<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Stale ARP Entries in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Stale-ARP-Entries/m-p/131577#M19393</link>
    <description>&lt;P&gt;Ever since we upgrade to R80.40 JHF118 at the end of August, we've run into issues where ARP entries are not getting updated (or purged) on the gateways appropriately.&amp;nbsp; This really only impacts our Guest Wifi as the churn on DHCP leases is the highest.&lt;/P&gt;&lt;P&gt;I've changed the lease time on the scope from 1 day to 3 days to avoid a lease being handed back out too soon to give the gateways time to purge the stale ARP entry, but this is not really helping.&lt;/P&gt;&lt;P&gt;What did help was to ping each IP in the subnet once day to help the gateway refresh its ARP table.&amp;nbsp; This is well and good unless we have a surge of guest wifi users (large meeting).&amp;nbsp; When I first tracked down the issue there weren't any SKs published related to the behavior and we had a decent workaround until the problem with larger meetings became apparent.&lt;/P&gt;&lt;P&gt;On 10/7, a new SK was published (&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk175603&amp;amp;partition=Advanced&amp;amp;product=SecureXL" target="_self"&gt;sk175603&lt;/A&gt;) that describes the behavior and that CP support pointed out to us after opening a case.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I wanted to share this out to the community in case you were running into anything like this.&amp;nbsp; &amp;nbsp;The fix will be included in a JHF in mid-December (right during our year-end change freeze) so we're looking at not having a JHF until January sometime in our environment.&amp;nbsp; Anyone have any issues applying a specific hotfix provided by Checkpoint (which is also an option to resolve this)?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any thoughts on workarounds/alternatives to help alleviate the issue (I'm already debating changing the frequency of pinging the individual IP addresses in the subnet from once a day to maybe once an hour).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Tue, 12 Oct 2021 15:09:46 GMT</pubDate>
    <dc:creator>Matt_Taber</dc:creator>
    <dc:date>2021-10-12T15:09:46Z</dc:date>
    <item>
      <title>Stale ARP Entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Stale-ARP-Entries/m-p/131577#M19393</link>
      <description>&lt;P&gt;Ever since we upgrade to R80.40 JHF118 at the end of August, we've run into issues where ARP entries are not getting updated (or purged) on the gateways appropriately.&amp;nbsp; This really only impacts our Guest Wifi as the churn on DHCP leases is the highest.&lt;/P&gt;&lt;P&gt;I've changed the lease time on the scope from 1 day to 3 days to avoid a lease being handed back out too soon to give the gateways time to purge the stale ARP entry, but this is not really helping.&lt;/P&gt;&lt;P&gt;What did help was to ping each IP in the subnet once day to help the gateway refresh its ARP table.&amp;nbsp; This is well and good unless we have a surge of guest wifi users (large meeting).&amp;nbsp; When I first tracked down the issue there weren't any SKs published related to the behavior and we had a decent workaround until the problem with larger meetings became apparent.&lt;/P&gt;&lt;P&gt;On 10/7, a new SK was published (&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk175603&amp;amp;partition=Advanced&amp;amp;product=SecureXL" target="_self"&gt;sk175603&lt;/A&gt;) that describes the behavior and that CP support pointed out to us after opening a case.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I wanted to share this out to the community in case you were running into anything like this.&amp;nbsp; &amp;nbsp;The fix will be included in a JHF in mid-December (right during our year-end change freeze) so we're looking at not having a JHF until January sometime in our environment.&amp;nbsp; Anyone have any issues applying a specific hotfix provided by Checkpoint (which is also an option to resolve this)?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any thoughts on workarounds/alternatives to help alleviate the issue (I'm already debating changing the frequency of pinging the individual IP addresses in the subnet from once a day to maybe once an hour).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 15:09:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Stale-ARP-Entries/m-p/131577#M19393</guid>
      <dc:creator>Matt_Taber</dc:creator>
      <dc:date>2021-10-12T15:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Stale ARP Entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Stale-ARP-Entries/m-p/131809#M19463</link>
      <description>&lt;P&gt;Did you receive a private fix from TAC?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 08:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Stale-ARP-Entries/m-p/131809#M19463</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-10-15T08:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Stale ARP Entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Stale-ARP-Entries/m-p/131842#M19477</link>
      <description>&lt;P&gt;I submitted requested cpinfo files a few days ago; still waiting on the hotfix.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 12:32:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Stale-ARP-Entries/m-p/131842#M19477</guid>
      <dc:creator>Matt_Taber</dc:creator>
      <dc:date>2021-10-15T12:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Stale ARP Entries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Stale-ARP-Entries/m-p/131844#M19479</link>
      <description>&lt;P&gt;Replied to this before checking my email this morning,&amp;nbsp; Support notified me yesterday evening that the hotfix is available via SFTP.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Oct 2021 12:34:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Stale-ARP-Entries/m-p/131844#M19479</guid>
      <dc:creator>Matt_Taber</dc:creator>
      <dc:date>2021-10-15T12:34:40Z</dc:date>
    </item>
  </channel>
</rss>

