We have 4 interfaces on the pfsense boxes:
3) STAGE LAN
4) XOVER (pfsync).
When we select the radio buttong for "Manual outbout NAT rule generation" it only generates a rule for the WAN with the source being the LAN network.
Interface Source Source Port Destination Destination Port NAT Address NAT Port Static Port
WAN 10.9.32.0/24 * * * * * NO
Sureley the source should be "*", or at least both the the LAN network and the STAGE LAN network (and all network underneath these two - in a muti tier network architecture, the top LAN tier being the DMZ, and APP/DB teirs firewalled underneath it).
Also, surely the default rule should have had the NAT address set to the WAN IP? Obviosly, it needs to be changed to the CARPed WAN ip.