<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't access host external address - possible ARP issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-access-host-external-address-possible-ARP-issue/m-p/27520#M2167</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All, I'm trying to access a test laptop externally that is in a IDF switch -&amp;gt; core switch -&amp;gt; DMZ switch -&amp;gt; Check Point 4800.&amp;nbsp; All using VLAN 25.&amp;nbsp; from the gateway I can ping the internal DMZ address, but I cannot ping the external.&amp;nbsp; I ran "tcpdump -eni eth1 arp" and I see requests but no replies.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Sep 2018 23:32:25 GMT</pubDate>
    <dc:creator>Henry_Nouel</dc:creator>
    <dc:date>2018-09-17T23:32:25Z</dc:date>
    <item>
      <title>Can't access host external address - possible ARP issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-access-host-external-address-possible-ARP-issue/m-p/27520#M2167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All, I'm trying to access a test laptop externally that is in a IDF switch -&amp;gt; core switch -&amp;gt; DMZ switch -&amp;gt; Check Point 4800.&amp;nbsp; All using VLAN 25.&amp;nbsp; from the gateway I can ping the internal DMZ address, but I cannot ping the external.&amp;nbsp; I ran "tcpdump -eni eth1 arp" and I see requests but no replies.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2018 23:32:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-access-host-external-address-possible-ARP-issue/m-p/27520#M2167</guid>
      <dc:creator>Henry_Nouel</dc:creator>
      <dc:date>2018-09-17T23:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access host external address - possible ARP issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-access-host-external-address-possible-ARP-issue/m-p/27521#M2168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How did you setup the NAT, manual or Automatic (use the NAT tab in the object)?&lt;/P&gt;&lt;P&gt;When you type &lt;EM&gt;fw ctl arp&lt;/EM&gt;&amp;nbsp;do you see the external IP with the mac fir the external interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the first answer is manual and the second is no, then you need to add a proxy arp with the following command:&lt;/P&gt;&lt;P&gt;add arp proxy ipv4-address 123.123.123.121 interface eth1&amp;nbsp;&lt;/P&gt;&lt;P&gt;or&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;add arp proxy ipv4-address&amp;nbsp;123.123.123.121 macaddress 00:1c:7f:aa:bb:cc real-ip 123.123.123.123&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Where 123.123.123.121 is the external address of the test laptop and eth1 is the external interface, in the second command the macaddress is the address of the external interface&amp;nbsp;and 123.123.123.123 is the external IP of the gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2018 06:22:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-t-access-host-external-address-possible-ARP-issue/m-p/27521#M2168</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-09-18T06:22:58Z</dc:date>
    </item>
  </channel>
</rss>

