Pinned content
Contact
® InformatiWeb-Pro.net - InformatiWeb.net 2008-2022 - © Lionel Eppe - All rights reserved.
Total or partial reproduction of this site is prohibited and constitutes an infringement punishable by articles L.335-2 and following of the intellectual property Code.
No comment