Crossposted using Lemmit.

Original post from /r/techsupport by /u/Siwat2545 on 2023-07-07 15:02:59+00:00.


So I have an ISP router and 2 of my routers and I want to put 2 firewalls in HA mode behind the ISP router as I only have one public dynamic IP and cannot setup VRRP (need 3, 2Router+1VIP)

I was thinking that I would use private IPs to do VRRP and 1:1 NAT to the VIP on the WAN side.

If I do this I was wondering what will break. Right now I’m using bridge mode to make double nat goes away.

Diagram

https://imgur.com/a/4JH3Jal