Configuring pfSense High Availability with CARP for Firewall Failover
Step‑by‑step guide to configure pfSense HA with CARP, including prerequisites, VIP configuration, XMLRPC sync, verification, and failover recovery.
19 Aug 2025, 22:58 UTC

Desired outcome
Two pfSense appliances operate as an active‑passive pair: one node holds the CARP Virtual IPs (VIPs) as MASTER, the other stands by as BACKUP. If the MASTER fails, the BACKUP automatically assumes the VIPs, keeping traffic flowing without manual intervention.
Prerequisites
- Two identical hardware or virtual machines running the same pfSense version (e.g., 2.7.0).
- Each appliance has at least three interfaces configured identically: WAN, LAN, and a dedicated SYNC interface (or VLAN) used only for CARP synchronization traffic.
- Administrator access to the web GUI or SSH on both nodes.
- Layer‑2 connectivity between the SYNC interfaces (no routing, same broadcast domain).
- Optional but recommended: a separate management network for accessing the GUI during failover testing.
Procedure
1. Enable CARP on each node
Log in to the pfSense web GUI as admin, navigate to System → Virtual IPs → CARP and click Add. Set:
- Virtual IP type: Single address
- Interface: WAN (repeat for LAN later)
- Address:
203.0.113.10/24(example) - Password: a strong shared secret (same on both nodes)
- Description: WAN‑CARP‑VIP
Click Save and then Apply Changes. Repeat the same steps on the second appliance, using the identical VIP address and password.
2. Assign CARP VIPs for LAN (and any other interfaces)
Repeat the CARP VIP creation for the LAN interface, using an address such as 10.0.0.1/24. Keep the same CARP password.
3. Configure XMLRPC Sync (settings replication)
On the node that will be the primary MASTER (you can decide later):
- Go to System → High Avail. Sync.
- Set Synchronize Config to IP to the IP address of the backup node’s SYNC interface (e.g.,
192.168.99.2). - Check Synchronize firewall rules, NAT, virtual IPs, and DHCP (or select specific items as needed).
- Enter the Remote System Username and Password of an admin account on the backup node.
- Set Synchronize to to XMLRPC Sync.
- Click Save.
Repeat the same configuration on the backup node, pointing the Synchronize Config to IP to the primary’s SYNC IP (192.168.99.1) and using the primary’s admin credentials.
4. Set the failover peer IP on the SYNC interface
Assign static IPs to the SYNC interfaces (they must be in the same subnet but not overlap with any other traffic):
- Primary:
192.168.99.1/24 - Backup:
192.168.99.2/24
Do this via Interfaces → [SYNC] → Static IPv4. Ensure the interface is Enabled and Block private networks is unchecked if you plan to use RFC1918 addresses.
5. Enable CARP on the SYNC interface (optional but recommended)
Create a CARP VIP on the SYNC interface (e.g., 192.168.99.100/24) with the same password. This allows the backup to detect loss of the master via CARP advertisements on the sync link as an additional safety check.
Expected checks
- From a management PC, ping each CARP VIP:
ping -c 3 203.0.113.10ping -c 3 10.0.0.1
Successful replies indicate the VIP is active on the MASTER node. - Check CARP status: Status → CARP. One node should show MASTER for each VIP, the other BACKUP.
- Verify settings sync: make a change (e.g., add a firewall rule) on the MASTER, then confirm it appears on the BACKUP under Firewall → Rules after a few seconds.
- Review system logs for CARP advertisements: Status → System Logs → System and look for entries like
carp0: MASTERorcarp0: BACKUP.
Recovery options
Automatic failover
If the MASTER node loses power or its CARP interface goes down, the BACKUP will see missing CARP advertisements, transition to MASTER, and begin answering to the VIPs. Traffic resumes automatically.
Manual failover (for testing or maintenance)
- On the MASTER, navigate to Status → CARP and click the Advise Backup button for each VIP, or simply shut down the MASTER’s power or disable its CARP interface via Interfaces → [WAN/LAN] → Disable.
- Observe the BACKUP’s CARP status change to MASTER and verify VIP responsiveness.
Rollback / returning to original MASTER
After restoring the failed node:
- Ensure the restored node’s CARP interfaces are enabled and it has the same configuration (sync will have brought it up to date).
- On the restored node, go to Status → CARP and click Advise Master for each VIP to force it to become MASTER.
- Alternatively, reboot the current MASTER; the restored node will reclaim MASTER status after the CARP advertisement election.
If you need to revert the CARP configuration entirely (e.g., to test a different HA method), you can:
- Delete each CARP VIP (System → Virtual IPs → CARP → Delete).
- Disable XMLRPC Sync (System → High Avail. Sync → uncheck synchronize options).
- Remove the static IPs from the SYNC interfaces or repurpose them.
- Apply changes and verify that traffic now flows via the physical interfaces only.
Limitations and practical verification
Version mismatch – CARP and XMLRPC sync rely on identical pfSense builds. Running different versions can cause sync failures or VIP conflicts. Verify version equality via System → Information before proceeding.
Split‑brain risk – If the SYNC interface carries user traffic or is not isolated, both nodes may believe they are MASTER. Keep the SYNC link on a dedicated VLAN or physical switch with no other hosts.
Asymmetric routing – Ensure that upstream routers return traffic to the same firewall that sent it (e.g., using the same gateway on both nodes). Use outbound NAT with a consistent source address or configure equal‑cost multi‑path (ECMP) carefully.
To confirm the HA pair is functioning correctly after any change:
- Ping each CARP VIP from an external host.
- Run
pfctl -s carpvia SSH on both nodes; look forcarp0: MASTERon one andcarp0: BACKUPon the other. - Check the config sync timestamp: Diagnostics → Backup & Restore → History should show recent XMLRPC actions on both nodes.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.