@Delegator5042 said in Setting up CARP Master and Backup on a per VLAN basis (Like VRRP): is it possible?:
I've read that you can use a switch on the ISP Ethernet connection so it could be shared with multiple routers, but I haven't tried this.
Yes, put a small switch into each line or even a VLAN capable switch and split it into two virtual switches.
Consider that for CARP, you need an IP on each pfSense and a third as VIP. So you should have 3 IPs on each.
If you haven't there is also a way to configure private IPs on the boxes, but this has some drawbacks.
I would still like to know if I could force a vlan (or subnet) to use a specific gateway and only when that gateway is down to send the traffic over to designated backup connection.
You can configure a gateway group and set this as default gateway.
For routing traffic other than according the default gateway you can do policy routing by stating a gateway in the firewall pass rule.
You your purposes you can configure an additional gateway group, say with inverted priorities, and use this in the policy routing rule.