<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proxy Arp's for subnet not on firewall in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6189#M228</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As stated in original post R80.10 is the version and adding in the manual proxy arps is not suffice.  When I do this the arp entries are seeing via ‘fw ctl arp’ but when you run an ‘fw monitor’ on the firewall you see that it just simply tries to route the traffic back out if there is not s subsequent “dummy” route provisioned for the address space that does not pertain to the subnet configured on it’s external interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Juan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 10 Sep 2017 19:15:17 GMT</pubDate>
    <dc:creator>Juan_Concepcion</dc:creator>
    <dc:date>2017-09-10T19:15:17Z</dc:date>
    <item>
      <title>Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6187#M226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have run into this several times where I create proxy arp(s) on external interface of the firewall for a distinct subnet so for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall interface 1.1.1.2&lt;/P&gt;&lt;P&gt;NAT: 2.2.2.2&lt;/P&gt;&lt;P&gt;add arp proxy ipv4-address 2.2.2.2&amp;nbsp;interface eth1 real-ipv4-address 1.1.1.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the firewall does not respond for the proxy arp(s) but rather routes it back to it's default gateway. &amp;nbsp;It's not until I add in a static route with reads:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add static-route 1.1.1.2/32 nexthop gateway logical eth1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that it will start responding for the arps. &amp;nbsp;Is this expected behavior??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Juan&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Sep 2017 12:09:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6187#M226</guid>
      <dc:creator>Juan_Concepcion</dc:creator>
      <dc:date>2017-09-10T12:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6188#M227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The correct procedure to add your own manual static proxy ARPs will vary substantially depending on code version, OS, and/or the presence of a firewall cluster.&amp;nbsp; Please see the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30197&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," style="max-width: 840px;"&gt;sk30197: Configuring &lt;STRONG&gt;Proxy&lt;/STRONG&gt; &lt;STRONG&gt;ARP&lt;/STRONG&gt; for Manual NAT&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; now available via &lt;A href="http://maxpowerfirewalls.com" target="_blank"&gt;http://maxpowerfirewalls.com&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Sep 2017 18:49:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6188#M227</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-09-10T18:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6189#M228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As stated in original post R80.10 is the version and adding in the manual proxy arps is not suffice.  When I do this the arp entries are seeing via ‘fw ctl arp’ but when you run an ‘fw monitor’ on the firewall you see that it just simply tries to route the traffic back out if there is not s subsequent “dummy” route provisioned for the address space that does not pertain to the subnet configured on it’s external interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Juan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 10 Sep 2017 19:15:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6189#M228</guid>
      <dc:creator>Juan_Concepcion</dc:creator>
      <dc:date>2017-09-10T19:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6190#M229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can only arp for IPs on the same subnet as one of your interfaces.&lt;/P&gt;&lt;P&gt;This is how arp works.&lt;/P&gt;&lt;P&gt;I suppose adding static routes like you described is another way to achieve the same result.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 05:52:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6190#M229</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-11T05:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6191#M230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So how am I supposed to handle NAT's when they are not located on the same subnet as the external interface of the firewall and you don't have control of upstream router (to route traffic to firewall)?? &amp;nbsp;In previous versions all you had to do was add in manual proxy arps and the firewall received the traffic and processed it correctly. &amp;nbsp;Now it receives the traffic correctly but then incorrectly just tries to route it out unless you have the dummy static route in place.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 18:04:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6191#M230</guid>
      <dc:creator>Juan_Concepcion</dc:creator>
      <dc:date>2017-09-11T18:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6192#M231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm actually surprised it worked like you described at all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your workaround reminds me of NAT in the old days &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 19:55:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6192#M231</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-11T19:55:57Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6193#M232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is what came to mind in how to fix it ☺&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is the behavior it’s exhibiting…&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 19:58:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6193#M232</guid>
      <dc:creator>Juan_Concepcion</dc:creator>
      <dc:date>2017-09-11T19:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6194#M233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seriously, though, it might be worth a TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 21:17:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6194#M233</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-11T21:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6195#M234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You should handle such cases by routing the required IPs / subnets from your nexthop to the gateway(-cluster)-IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if your gw/cluster has IP&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;1.1.1.2 and router in front has&amp;nbsp;&lt;SPAN&gt;1.1.1.1, there should be a route from the router for 2.2.2.2 (or corresponding subnet like 2.2.2.0/x) to the IP 1.1.1.2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Sep 2017 06:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6195#M234</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2017-09-13T06:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6196#M235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doesn’t work – customer has the traffic routed to his firewall and it just routes it back out without the configuration I put in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Juan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Sep 2017 14:53:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/6196#M235</guid>
      <dc:creator>Juan_Concepcion</dc:creator>
      <dc:date>2017-09-13T14:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy Arp's for subnet not on firewall</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/47542#M3537</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I noticed your post is from sep 2017, do you know if, by any chance, they have fixed this in recent Jumbos or maybe R80.20?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 21:44:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-Arp-s-for-subnet-not-on-firewall/m-p/47542#M3537</guid>
      <dc:creator>Sergio_Alvarez</dc:creator>
      <dc:date>2019-03-18T21:44:12Z</dc:date>
    </item>
  </channel>
</rss>

