Yeah the same thing applies connecting internally, you should use the individual node IPs and not the CARP VIP.

The firewall states are sync'd so traffic through the nodes can fail over but traffic directly to or from a node like this is not that. VPN connections need to be re-established for example. And as you have seen the connection to the webgui is unique.

Steve