Configuring a CARP failover group
In this recipe, we will configure a CARP failover group with two firewalls; one firewall will be online, and the other will be offline, ready to take over as soon as the primary firewall fails.
Getting ready
Implementing a CARP failover group requires an additional investment in hardware. Namely, you must have access to the following hardware to complete this recipe, in addition to your primary firewall:
- A secondary firewall that is an exact copy of the first.
- A router for the WAN side of the network, one that will provide a way of connecting both the primary and secondary firewall to the ISP.
- A crossover cable, to provide a way of connecting the pfsync interfaces on the primary and secondary firewalls.
How to do it...
The following recipe is the most involved recipe in this book; nonetheless, if you follow these steps painstakingly, setting up a CARP failover group should prove to be fairly easy.
The following diagram illustrates the new network topology. The f...