<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem with proxy arp in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/72236#M100168</link>
    <description>Thanks for this.</description>
    <pubDate>Tue, 14 Jan 2020 15:40:21 GMT</pubDate>
    <dc:creator>Stefano_Bucci</dc:creator>
    <dc:date>2020-01-14T15:40:21Z</dc:date>
    <item>
      <title>problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7289#M100154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to perform a simple operation to publish the server to the Internet. &lt;BR /&gt;For this:&lt;BR /&gt;1. I create a manual static nat&lt;BR /&gt;2. Add the address in the proxy arp via WEB-UI (85.21.100.105 - Public server IP)&lt;BR /&gt;3. I turn on the global settings option "Merge manual proxy ARP configuration"&lt;BR /&gt;4. install policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But unfortunately, the firewall does not respond to arp requests for the published server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What did not I finish?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FW-r80.10, MNG-r80.10&lt;/P&gt;&lt;P&gt;show arp proxy all &lt;BR /&gt;IP Address MAC Address / Interface Real IP Address &lt;BR /&gt;85.21.100.105 eth8 85.21.100.111&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;85.21.100.111 - ext ip&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 12:43:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7289#M100154</guid>
      <dc:creator>Andrew25</dc:creator>
      <dc:date>2017-10-09T12:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7290#M100155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What does the output of "fw ctl arp" show from expert mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the subnet mask of 85.21.100.X?&amp;nbsp; Are you SURE that 85.21.100.105 and 85.21.100.111 exist in the same subnet?&amp;nbsp; Proxy ARP will only be performed by the firewall for NAT addresses plucked from what it thinks is a directly-attached IP range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is a firewall cluster involved?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also make sure it is a *proxy* ARP you added via the Gaia web interface, not a *static* ARP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 13:39:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7290#M100155</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-10-09T13:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7291#M100156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;[]# fw ctl arp&lt;BR /&gt; (85.21.100.105) at 00-1c-7f-83-b7-7f interface 85.21.100.111&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes this one subnet&lt;/P&gt;&lt;P&gt;This is not a cluster&lt;/P&gt;&lt;P&gt;This is not statics ARP, you can see from the output of commands&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 13:44:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7291#M100156</guid>
      <dc:creator>Andrew25</dc:creator>
      <dc:date>2017-10-09T13:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7292#M100157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you run "tcpdump -eni eth8 arp" from expert mode, are you seeing an inbound ARP request for 85.21.100.105 from your perimeter router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A class="" href="http://maxpowerfirewalls.com" rel="nofollow"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 13:52:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7292#M100157</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-10-09T13:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7293#M100158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are queries, no answers&lt;/P&gt;&lt;P&gt;17:12:15.468575 6c:c2:17:78:7c:2a &amp;gt; Broadcast, ethertype ARP (0x0806), length 60: arp who-has 85.21.100.105 tell 85.21.100.112 - my test PC&lt;/P&gt;&lt;P&gt;17:12:16.384090 d4:6d:50:6b:c5:61 &amp;gt; Broadcast, ethertype ARP (0x0806), length 60: arp who-has 85.21.100.105 tell 85.21.100.97&lt;/P&gt;&lt;P&gt;17:12:16.468832 6c:c2:17:78:7c:2a &amp;gt; Broadcast, ethertype ARP (0x0806), length 60: arp who-has 85.21.100.105 tell 85.21.100.112&lt;/P&gt;&lt;P&gt;17:12:24.468699 6c:c2:17:78:7c:2a &amp;gt; Broadcast, ethertype ARP (0x0806), length 60: arp who-has 85.21.100.105 tell 85.21.100.112&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 14:15:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7293#M100158</guid>
      <dc:creator>Andrew25</dc:creator>
      <dc:date>2017-10-09T14:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7294#M100159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm suspecting that the firewall object topology definition for eth8 does not match the underlying Gaia interface configuration.&amp;nbsp; Please provide a screenshot of eth8's topology in the SmartConsole, and the output from following expert mode commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ifconfig eth8&lt;/P&gt;&lt;P&gt;fw stat&lt;/P&gt;&lt;P&gt;arp -an | grep 85.21.100.&lt;/P&gt;&lt;P&gt;netstat -rn | grep 85.21.100.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" rel="nofollow"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 14:38:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7294#M100159</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-10-09T14:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7295#M100160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrey, try move your NAT rules above implied rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;ak.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 14:45:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7295#M100160</guid>
      <dc:creator>Andrejs__Андрей</dc:creator>
      <dc:date>2017-10-09T14:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7296#M100161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;ifconfig eth8&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;eth8 Link encap:Ethernet HWaddr 00:1C:7F:83:B7:7F&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;inet addr:85.21.100.111 Bcast:85.21.100.127 Mask:255.255.255.224&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;RX packets:60326 errors:0 dropped:0 overruns:0 frame:0&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;TX packets:42250 errors:0 dropped:0 overruns:0 carrier:0&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;collisions:0 txqueuelen:1000&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;RX bytes:34872545 (33.2 MiB) TX bytes:10041607 (9.5 MiB)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;&amp;nbsp;fw stat&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;HOST POLICY DATE&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;localhost CO_test 9Oct2017 15:45:59 : [^eth1] [^eth1] [^eth8] [^eth8]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;arp -an ^ grep 85.21.100.&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;? (85.21.100.97) at D4:6D:50:6B:C5:61 [ether] on eth8&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;&lt;SPAN&gt;netstat -rn ^ grep 85.21.100.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;85.21.100.96 0.0.0.0 255.255.255.224 U 0 0 0 eth8&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;0.0.0.0 85.21.100.97 0.0.0.0 UGD 0 0 0 eth8&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/59791_topology.jpg" style="width: 620px; height: 341px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 14:51:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7296#M100161</guid>
      <dc:creator>Andrew25</dc:creator>
      <dc:date>2017-10-09T14:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7297#M100162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are the highest rules, there is nowhere to go &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 14:52:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7297#M100162</guid>
      <dc:creator>Andrew25</dc:creator>
      <dc:date>2017-10-09T14:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7298#M100163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well everything looks correct here, has anything in the config of the underlying Gaia eth8 interface been changed on the fly at all since the last boot? Try tcpdump again, but this time with the -p option to suppress promiscuous mode as shown below, do you still see the ARP requests for 85.21.100.105 coming in:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tcpdump -p -eni eth8 arp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't seem them coming in any more it is a network problem.&amp;nbsp; If you do still see them coming in, try running&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw ctl zdebug drop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it logging any kind of drop or other difficulty handling ARP in the zdebug?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next try reinstalling policy, then try this next from expert mode:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ifdown eth8;ifup eth8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that still doesn't work only thing I can suggest at this point is a reboot, lame as that sounds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" rel="nofollow"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 15:29:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7298#M100163</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-10-09T15:29:40Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7299#M100164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very interesting, this firewall is not a cluster&lt;/P&gt;&lt;P&gt;;[cpu_1];[fw4_0];fw_log_drop_ex: Packet proto=-1 ?:0 -&amp;gt; ?:0 dropped by fwha_process_incoming_arp Reason: The packet is designated to an ip address that is proxied, but I'm not an active member&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 15:41:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7299#M100164</guid>
      <dc:creator>Andrew25</dc:creator>
      <dc:date>2017-10-09T15:41:53Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7300#M100165</link>
      <description>&lt;P&gt;You may not have the ClusterXL box checked on the firewall object in the SmartConsole, but I can pretty much guarantee that clustering is enabled in &lt;STRONG&gt;cpconfig&lt;/STRONG&gt; which is the problem.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--&lt;BR /&gt;My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt;now available via &lt;A class="" href="http://maxpowerfirewalls.com" rel="nofollow" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 18:57:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7300#M100165</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-08-04T18:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7301#M100166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you were right! I disabled clustering - the proxy arp earned. It's great, thanks a lot, excellent troubleshooting!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 15:52:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7301#M100166</guid>
      <dc:creator>Andrew25</dc:creator>
      <dc:date>2017-10-09T15:52:29Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7302#M100167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to hear, as it turns out there is actually a SK documenting this that I'll link here for future reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk34453&amp;amp;partition=General&amp;amp;product=Security" style="max-width: 840px;"&gt;sk34453: Automatic Static NAT does not work on Security Gateway&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A class="" href="http://maxpowerfirewalls.com" rel="nofollow"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2017 15:57:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/7302#M100167</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-10-09T15:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/72236#M100168</link>
      <description>Thanks for this.</description>
      <pubDate>Tue, 14 Jan 2020 15:40:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/72236#M100168</guid>
      <dc:creator>Stefano_Bucci</dc:creator>
      <dc:date>2020-01-14T15:40:21Z</dc:date>
    </item>
    <item>
      <title>Re: problem with proxy arp</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/72244#M100169</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7930"&gt;@Andrew25&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can configure the below configuration on the CLI of each cluster member.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Modify the&amp;nbsp;$CPDIR/tmp/.CPprofile.sh&amp;nbsp;script:&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Back up the current&amp;nbsp;$CPDIR/tmp/.CPprofile.sh&amp;nbsp;script:&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;[Expert@HostName:0]# cp -v $CPDIR/tmp/.CPprofile.sh $CPDIR/tmp/.CPprofile.sh_ORIGINAL&lt;/P&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI&gt;Edit the current&amp;nbsp;$CPDIR/tmp/.CPprofile.sh&amp;nbsp;script:&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;[Expert@HostName:0]# vi $CPDIR/tmp/.CPprofile.sh&lt;/P&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI&gt;Before the last line, add:&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;_cpprof_add CP_AUTO_ARP_FOR_MANUAL_NAT_RULES "1" 0 0&lt;/P&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI&gt;Save the changes and exit the Vi editor.&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Modify the&amp;nbsp;$CPDIR/tmp/.CPprofile.csh&amp;nbsp;script:&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Back up the current&amp;nbsp;$CPDIR/tmp/.CPprofile.csh&amp;nbsp;script:&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;[Expert@HostName:0]# cp -v $CPDIR/tmp/.CPprofile.csh $CPDIR/tmp/.CPprofile.csh_ORIGINAL&lt;/P&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI&gt;Edit the current&amp;nbsp;$CPDIR/tmp/.CPprofile.csh&amp;nbsp;script:&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;[Expert@HostName:0]# vi $CPDIR/tmp/.CPprofile.csh&lt;/P&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI&gt;Before the last line, add:&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;setenv CP_AUTO_ARP_FOR_MANUAL_NAT_RULES "1"&lt;/P&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI&gt;Save the changes and exit from Vi editor.&lt;/LI&gt;&lt;/OL&gt;&lt;LI&gt;Reboot the Security Gateway.&lt;/LI&gt;&lt;LI&gt;Verify that the relevant environment variable was set:&lt;/LI&gt;&lt;/OL&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI&gt;In the Bash shell:&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Log into the Expert mode.&lt;/LI&gt;&lt;LI&gt;Check the value of the variable:&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;[Expert@HostName:0]# echo $CP_AUTO_ARP_FOR_MANUAL_NAT_RULES&lt;/P&gt;&lt;P&gt;Output should show a value of 1.&lt;/P&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI&gt;In the Csh shell:&lt;/LI&gt;&lt;OL&gt;&lt;LI&gt;Log into the Expert mode.&lt;/LI&gt;&lt;LI&gt;Log into the Csh shell:&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;[Expert@HostName:0]# csh&lt;/P&gt;&lt;OL&gt;&lt;OL&gt;&lt;OL&gt;&lt;LI&gt;Check the value of the variable:&lt;/LI&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;/OL&gt;&lt;P&gt;[admin@HostName ~]# echo $CP_AUTO_ARP_FOR_MANUAL_NAT_RULES&lt;/P&gt;&lt;P&gt;Output should show a value of 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2020 16:22:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-proxy-arp/m-p/72244#M100169</guid>
      <dc:creator>Yatiraj_Panchal</dc:creator>
      <dc:date>2020-01-14T16:22:49Z</dc:date>
    </item>
  </channel>
</rss>

