<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gaia 80.40 arp cache time out issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/181466#M33210</link>
    <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/88946"&gt;@GeorgeF&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;Couple of things I would check. Please run fw ctl arp from expert mode and verify the output, as well as settings from below (global properties in smart console)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20983i3C55EDFB81E266C2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Fri, 19 May 2023 13:34:55 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-05-19T13:34:55Z</dc:date>
    <item>
      <title>Gaia 80.40 arp cache time out issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/181463#M33209</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a Gaia 80.40 security gateway cluster ( Active,Standby) , and&amp;nbsp; its VLAN21's interface acts as the gateway of Cisco WLC+APs VLAN21.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;The end users complains about no internet after connected to WIFI.(passed 802.1x authentication). DHCP server is on CiscoWLC VLAN21 SVI and laptop got a dynamic IP address.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;On gateway(Gaia), the Dynamic ARP table seems no update&lt;/STRONG&gt;. (The validity timeout is 60s, and Announce Restriction level is 2.)&lt;/P&gt;&lt;P&gt;We find the ARP entry is not right for the non-working laptop. If we delete the ARP entry on gateway, or ping 8.8.8.8 on the laptop, the ARP entry on gateway will update to the right MAC address in a few seconds. ( I think the reply packets was sent to wrong MAC address, which caused the laptop "no internet" before we deleted the wrong one)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;It is very weird that the ARP entry on the gateway will stay a very long time, and didn't update.&lt;/STRONG&gt;(An example is that: there are only 3 WIFI users, but there are still 80 entries in the gateway's ARP table) . I assume that if the laptop leave the office, its gateway(Gaia) ARP entry should be deleted, as the validity timeout is 60s. I checked the ARP table on WLC, it will delete the laptop's MAC address when users dropped off.&lt;/P&gt;&lt;P&gt;I captured packets form non-working laptop, it seems gateway replied its MAC to laptop when laptop requests, and the laptop also announced itself's MAC address. I assume that during this process, gateway should learn and update ARP table. But it didn't. The IP was still bond to its previous MAC address.( Unless you ping 8.8.8.8 from laptop, or delete ARP entry on the gateway, which is mentioned above)&lt;/P&gt;&lt;P&gt;Is there any mechanic to trigger the gateway(Gaia)'s ARP entry update? Why the dropped off user's ARP entries are still shown in the ARP table? It should be deleted after dropped off for 60s, isn't it?&amp;nbsp; ( there is no static ARP entry configured, all talking about dynamic entry)&lt;/P&gt;&lt;P&gt;Thanks very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 13:23:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/181463#M33209</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2023-05-19T13:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia 80.40 arp cache time out issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/181466#M33210</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/88946"&gt;@GeorgeF&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P&gt;Couple of things I would check. Please run fw ctl arp from expert mode and verify the output, as well as settings from below (global properties in smart console)&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20983i3C55EDFB81E266C2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 13:34:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/181466#M33210</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-19T13:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia 80.40 arp cache time out issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/181545#M33229</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; the command &lt;SPAN&gt;fw ctl arp&amp;nbsp;&lt;/SPAN&gt;output is&amp;nbsp; " No proxy ARP entries "&lt;/P&gt;&lt;P&gt;2. NAT settings is attached.&lt;/P&gt;&lt;P&gt;By the way, On Saturday&amp;nbsp; and there are only 3 devices connected to wifi, and on the WLC, the DHCP pool has only 3 active IP addresses. Also I checked the ARP table on the WLC, it has only 3 entries.&lt;/P&gt;&lt;P&gt;But , on the gateway, I find that all the DCHP pool scope entries are there. I mean from 192.168.21.20 - 192.168.21.200, entries are all there! I assume it should be deleted if no one answers its arp request when reached the validity timeout (60s).&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;[update] On Sunday, there are only 1 devices connected to wifi, and on the WLC there is only 2 ARP entries (DHCP server and gateway) , But on the gateway, there are still 66 ARP entries... (VLAN21)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;It seems the ARP entry stuck for a long time and can't update automatically!&amp;nbsp; It can only update until Ping or&amp;nbsp; until many days later it was deleted automatically.&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;On the other hand, about the validity timeout, I found it is explained as below:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;" Configures the time, in seconds, to keep resolved dynamic ARP entries in the ARP cache table.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;If the entry is not referred to&lt;/STRONG&gt;&lt;/EM&gt; and &lt;STRONG&gt;&lt;EM&gt;is not used by traffic&lt;/EM&gt;&lt;/STRONG&gt; before this time elapses, the dynamic ARP entry is deleted from the ARP cache table.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Otherwise, an ARP Request will be sent to verify the MAC address. "&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;How can I check the condition: be referred and be used by traffic ?&amp;nbsp; I see that all echo-requests ICMP traffic to to gateway ( from 192.168.21.x to 192.168.1.1) are dropped by Clean-up rules, is it "referred" and "used"?&amp;nbsp; (client to gateway echo-request is allowed)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 05:26:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/181545#M33229</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2023-05-22T05:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia 80.40 arp cache time out issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/181546#M33230</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems someone has the same issue with me:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Stale-ARP-Entries/td-p/131577" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/Stale-ARP-Entries/td-p/131577&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk175603" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk175603&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;This is the output for command:&amp;nbsp;&amp;nbsp;&lt;EM&gt;cpinfo -y all&lt;/EM&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is Check Point CPinfo Build 914000234 for GAIA&lt;BR /&gt;[IDA]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[MGMT]&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 48&lt;BR /&gt;[CPFC]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[FW1]&lt;BR /&gt;HOTFIX_R80_40_MAAS_TUNNEL_AUTOUPDATE&lt;BR /&gt;HOTFIX_GOT_TPCONF_AUTOUPDATE&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 48&lt;/P&gt;&lt;P&gt;FW1 build number:&lt;BR /&gt;This is Check Point's software version R80.40 - Build 088&lt;BR /&gt;kernel: R80.40 - Build 079&lt;BR /&gt;[SecurePlatform]&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 48&lt;BR /&gt;[PPACK]&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 48&lt;BR /&gt;[CPinfo]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[AutoUpdater]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[CVPN]&lt;BR /&gt;HOTFIX_R80_40_JUMBO_HF_MAIN Take: 48&lt;BR /&gt;[CPUpdates]&lt;BR /&gt;BUNDLE_CPVIEWEXPORTER_AUTOUPDATE Take: 27&lt;BR /&gt;BUNDLE_CPOTELCOL_AUTOUPDATE Take: 25&lt;BR /&gt;BUNDLE_GENERAL_AUTOUPDATE Take: 13&lt;BR /&gt;BUNDLE_CPSDC_AUTOUPDATE Take: 23&lt;BR /&gt;BUNDLE_CORE_FILE_UPLOADER_AUTOUPDATE Take: 21&lt;BR /&gt;BUNDLE_R80_40_MAAS_TUNNEL_AUTOUPDATE Take: 49&lt;BR /&gt;BUNDLE_HCP_AUTOUPDATE Take: 59&lt;BR /&gt;BUNDLE_GOT_TPCONF_AUTOUPDATE Take: 112&lt;BR /&gt;BUNDLE_R80_40_JUMBO_HF_MAIN Take: 48&lt;BR /&gt;BUNDLE_INFRA_AUTOUPDATE Take: 58&lt;BR /&gt;BUNDLE_DEP_INSTALLER_AUTOUPDATE Take: 25&lt;BR /&gt;BUNDLE_R80_40_JUMBO_HF_MAIN_SC Take: 45&lt;BR /&gt;[CPDepInst]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[hcp_wrapper]&lt;BR /&gt;HOTFIX_HCP_AUTOUPDATE&lt;BR /&gt;[DIAG]&lt;BR /&gt;No hotfixes..&lt;BR /&gt;[core_uploader]&lt;BR /&gt;HOTFIX_CHARON_HF&lt;BR /&gt;[cpsdc_wrapper]&lt;BR /&gt;HOTFIX_CPSDC_AUTOUPDATE&lt;BR /&gt;[CPotelcol]&lt;BR /&gt;HOTFIX_OTLP_GA&lt;BR /&gt;[CPviewExporter]&lt;BR /&gt;HOTFIX_OTLP_GA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 06:38:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/181546#M33230</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2023-05-22T06:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: Gaia 80.40 arp cache time out issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/183676#M33714</link>
      <description>&lt;P&gt;Updated to the hotfix take 197 and set the new added parameter to 1, then solved the issue, the arp table's updates works well.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2023 04:15:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Gaia-80-40-arp-cache-time-out-issue/m-p/183676#M33714</guid>
      <dc:creator>GeorgeF</dc:creator>
      <dc:date>2023-06-09T04:15:12Z</dc:date>
    </item>
  </channel>
</rss>

