I forgot to mention that I am running 4.9 STABLE on both firewalls I have the rule below in both firewalls:
pass proto carp all keep state And fw1# sysctl net.inet.carp net.inet.carp.allow=1 net.inet.carp.preempt=1 net.inet.carp.log=2 fw2# sysctl net.inet.carp net.inet.carp.allow=1 net.inet.carp.preempt=1 net.inet.carp.log=2 Regards, Joao