Build PFsense HA on VMWare without promiscuous mode



  • Hello,

    Do you have information on a possible method or future changes that could allow to mount VIP without port-group , or vSwitch dvSwitch in promiscuous mode ?

    Today , this method is a security hole if a shared VLAN on multiple clients (for example Public IP ) would capture the traffic of the entire VLAN concerned.

    Regards,


  • Netgate

    that would require that we move away from CARP.

    I don't discuss future plans here.  (try reddit… lol)


Log in to reply