@Derelict:
So for the 1:1 NAT entry Single host is selected for Internal IP?
All of the netmasks on all the CARP VIPs on your L3 circuit should be /28. Not that it's causing this problem.
Enabling that 1:1 NAT should not stop any traffic.
How about a screen shot of the 1:1 NAT edit screen?
Ah, good eye on the /28 CARP IPs. Although, I'm attempting to reach an IP on the WAN_COX circuit (WAN_L3 isn't connected yet).
Initially I was thinking that it was an incorrect outbound NAT rule, however without the 1:1 rule enabled, the device at 192.168.4.225 has no problem reaching the internet.
Screenshot of the 1:1 edit is below.
[image: pfsense-1-1edit.png]
[image: pfsense-1-1edit.png_thumb]