I installed another secondary pfSense node and configured only the necessary interfaces, VIPs, and HA. I restored only the firewall rules and tried to sync — it worked fine. Then I deleted all rules except those needed on the SYNC interface. After that, I installed pfBlockerNG (without configuring anything). Sync stopped working immediately.
As always reports synced sections... but test firewall rule is not synced. configuration diff shows only date/time changed.
Nov 26 17:41:15 pkg-static 26347 pfSense-pkg-pfBlockerNG-3.2.9_1 installed
Nov 26 17:41:17 php-fpm 582 /rc.filter_configure_sync: Gateway Recovery: killed policy routing states for tier 2 in failOVERWANS
Nov 26 17:41:17 php-fpm 582 /rc.filter_configure_sync: Gateway Recovery: killed policy routing states for tier 2 in IPV6_group
Nov 26 17:42:06 php-fpm 84114 /xmlrpc.php: Configuration Change: (system)@10.0.88.1: Merged in config (dhcpdv6, staticroutes, gateways, virtualip, system, hasync, aliases, ca, cert, crl, dhcpd, dnshaper, dnsmasq, filter, ipsec, kea, kea6, nat, schedules, shaper, unbound, wol sections) from XMLRPC client.
Nov 26 17:42:06 check_reload_status 653 Syncing firewall
Nov 26 17:42:06 check_reload_status 653 Reloading filter
This leads me to think there is some underlying problem on the primary node, or that it is somehow related to the interface configuration. I’m not sure.