Clustering multiple pfsync 2.0.1 installs

  • I've got 3 boxes running pfsync. Going to carp them for redundancy on in/out traffic.

    Is there any way to make each install aware of the other? So all packages are installed on all machines, firewall rules are sync'd, and all usage graphs are accurate?

    The graphs won't sync, but you can do the pfsync and config sync.

    You'll need to do the config sync in a chain.

    Master -> Slave1 -> Slave2 in the XMLRPC settings.

    pfsync should on, but with no IP set in the box, so the pfsync messages are not directed, and everyone on that shared segment will get them.