Backup Firewall Using CARP Address

  • I'm running CARP on two pfSense firewalls.  Everything appeared to be working correctly, but I noticed that pings from the backup firewall to an external gateway were failing.  I ran tcpdump and found that pings leaving the backup firewall are using the CARP virtual IP for that interface, so the replies go to the master.  This is only happening on one of four interfaces.  On the others, packets from the backup firewall are sourced from its real interface IP address as I would expect.


  • Rebel Alliance Developer Netgate

    Check your outbound NAT, make sure you don't have any manual outbound NAT rules with a source of "*" (any). Those also apply to traffic from the firewall.

    Properly specify a source and it will stop doing the NAT to the CARP VIP.

  • Thank-you, Jim.  That was the issue - I needed to tighten up my NAT rule.

Log in to reply