This seems related to the other issues secgeek and I have seen.
In my case, the working behaviour (when triggered by the problem we're noticing) can be restored by triggering carp failover (disabling on primary) - the setup will continue to work after failback.
When I do static set ups, I don't use a single DNS - even if using carp - I use the DNS of each router.
The GW does have to be the floating IP though.
It might be helpful to those trying to help if you posted more info about the config? Or did you resolve already? Thanks!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.