Passing HSRP/VRRP through a FW pair



  • Hi all,

    Many datacenters will give dual uplinks with an HSRP address, but in order for this to be valid, they use those uplinks to pass the HSRP messages from one uplink to the other to connunicate status.  If I have two pfSense firewalls, each with a single WAN interface, configured to be a failover pair (we'll say with an OPT1 interface for pfSYNC/CARP traffic), is it possible to forward this HSRP traffic from one box to the other and then out the interface of the second machine such that the HSRP message is received on the other interface?  This would be to eliminate the need for an external switch (or pair of switches) that basically just "close the loop" for HSRP.

    Thanks!


Log in to reply