I'm still a bit confused as to how the configuration works with the backup.
Right now I have a pair of routers and CARP is working on the internal interfaces and I want to add CARP on the public interface.
I get that doing NAT to the CARP address works on the active/master router because it has that address. The passive/backup router won't get any traffic to route so the only thing going out would be internally generated. But if the backup router has a NAT to the CARP address, won't the return path be wrong?
|