xref: /freebsd/share/man/man4/carp.4 (revision a1ae564ebff4fde16c5a6c51f51e0bc0abcbcc8a)
18e925890SGleb Smirnoff.\"	$OpenBSD: carp.4,v 1.16 2004/12/07 23:41:35 jmc Exp $
28e925890SGleb Smirnoff.\"
38e925890SGleb Smirnoff.\" Copyright (c) 2003, Ryan McBride.  All rights reserved.
408b68b0eSGleb Smirnoff.\" Copyright (c) 2011, Gleb Smirnoff <glebius@FreeBSD.org>
58e925890SGleb Smirnoff.\"
68e925890SGleb Smirnoff.\" Redistribution and use in source and binary forms, with or without
78e925890SGleb Smirnoff.\" modification, are permitted provided that the following conditions
88e925890SGleb Smirnoff.\" are met:
98e925890SGleb Smirnoff.\" 1. Redistributions of source code must retain the above copyright
108e925890SGleb Smirnoff.\"    notice, this list of conditions and the following disclaimer.
118e925890SGleb Smirnoff.\" 2. Redistributions in binary form must reproduce the above copyright
128e925890SGleb Smirnoff.\"    notice, this list of conditions and the following disclaimer in the
138e925890SGleb Smirnoff.\"    documentation and/or other materials provided with the distribution.
148e925890SGleb Smirnoff.\"
158e925890SGleb Smirnoff.\" THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
168e925890SGleb Smirnoff.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
178e925890SGleb Smirnoff.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
188e925890SGleb Smirnoff.\" ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
198e925890SGleb Smirnoff.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
208e925890SGleb Smirnoff.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
218e925890SGleb Smirnoff.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
228e925890SGleb Smirnoff.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
238e925890SGleb Smirnoff.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
248e925890SGleb Smirnoff.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
258e925890SGleb Smirnoff.\" SUCH DAMAGE.
268e925890SGleb Smirnoff.\"
278e925890SGleb Smirnoff.\" $FreeBSD$
288e925890SGleb Smirnoff.\"
29*a1ae564eSGleb Smirnoff.Dd January 26, 2012
308e925890SGleb Smirnoff.Dt CARP 4
318e925890SGleb Smirnoff.Os
328e925890SGleb Smirnoff.Sh NAME
338e925890SGleb Smirnoff.Nm carp
348e925890SGleb Smirnoff.Nd Common Address Redundancy Protocol
358e925890SGleb Smirnoff.Sh SYNOPSIS
368e925890SGleb Smirnoff.Cd "device carp"
378e925890SGleb Smirnoff.Sh DESCRIPTION
3808b68b0eSGleb SmirnoffThe CARP allows multiple hosts on the same local network to share a set of
3908b68b0eSGleb SmirnoffIPv4 and/or IPv6 addresses.
408e925890SGleb SmirnoffIts primary purpose is to ensure that these
4108b68b0eSGleb Smirnoffaddresses are always available.
428e925890SGleb Smirnoff.Pp
438e925890SGleb SmirnoffTo use
448e925890SGleb Smirnoff.Nm ,
4508b68b0eSGleb Smirnoffthe administrator needs to configure at minimum a common virtual host ID
4608b68b0eSGleb Smirnoff(vhid) and attach at least one IP address to this vhid on each machine which
4708b68b0eSGleb Smirnoffis to take part in the virtual group.
4808b68b0eSGleb SmirnoffAdditional parameters can also be set on a per-vhid basis:
498e925890SGleb Smirnoff.Cm advbase
508e925890SGleb Smirnoffand
518e925890SGleb Smirnoff.Cm advskew ,
528e925890SGleb Smirnoffwhich are used to control how frequently the host sends advertisements when it
538e925890SGleb Smirnoffis the master for a virtual host, and
548e925890SGleb Smirnoff.Cm pass
553e630869SGleb Smirnoffwhich is used to authenticate
563e630869SGleb Smirnoff.Nm
573e630869SGleb Smirnoffadvertisements.
58762ce3e6SGleb SmirnoffThe
59762ce3e6SGleb Smirnoff.Cm advbase
60762ce3e6SGleb Smirnoffparameter stands for
61a4be0b3cSRuslan Ermilov.Dq "advertisement base" .
621a1fa3bdSGiorgos KeramidasIt is measured in seconds and specifies the base of the advertisement interval.
63762ce3e6SGleb SmirnoffThe
64762ce3e6SGleb Smirnoff.Cm advskew
65762ce3e6SGleb Smirnoffparameter stands for
66a4be0b3cSRuslan Ermilov.Dq "advertisement skew" .
67762ce3e6SGleb SmirnoffIt is measured in 1/256 of seconds.
68762ce3e6SGleb SmirnoffIt is added to the base advertisement interval to make one host advertise
69762ce3e6SGleb Smirnoffa bit slower that the other does.
70762ce3e6SGleb SmirnoffBoth
71762ce3e6SGleb Smirnoff.Cm advbase
72762ce3e6SGleb Smirnoffand
73762ce3e6SGleb Smirnoff.Cm advskew
74a4be0b3cSRuslan Ermilovare put inside CARP advertisements.
758e925890SGleb SmirnoffThese configurations can be done using
768e925890SGleb Smirnoff.Xr ifconfig 8 ,
778e925890SGleb Smirnoffor through the
788e925890SGleb Smirnoff.Dv SIOCSVH
793e630869SGleb Smirnoff.Xr ioctl 2 .
808e925890SGleb Smirnoff.Pp
8108b68b0eSGleb SmirnoffCARP virtual hosts can be configured on multicast capable interfaces: Ethernet,
8208b68b0eSGleb Smirnofflayer 2 VLAN, FDDI and Token Ring.
8308b68b0eSGleb SmirnoffAn arbitrary number of virtual host IDs can be configured on an interface.
8408b68b0eSGleb SmirnoffAn arbitrary number of IPv4 or IPv6 addresses can be attached to a particular
8508b68b0eSGleb Smirnoffvhid.
8608b68b0eSGleb SmirnoffIt is important that all hosts participating in a vhid have the same list
8708b68b0eSGleb Smirnoffof prefixes configured on the vhid, since all prefixes are included in the
8808b68b0eSGleb Smirnoffcryptographic checksum supplied in each advertisement.
8908b68b0eSGleb SmirnoffMultiple vhids running on one interface participate in master/backup
9008b68b0eSGleb Smirnoffelections independently.
9108b68b0eSGleb Smirnoff.Pp
928e925890SGleb SmirnoffAdditionally, there are a number of global parameters which can be set using
938e925890SGleb Smirnoff.Xr sysctl 8 :
9408b68b0eSGleb Smirnoff.Bl -tag -width ".Va net.inet.carp.preempt"
953e630869SGleb Smirnoff.It Va net.inet.carp.allow
968e925890SGleb SmirnoffAccept incoming
978e925890SGleb Smirnoff.Nm
988e925890SGleb Smirnoffpackets.
998e925890SGleb SmirnoffEnabled by default.
1003e630869SGleb Smirnoff.It Va net.inet.carp.preempt
1018e925890SGleb SmirnoffAllow virtual hosts to preempt each other.
102*a1ae564eSGleb SmirnoffWhen enabled, a vhid in a backup state would preempt a master that
103*a1ae564eSGleb Smirnoffis announcing itself with a lower advskew.
1048e925890SGleb SmirnoffDisabled by default.
1053e630869SGleb Smirnoff.It Va net.inet.carp.log
106442af10aSGleb SmirnoffValue of 0 disables any logging.
107acc0fee0SRuslan ErmilovValue of 1 enables logging state changes of
108442af10aSGleb Smirnoff.Nm
109*a1ae564eSGleb Smirnoffvhids.
110acc0fee0SRuslan ErmilovValues above 1 enable logging of bad
111acc0fee0SRuslan Ermilov.Nm
112acc0fee0SRuslan Ermilovpackets.
113442af10aSGleb SmirnoffDefault value is 1.
114f08535f8SGleb Smirnoff.It Va net.inet.carp.demotion
115f08535f8SGleb SmirnoffThis value shows current level of CARP demotion.
116f08535f8SGleb SmirnoffThe value is added to the actual advskew sent in announcements for
117f08535f8SGleb Smirnoffall vhids.
118f08535f8SGleb SmirnoffAt normal system operation the demotion factor is zero.
119f08535f8SGleb SmirnoffHowever, problematic conditions raise its level: when
120f08535f8SGleb Smirnoff.Nm
121f08535f8SGleb Smirnoffexperiences problem with sending announcements, when an interface
122f08535f8SGleb Smirnoffrunning a vhid goes down, or while the
1231771f872SGleb Smirnoff.Xr pfsync 4
1241771f872SGleb Smirnoffinterface is not synchronized.
125f08535f8SGleb SmirnoffThe demotion value is writable, so that user may alter it
126f08535f8SGleb Smirnoffdepending on some external conditions, for example on status of some
127f08535f8SGleb Smirnoffdaemon utility.
128f08535f8SGleb SmirnoffHowever, altering the value should be performed with care, do
129f08535f8SGleb Smirnoffnot conflict with subsystems that adjust demotion factor
130f08535f8SGleb Smirnoffautomatically:
131f08535f8SGleb Smirnoff.Nm
132f08535f8SGleb Smirnoffand
133f08535f8SGleb Smirnoff.Xr pfsync 4 .
134f08535f8SGleb Smirnoff.It Va net.inet.carp.ifdown_demotion_factor
135f08535f8SGleb SmirnoffValue added to
136f08535f8SGleb Smirnoff.Va net.inet.carp.demotion
137f08535f8SGleb Smirnoffwhen interface running a vhid goes down.
138f08535f8SGleb SmirnoffDefault value is 240 (maximum advskew value).
139f08535f8SGleb Smirnoff.It Va net.inet.carp.senderr_demotion_factor
140f08535f8SGleb SmirnoffValue added to
141f08535f8SGleb Smirnoff.Va net.inet.carp.demotion
142f08535f8SGleb Smirnoffwhen
143f08535f8SGleb Smirnoff.Nm
144f08535f8SGleb Smirnoffexperiences errors sending its announcements.
145f08535f8SGleb SmirnoffDefault value is 240 (maximum advskew value).
1468e925890SGleb Smirnoff.El
14708b68b0eSGleb Smirnoff.\".Sh ARP level load balancing
14808b68b0eSGleb Smirnoff.\"The
14908b68b0eSGleb Smirnoff.\".Nm
15008b68b0eSGleb Smirnoff.\"has limited abilities for load balancing the incoming connections
15108b68b0eSGleb Smirnoff.\"between hosts in Ethernet network.
15208b68b0eSGleb Smirnoff.\"For load balancing operation, one needs several CARP interfaces that
15308b68b0eSGleb Smirnoff.\"are configured to the same IP address, but to a different vhids.
15408b68b0eSGleb Smirnoff.\"Once an ARP request is received, the CARP protocol will use a hashing
15508b68b0eSGleb Smirnoff.\"function against the source IP address in the ARP request to determine
15608b68b0eSGleb Smirnoff.\"which vhid should this request belong to.
15708b68b0eSGleb Smirnoff.\"If the corresponding CARP interface is in master state, the ARP request
15808b68b0eSGleb Smirnoff.\"will be replied, otherwise it will be ignored.
15908b68b0eSGleb Smirnoff.\"See the
16008b68b0eSGleb Smirnoff.\".Sx EXAMPLES
16108b68b0eSGleb Smirnoff.\"section for a practical example of load balancing.
16208b68b0eSGleb Smirnoff.\".Pp
16308b68b0eSGleb Smirnoff.\"The ARP load balancing has some limitations.
16408b68b0eSGleb Smirnoff.\"First, ARP balancing only works on the local network segment.
16508b68b0eSGleb Smirnoff.\"It cannot balance traffic that crosses a router, because the
16608b68b0eSGleb Smirnoff.\"router itself will always be balanced to the same virtual host.
16708b68b0eSGleb Smirnoff.\"Second, ARP load balancing can lead to asymmetric routing
16808b68b0eSGleb Smirnoff.\"of incoming and outgoing traffic, and thus combining it with
16908b68b0eSGleb Smirnoff.\".Xr pfsync 4
17008b68b0eSGleb Smirnoff.\"is dangerous, because this creates a race condition between
17108b68b0eSGleb Smirnoff.\"balanced routers and a host they are serving.
17208b68b0eSGleb Smirnoff.\"Imagine an incoming packet creating state on the first router, being
17308b68b0eSGleb Smirnoff.\"forwarded to its destination, and destination replying faster
17408b68b0eSGleb Smirnoff.\"than the state information is packed and synced with the second router.
17508b68b0eSGleb Smirnoff.\"If the reply would be load balanced to second router, it will be
17608b68b0eSGleb Smirnoff.\"dropped due to no state.
177cc8b2291SGleb Smirnoff.Sh STATE CHANGE NOTIFICATIONS
178cc8b2291SGleb SmirnoffSometimes it is useful to get notified about
179cc8b2291SGleb Smirnoff.Nm
180cc8b2291SGleb Smirnoffstatus change events.
181cc8b2291SGleb SmirnoffThis can be accomplished by using
182cc8b2291SGleb Smirnoff.Xr devd 8
183cc8b2291SGleb Smirnoffhooks.
18408b68b0eSGleb SmirnoffMaster/slave events are signalled under system
18508b68b0eSGleb Smirnoff.Dv CARP .
18689486220SUlrich SpörleinSubsystem specifies vhid and name of interface, where event occurred.
18708b68b0eSGleb SmirnoffType of the message displays new state of vhid.
188cc8b2291SGleb SmirnoffPlease see
189cc8b2291SGleb Smirnoff.Xr devd.conf 5
190cc8b2291SGleb Smirnoffand
191cc8b2291SGleb Smirnoff.Sx EXAMPLES
192cc8b2291SGleb Smirnoffsection for more information.
1938e925890SGleb Smirnoff.Sh EXAMPLES
1948e925890SGleb SmirnoffFor firewalls and routers with multiple interfaces, it is desirable to
195*a1ae564eSGleb Smirnofffailover all of the addresses running
1968e925890SGleb Smirnoff.Nm
197*a1ae564eSGleb Smirnofftogether, when one of the physical interfaces goes down.
1988e925890SGleb SmirnoffThis is achieved by the preempt option.
1998e925890SGleb SmirnoffEnable it on both host A and B:
2008e925890SGleb Smirnoff.Pp
2013e630869SGleb Smirnoff.Dl sysctl net.inet.carp.preempt=1
2028e925890SGleb Smirnoff.Pp
20308b68b0eSGleb SmirnoffAssume that host A is the preferred master and we are running the
20408b68b0eSGleb Smirnoff192.168.1.0/24 prefix on em0 and 192.168.2.0/24 on em1.
2058e925890SGleb SmirnoffThis is the setup for host A:
2068e925890SGleb Smirnoff.Bd -literal -offset indent
20708b68b0eSGleb Smirnoffifconfig em0 vhid 1 pass mekmitasdigoat 192.168.1.1/24
20808b68b0eSGleb Smirnoffifconfig em1 vhid 2 pass mekmitasdigoat 192.168.2.1/24
2098e925890SGleb Smirnoff.Ed
2108e925890SGleb Smirnoff.Pp
2113e630869SGleb SmirnoffThe setup for host B is identical, but it has a higher
2123e630869SGleb Smirnoff.Cm advskew :
2138e925890SGleb Smirnoff.Bd -literal -offset indent
21408b68b0eSGleb Smirnoffifconfig em0 vhid 1 advskew 100 pass mekmitasdigoat 192.168.1.1/24
21508b68b0eSGleb Smirnoffifconfig em1 vhid 2 advskew 100 pass mekmitasdigoat 192.168.2.1/24
2168e925890SGleb Smirnoff.Ed
2178e925890SGleb Smirnoff.Pp
218*a1ae564eSGleb SmirnoffWhen one of the physical interfaces of host A fails,
2193e630869SGleb Smirnoff.Cm advskew
220*a1ae564eSGleb Smirnoffis demoted to a configured value on all its
2218e925890SGleb Smirnoff.Nm
222*a1ae564eSGleb Smirnoffvhids.
223*a1ae564eSGleb SmirnoffDue to the preempt option, host B would start announcing itself, and thus
224*a1ae564eSGleb Smirnoffpreempt host A on both interfaces instead of just the failed one.
22508b68b0eSGleb Smirnoff.\".Pp
22608b68b0eSGleb Smirnoff.\"In order to set up an ARP balanced virtual host, it is necessary to configure
22708b68b0eSGleb Smirnoff.\"one virtual host for each physical host which would respond to ARP requests
22808b68b0eSGleb Smirnoff.\"and thus handle the traffic.
22908b68b0eSGleb Smirnoff.\"In the following example, two virtual hosts are configured on two hosts to
23008b68b0eSGleb Smirnoff.\"provide balancing and failover for the IP address 192.168.1.10.
23108b68b0eSGleb Smirnoff.\".Pp
23208b68b0eSGleb Smirnoff.\"First the
23308b68b0eSGleb Smirnoff.\".Nm
23408b68b0eSGleb Smirnoff.\"interfaces on host A are configured.
23508b68b0eSGleb Smirnoff.\"The
23608b68b0eSGleb Smirnoff.\".Cm advskew
23708b68b0eSGleb Smirnoff.\"of 100 on the second virtual host means that its advertisements will be sent
23808b68b0eSGleb Smirnoff.\"out slightly less frequently.
23908b68b0eSGleb Smirnoff.\".Bd -literal -offset indent
24008b68b0eSGleb Smirnoff.\"ifconfig carp0 create
24108b68b0eSGleb Smirnoff.\"ifconfig carp0 vhid 1 pass mekmitasdigoat 192.168.1.10/24
24208b68b0eSGleb Smirnoff.\"ifconfig carp1 create
24308b68b0eSGleb Smirnoff.\"ifconfig carp1 vhid 2 advskew 100 pass mekmitasdigoat 192.168.1.10/24
24408b68b0eSGleb Smirnoff.\".Ed
24508b68b0eSGleb Smirnoff.\".Pp
24608b68b0eSGleb Smirnoff.\"The configuration for host B is identical, except the
24708b68b0eSGleb Smirnoff.\".Cm advskew
24808b68b0eSGleb Smirnoff.\"is on virtual host 1 rather than virtual host 2.
24908b68b0eSGleb Smirnoff.\".Bd -literal -offset indent
25008b68b0eSGleb Smirnoff.\"ifconfig carp0 create
25108b68b0eSGleb Smirnoff.\"ifconfig carp0 vhid 1 advskew 100 pass mekmitasdigoat 192.168.1.10/24
25208b68b0eSGleb Smirnoff.\"ifconfig carp1 create
25308b68b0eSGleb Smirnoff.\"ifconfig carp1 vhid 2 pass mekmitasdigoat 192.168.1.10/24
25408b68b0eSGleb Smirnoff.\".Ed
25508b68b0eSGleb Smirnoff.\".Pp
25608b68b0eSGleb Smirnoff.\"Finally, the ARP balancing feature must be enabled on both hosts:
25708b68b0eSGleb Smirnoff.\".Pp
25808b68b0eSGleb Smirnoff.\".Dl sysctl net.inet.carp.arpbalance=1
25908b68b0eSGleb Smirnoff.\".Pp
26008b68b0eSGleb Smirnoff.\"When the hosts receive an ARP request for 192.168.1.10, the source IP address
26108b68b0eSGleb Smirnoff.\"of the request is used to compute which virtual host should answer the request.
26208b68b0eSGleb Smirnoff.\"The host which is master of the selected virtual host will reply to the
26308b68b0eSGleb Smirnoff.\"request, the other(s) will ignore it.
26408b68b0eSGleb Smirnoff.\".Pp
26508b68b0eSGleb Smirnoff.\"This way, locally connected systems will receive different ARP replies and
26608b68b0eSGleb Smirnoff.\"subsequent IP traffic will be balanced among the hosts.
26708b68b0eSGleb Smirnoff.\"If one of the hosts fails, the other will take over the virtual MAC address,
26808b68b0eSGleb Smirnoff.\"and begin answering ARP requests on its behalf.
269cc8b2291SGleb Smirnoff.Pp
270cc8b2291SGleb SmirnoffProcessing of
271cc8b2291SGleb Smirnoff.Nm
27208b68b0eSGleb Smirnoffstatus change events can be set up by using the following devd.conf rule:
273cc8b2291SGleb Smirnoff.Bd -literal -offset indent
274cc8b2291SGleb Smirnoffnotify 0 {
27508b68b0eSGleb Smirnoff	match "system"          "CARP";
27608b68b0eSGleb Smirnoff	match "subsystem"       "[0-9]+@";
27708b68b0eSGleb Smirnoff	match "type"            "(MASTER|BACKUP)";
27808b68b0eSGleb Smirnoff	action "/root/carpcontrol.sh $subsystem $type";
279cc8b2291SGleb Smirnoff};
280cc8b2291SGleb Smirnoff.Ed
2818e925890SGleb Smirnoff.Sh SEE ALSO
2828e925890SGleb Smirnoff.Xr inet 4 ,
2831771f872SGleb Smirnoff.Xr pfsync 4 ,
2841771f872SGleb Smirnoff.Xr rc.conf 5 ,
2851eefdc3bSGleb Smirnoff.Xr devd.conf 5 ,
286a4be0b3cSRuslan Ermilov.Xr ifconfig 8 ,
2878e925890SGleb Smirnoff.Xr sysctl 8
2888e925890SGleb Smirnoff.Sh HISTORY
2898e925890SGleb SmirnoffThe
2908e925890SGleb Smirnoff.Nm
2918e925890SGleb Smirnoffdevice first appeared in
2928e925890SGleb Smirnoff.Ox 3.5 .
2938e925890SGleb SmirnoffThe
2948e925890SGleb Smirnoff.Nm
2953e630869SGleb Smirnoffdevice was imported into
2968e925890SGleb Smirnoff.Fx 5.4 .
29708b68b0eSGleb SmirnoffIn
29808b68b0eSGleb Smirnoff.Fx 10
29908b68b0eSGleb Smirnoffthe
30008b68b0eSGleb Smirnoff.Nm
30108b68b0eSGleb Smirnoffwas significantly rewritten, and is no longer a pseudo-interface.
302