CARP and PFsync for PF Firewall

I'm seeing lots of PFsense posts here. Anyone have a redundant PF setup using anything that hosts PF? Do tell. In your oppinion, is it worth it for a home network?

PFsync looks kinda cool. Might be nice to have redundancy so you can take down a firewall for maintenance without discontinuity of service. Probably overkill (and expensive; roughly $200 USD per unit) for personal home network but great coolness factor. The PC Engines APU1D4 (with RealTek NICs) and APU2C4 (with intel NICs) both have three Gigabit Ethernet NICs. Could use the third to PFsync between two or more units.

Matt

I use 2 Pfsense firewalls that sync between eachother at work.

Both are running on some oldish HP servers with an Intel Nic added in each. 1 Line from the ISP goes into each one, then they are connected together, then 1 line from each goes into the core switch.

Very cool. Have you tested or witnessed it's failover capabilities? Will service continue without interruption if one firewall is disconnected or goes down?

Yes. But not in a "real world" test. After I set the 2 FWs up, I set up a laptop and started pinging google, then unplugged FW1 I lost 2 pings before FW2 took over.

I am honestly unsure if the swap happened during normal business hours if anyone would even notice.

Good info. Thanks for the input.

Matt

I've looked into this for home but gave up because it sounded like I would need at least 3 public IPs - one for each pfsense box external interface and one virtual. Is this true? If so are there workarounds?

I believe you can Connect the wan port of a non-managed switch, if it has one, to your cable or dsl modem, then plug one leg of each firewall into the switch. A non-managed might be simpler cause a managed switch might require filtering from the modem side. (Anyone with experience with this?) I would also connect another leg of each firewall into your home switch. Does that make sense? If not, I'll try to draw it up.

For me, my isp is expecting a device with particular MAC address to be plucgged into my modem. To make this work, I would have to either hack the Mac on the wan port on the modem facing switch or call up isp and have them change.

Matt

My words are imprecise. I found this drawing that might make things clearer.

https://www.google.com/search?q=pfsync+network+diagram&sa=X&rlz=1CDGOYI_enUS655US655&hl=en-US&biw=736&bih=392&prmd=ivn&tbm=isch&tbo=u&source=univ&fir=SRvcuGpoE1XtnM%253A%252CDEt88MZKOkKNsM%252C_%253BLxaAPDYYbqn2mM%253A%252Cb7nIjyMcd3TyXM%252C_%253BvhKY301cGPJyYM%253A%252CLD1pSkdd-qP5iM%252C_%253BVF7hhx2kPxuWZM%253A%252CEa8u0N29SnKpsM%252C_%253BGrTrTKpWKbBzHM%253A%252CxF3QIlITXVwaMM%252C_%253Bc3qCngcdTHa7jM%253A%252CWflTfe1SOsXcEM%252C_%253BGVADtNJQ07UaAM%253A%252C1qh9hh714GZUvM%252C_%253BL8no8srG1LvYRM%253A%252CyJw5KJ7lMBdeRM%252C_&usg=__XMFFR9GcHSJx5BqXUz93qoQ0FXQ%3D&ved=0ahUKEwi5gM2V9dDLAhXGHB4KHVViATIQ7AkILw#imgrc=jp-OuHdNIUBXKM%3A

My bad. You are correct. Three public IPs would be required.