I read that "each carp group has a virtual MAC (link layer) address" http://www.countersiege.com/doc/pfsync-carp/
So if you give an ip addres at each bridge, it should work ?
And for pfsync, a dedicated network interface with a crossover cable should work too ?


Am I wrong ?


Sean wrote:

Lyle Worthington wrote:


Our firewall is ipless, all traffic just runs through it because it is
the only way in or out of our network.



CARP and pfsync both needs IPs to operate. In pfsync's case, it'll use multicast or a unicast address. For CARP, failover is on a per IP basis and CARP'ed addresses require an address on an existing interface.

cheers,
Sean






Reply via email to