A few things have moved since the first post:
Docs and installer: https://github.com/toreamun/opnsense-plugins
- Single-IP is now field-validated. The whole single-IP topology has run on a live one-IP DHCP WAN, including a real CARP failover (the promoted node routed straight out the VIP). Still a single deployment, so more field reports across different ISP/CPE combinations are very welcome.
- Backup egress is now built in. On a single-IP setup the backup node reaches the internet through the master automatically (a leak-safe route set, withdrawn again on promotion), instead of a manual or gateway-group workaround.
- Default-route ownership by CARP role. The keeper can own the WAN default route as a function of CARP role and lease (off / observe / enforce), so a failover moves the default with the role and a backup never black-holes a route it cannot use.
Docs and installer: https://github.com/toreamun/opnsense-plugins
"