CARP and 1:1 NAT

    Is it possible to have firewall failover configuration (CARP) and 1:1 NAT instead of port forwarding? As far as I can tell, 1:1 NAT requires ProxyARP which will not work with CARP. We have several internal servers that require public IP address and doing port forward instead of 1:1 NAT would make one very long configuration list

  • You can use it with CARP.
    Just create a CARP VIP but dont use the CARP functionallity.

    So create CARP VIP instead of ProxyArp for all 1:1 NAT servers? Also, if i don't use CARP functionality, how will failover work?
  • Ah you want to use CARP with failover in the sense of failover from one router to the other.
    I though failover in the sense of dualWAN failover.

    I'm not sure how and if that works.
    I would just try to setup CARP for the 1:1 NAT VIP like you would for a normal failover interface.

