Firewall Failover with pfsync and CARP

OpenBSD developer Ryan McBride explains the new firewall redundancy features in the upcoming OpenBSD 3.5 release in his article Firewall Failover with pfsync and CARP.CARP (Common Address Redundancy Protocol) is a free alternative to the patent-encumbered VRRP, responsible for electing masters in a firewall cluster, while pfsync syncronizes packet filter state information among nodes.

The combination allows to replace single-point-of-failure firewalls with clusters of two (or more) nodes, which continue to filter ongoing and new connections when nodes fail. Additional features like arpbalance allow to share a single IP address for multiple servers, transparently balancing load among them, and adapting to servers failing.

Pre-order for OpenBSD 3.5 has started, CDs will ship May 1st.


  1. 2004-03-30 7:31 pm
  2. 2004-03-30 8:10 pm
  3. 2004-03-30 8:54 pm
  4. 2004-03-30 9:06 pm
  5. 2004-03-30 9:18 pm
  6. 2004-03-30 9:43 pm
  7. 2004-03-31 9:58 am
  8. 2004-03-31 2:11 pm
  9. 2004-03-31 3:35 pm