    I am not sure I can do this with PFSense. We are running huge number of app servers and DB servers. Now we would like to have firewalls between them, we do not want to have just a master-slave or master-master failover model which basically will not scale and become operational nightmare. So what ideally works well would be a SDNish solution. A master firewall like a Name node and multiple actual firewalls who does the job like data nodes. If you know any big data environment you understand this easily. Basically it is a cluster/pool of firewalls registered with a master. This master can have redundancy etc.  Policies can be pushed from the master firewall to which can be referred as a controller to actual firewalls to do the job.

    Is it possible with PFSense?

    It's not possible currently, CARP does not support an active-active configuration at this time for load sharing.

