I think it would be easy to patch a freebsd 4.x with
this carp.diff (http://pf4freebsd.love2party.net/DF_carp.diff)
to enable CARP support.
Secondly we have to wait for ipfilter-4 to
implement a new tool for syncronizing states (nat+filter)
between firewalls, just because "ipfs" is useless for such
a work (it just dumps all states while locking the firewall),
or we can fork monowall-1.0 to a new develompent tree
based on freebsd5.x and pf in replacement of ipfilter.
what do you think ?
http://www.freemail.gr - äùñåÜí õðçñåóßá çëåêôñïíéêïý ôá÷õäñïìåßïõ.
http://www.freemail.gr - free email service for the Greek-speaking.