<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Proxy ARP on VSNext in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274676#M104630</link>
    <description>&lt;P&gt;We are following the &lt;A href="https://support.checkpoint.com/results/sk/sk30197" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt; to create a proxy ARP on VSNext.&lt;/P&gt;
&lt;P&gt;However, we can't make it work. $FWDIR/conf/local.arp is created only on CTX 0 and not in the relevant CTX wheareas the gclish commands are issued in the correct virtual system.&lt;/P&gt;
&lt;P&gt;Maybe that moving it in the correct CTX would make it work but it's not documented and we'd rather avoid a situation where some update or process could cause ARP to fail.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;asg_arp --verify&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;g_fw ctl arp&lt;/FONT&gt; don't return anything in the VS.&lt;/P&gt;
&lt;P&gt;The solution we have for now is to create a loopback and add it to the topolgy of the VS. The system will accept a loopback which overlaps with an existing interface. For now it solves our issue.&lt;/P&gt;
&lt;P&gt;We have a TAC case open where for now we've been asked to reboot the gateways but the situation remains.&lt;/P&gt;
&lt;P&gt;R82 T60 + CRL fix.&lt;/P&gt;</description>
    <pubDate>Wed, 01 Apr 2026 18:25:57 GMT</pubDate>
    <dc:creator>Alex-</dc:creator>
    <dc:date>2026-04-01T18:25:57Z</dc:date>
    <item>
      <title>Proxy ARP on VSNext</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274676#M104630</link>
      <description>&lt;P&gt;We are following the &lt;A href="https://support.checkpoint.com/results/sk/sk30197" target="_blank" rel="noopener"&gt;documentation&lt;/A&gt; to create a proxy ARP on VSNext.&lt;/P&gt;
&lt;P&gt;However, we can't make it work. $FWDIR/conf/local.arp is created only on CTX 0 and not in the relevant CTX wheareas the gclish commands are issued in the correct virtual system.&lt;/P&gt;
&lt;P&gt;Maybe that moving it in the correct CTX would make it work but it's not documented and we'd rather avoid a situation where some update or process could cause ARP to fail.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;asg_arp --verify&lt;/FONT&gt; and &lt;FONT face="courier new,courier"&gt;g_fw ctl arp&lt;/FONT&gt; don't return anything in the VS.&lt;/P&gt;
&lt;P&gt;The solution we have for now is to create a loopback and add it to the topolgy of the VS. The system will accept a loopback which overlaps with an existing interface. For now it solves our issue.&lt;/P&gt;
&lt;P&gt;We have a TAC case open where for now we've been asked to reboot the gateways but the situation remains.&lt;/P&gt;
&lt;P&gt;R82 T60 + CRL fix.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 18:25:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274676#M104630</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-04-01T18:25:57Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on VSNext</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274703#M104644</link>
      <description>&lt;P&gt;Are the entries in local.arp that are created in VS0 context reflecting the configuration you're putting in for the VS in gclish?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 02:09:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274703#M104644</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-04-02T02:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on VSNext</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274705#M104645</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 04:04:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274705#M104645</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-04-02T04:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on VSNext</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274709#M104649</link>
      <description>&lt;P&gt;That sounds like a bug then. You should be able to manually copy the entries from VS0&amp;nbsp;&lt;SPAN&gt;$FWDIR/conf/local.arp to the VS&amp;nbsp;$FWDIR/conf/local.arp files and install policy.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 05:23:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274709#M104649</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-04-02T05:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on VSNext</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274717#M104657</link>
      <description>&lt;P&gt;Likely, or the documentation must be amended. We will follow-up with TAC, for now our customer has solutions with the loopback which effectively provide the desired functionality.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 06:09:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274717#M104657</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-04-02T06:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on VSNext</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274719#M104658</link>
      <description>&lt;P&gt;It worked on earlier R82 JHFs when I tested it without any manual file editing, hence I think it's a bug. Good luck with TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 06:18:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-VSNext/m-p/274719#M104658</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-04-02T06:18:06Z</dc:date>
    </item>
  </channel>
</rss>

