IPFW Can IPFW be used in a CARP pair for high availability?

Hello Fellow Forum Members--

I am considering a pair of firewalls controlled by CARP for a little more availability in my Internet connection. I have found examples of this using PF and PFSYNC between the machines for even better switchover, when needed and have managed to synthesize a configuration that seems to work. But I am interested in possibly changing to IPFW instead of PF. Has anyone got experience with such a configuration? If so, can you forewarn me of gotchas I might run into? There does not appear to be a means to synchronize state in IPFW as there is using pfsync in PF. Am I missing something, or is it neither available or needed in such a configuration?

Any guidance, including "Just use PF", would be appreciated.

Thanks,
QuesoGrande
 
IPFW doesn't have option to replicate / sync it's dynamic rule table so when you switch CARP from active to standby host it will drop the current TCP/UDP sessions as the dynamic rules will be not available on the other firewall so you will have some network interrupt.
 
That confirms my take on it. I, indeed, didn't just miss something in my reading. That confirms that PF it shall be, unless someone else has more to say about it.
 
Back
Top