<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manual NAT with proxy ARP fails randomly in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61465#M12400</link>
    <description>&lt;P&gt;R80.10 jumbo Take 203&lt;/P&gt;&lt;P&gt;Cluster XL &amp;amp; VMAC&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm referring to both the IP and the MAC address, using fw ctl arp. It's in place.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2019 10:57:48 GMT</pubDate>
    <dc:creator>Alex_Lillo</dc:creator>
    <dc:date>2019-08-29T10:57:48Z</dc:date>
    <item>
      <title>Manual NAT with proxy ARP fails randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61447#M12398</link>
      <description>&lt;P&gt;Hi mates,&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are dealing with another strange issue, where a published NAT stops working randomly after a policy install.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rule works as expected, the proxy ARP entry is in place, and after changing something completely unrelated (i.e. enabling a protection from staging to prevent), the NAT entry stops working.&lt;/P&gt;&lt;P&gt;Sometimes is one NAT rule, sometimes is another.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are cleaning up our NAT rulebase (currently 377 NAT rules, aproximatedly 40% had already been disabled) just to deal with this and clean things up.&lt;/P&gt;&lt;P&gt;Has somebody found this problem before?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 08:35:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61447#M12398</guid>
      <dc:creator>Alex_Lillo</dc:creator>
      <dc:date>2019-08-29T08:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT with proxy ARP fails randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61448#M12399</link>
      <description>Just a few simple questions:&lt;BR /&gt;Which version is on the gateway, which jumbo?&lt;BR /&gt;Are you using VMAC in clustering? ClusterXL or VRRP?&lt;BR /&gt;In the proxy arp command are you referring to the interface or the mac address?&lt;BR /&gt;When it does not work, what does 'fw ctl arp' tell you, is it really gone?</description>
      <pubDate>Thu, 29 Aug 2019 08:39:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61448#M12399</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-08-29T08:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT with proxy ARP fails randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61465#M12400</link>
      <description>&lt;P&gt;R80.10 jumbo Take 203&lt;/P&gt;&lt;P&gt;Cluster XL &amp;amp; VMAC&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm referring to both the IP and the MAC address, using fw ctl arp. It's in place.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 10:57:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61465#M12400</guid>
      <dc:creator>Alex_Lillo</dc:creator>
      <dc:date>2019-08-29T10:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT with proxy ARP fails randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61466#M12401</link>
      <description>&lt;P&gt;UPDATE: When launching "clusterXL_admin down &amp;amp;&amp;amp; clusterXL_admin up" from active member, passive member becomes ACTIVE and the NAT rule starts working again. If you fail back again, the NAT rule still does not work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;With cpstop &amp;amp;&amp;amp; cpstart on failing member, it starts working normally.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 11:02:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61466#M12401</guid>
      <dc:creator>Alex_Lillo</dc:creator>
      <dc:date>2019-08-29T11:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT with proxy ARP fails randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61467#M12402</link>
      <description>Are you using VMAC?&lt;BR /&gt;So the command you are using:&lt;BR /&gt;add arp proxy ipv4-address 123.123.123.125 macaddress 00:1c:7f:38:22:fe real-ip 123.123.123.123 &lt;BR /&gt;Where real-ip is the ip of the member, not the VIP and the macaddress is the VMAC when using VMAC.</description>
      <pubDate>Thu, 29 Aug 2019 11:03:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61467#M12402</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-08-29T11:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT with proxy ARP fails randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61470#M12403</link>
      <description>This sounds like you need to open a TAC case and involve &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14307"&gt;@Ilya_Yusupov&lt;/a&gt; with this issue.</description>
      <pubDate>Thu, 29 Aug 2019 11:12:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61470#M12403</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-08-29T11:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT with proxy ARP fails randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61471#M12404</link>
      <description>Exactly, that's it.</description>
      <pubDate>Thu, 29 Aug 2019 11:15:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61471#M12404</guid>
      <dc:creator>Alex_Lillo</dc:creator>
      <dc:date>2019-08-29T11:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: Manual NAT with proxy ARP fails randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61504#M12405</link>
      <description>&lt;P&gt;Sounds an awful lot like this (sk154092 - Security Gateway loses Proxy ARP entries after policy installation), for which there is a hotfix available:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk154092" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk154092&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2019 15:58:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Manual-NAT-with-proxy-ARP-fails-randomly/m-p/61504#M12405</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-08-29T15:58:21Z</dc:date>
    </item>
  </channel>
</rss>

