> active/active pfsync works absolutely fine, if you have some way to > send traffic to both firewalls. one way you can do that is if you run > OSPF on the firewalls and the router/s in front of them and enable > multipath.
Ok, but I'd like that firewalls share their load, so the traffic coming from the Internet is managed from both machines (behind those firewall I have a group of web server). Maybe I'm missing the point with active/active and load balancing?