CARP, 1 VIP on LAN side, but separate WAN IPs + incoming portmapping

  • Hello!

    I have a question: Is it possible for two pfSense boxes to act as Virtual Gateway on the LAN side, but still two separate IP addresses on the WAN side, each with its own portmapping?

    The situation is as follows:

    • I have two Public IP Addresses, let's say and
    • There will be 10+ servers on the LAN side, private subnet
    • I can procure another private subnet for CARP between the pfSense boxes
    • All servers and the 2 private networks are virtualized over VMware cloud
    • is to be mapped to
    • is to be mapped to
    • is to be mapped to
    • is to be mapped to
    • Various other ports between 50'000 and 59'999 are mapped to port 22 of the internal servers, identically on both pfSense

    I want the pfSense boxes to act as virtual gateways to the internal servers, i.e., is a Virtual IP shared by the 2 pfSense boxes.

    Is my configuration possible?

    Thanks beforehand.

    PS: I am currently using pfSense 1.2.3.

Log in to reply