<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use of Proxy ARP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195495#M36412</link>
    <description>&lt;P&gt;Bro, you are too funny &lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thats what nslookup command is for lol...even ping would give you an IP address, regardless if its successful or not.&lt;/P&gt;
&lt;P&gt;nslookup google.com or any fqdn&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 18 Oct 2023 03:06:03 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-10-18T03:06:03Z</dc:date>
    <item>
      <title>Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195353#M36359</link>
      <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;
&lt;P&gt;Is the use of Proxy ARP mandatory in Check Point Firewalls?&lt;/P&gt;
&lt;P&gt;According to the documentation and some materials I have found on the Internet, the use of Proxy ARP is usually related to the publications.&lt;/P&gt;
&lt;P&gt;Is this mandatory on all architectures?&lt;/P&gt;
&lt;P&gt;For example, if I publish a web service to the Internet, do I need to "focus" on the arp table of my publication?&lt;/P&gt;
&lt;P&gt;Proxy ARP is directly related only to Manual NAT, right?&lt;BR /&gt;&lt;BR /&gt;Cheers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 01:29:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195353#M36359</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-17T01:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195354#M36360</link>
      <description>&lt;P&gt;I find not needed in R81+.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 01:42:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195354#M36360</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-17T01:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195355#M36361</link>
      <description>&lt;P&gt;What is the need to use Proxy ARP?&lt;/P&gt;
&lt;P&gt;I have a client that has version R81.10 and has using this table.&lt;/P&gt;
&lt;P&gt;Is it mandatory to use this table when I "want" to publish services to the Internet?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 01:46:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195355#M36361</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-17T01:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195356#M36362</link>
      <description>&lt;P&gt;If you Google cisco proxy arp explanation, its best on the Internet, in my opinion, but below sums it up well.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;Let us consider the following scenario:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Two networks (&lt;EM&gt;Network_A&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Network_B&lt;/EM&gt;) are separated by a Security Gateway (single Security Gateway or ClusterXL).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;On each network, there is a host (&lt;EM&gt;Host_A&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Network_A&lt;/EM&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Host_B&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Network_B&lt;/EM&gt;).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Let us assume, that&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Network_A&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;represents the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Internal&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;network, and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Network_B&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;represents the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;External&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;network.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;According to the existing standards, when&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Host_B&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;needs to send data to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Host_A&lt;/EM&gt;, an ARP Request for the MAC address of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Host_A&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;will be sent by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Host_B&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Network_B&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;Since&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Host_A&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is located on another network, and the Security Gateway acts as a router, this ARP Request (sent to Broadcast address on Layer2) will not be forwarded by the Security Gateway from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Network_B&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Network_A&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;As a result,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Host_B&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;will not discover the MAC address of&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Host_A&lt;/EM&gt;, and will not be able to send the data to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Host_A&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;A standard solution, in such cases, is to configure the Security Gateway to act as&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;Proxy ARP&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;The Security Gateway will pretend to be the Host in question. The Security Gateway will accept the ARP Requests and the Security Gateway will send its own MAC Address in ARP Reply. Then, when the data is received from the External network, the Security Gateway will forward the data to the relevant host on the Internal network.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk30197" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk30197&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 01:52:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195356#M36362</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-17T01:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195382#M36369</link>
      <description>&lt;P&gt;Buddy,&lt;/P&gt;
&lt;P&gt;I find sense in your explanation and the documentation, but for "inbound" traffic (my company's publications, to the Internet, maybe).&lt;/P&gt;
&lt;P&gt;But, have you ever used or seen anyone use a Proxy ARP entry for "Outbound" traffic (Surfing to the Internet from my LAN)?&lt;/P&gt;
&lt;P&gt;I have come across a customer, who has in his ARP Table, added a line, with the VIP IP of his Cluster (IP with which his LAN surfs the Internet), but I don't find much sense in it.&lt;/P&gt;
&lt;P&gt;If I delete that entry in the TABLE, they simply run out of Internet.&lt;/P&gt;
&lt;P&gt;Does it make sense to use the Proxy ARP in the LAN -&amp;gt; WAN direction?&lt;/P&gt;
&lt;P&gt;Cheers.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 10:39:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195382#M36369</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-17T10:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195383#M36370</link>
      <description>&lt;P&gt;Yes but usually not the VIP itself rather if the hide NAT IP is on the same subnet as the External VIP is one such case.&lt;/P&gt;
&lt;P&gt;Where possibly use routing rather than proxy-arp is my recommendation for reliability&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 10:51:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195383#M36370</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-17T10:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195384#M36371</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;In my case, the client has a public pool that is /27.&lt;/P&gt;
&lt;P&gt;One of those publics is set as "VIP" of the External Cluster interface.&lt;/P&gt;
&lt;P&gt;I have never seen ARP proxy configured in the LAN -&amp;gt; WAN direction, and that caused me doubts.&lt;/P&gt;
&lt;P&gt;Is there any way to guarantee the LAN Internet service, if I remove the entry from the ARP Table?&lt;/P&gt;
&lt;P&gt;Because we already tried it, and when we remove it, the LAN is without Internet.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 11:10:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195384#M36371</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-17T11:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195388#M36375</link>
      <description>&lt;P&gt;No buddy, in my 15 years dealing with CP, I had NEVER seen anyone use proxy arp for outbound connection.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 11:33:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195388#M36375</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-17T11:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195394#M36378</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;When you have a cluster, the active member replys to arp request for the VIP, so it is like a "implicit proxy arp" then you do not need to configure. The cluster knows which is the VIP based on the topology configuration on smartconsole, so if you need to create this proxy arp entry manually it seems to me that there is some misconfiguration on the cluster topology. Using this command "cphaprob -a if" do you see the cluster VIP on the external interface? are the members IP addresses on the same public network than the VIP?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 12:19:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195394#M36378</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2023-10-17T12:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195429#M36390</link>
      <description>&lt;P&gt;Proxy ARP is only necessary if you are using an IP address on the same subnet as the firewall for NAT or similar.&lt;BR /&gt;If it a different subnet than the firewall, Proxy ARP is not necessary.&lt;BR /&gt;Automatic NAT rules will handle the Proxy ARP configuration.&lt;BR /&gt;Manual NAT rules may require additional Proxy ARP configuration.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 14:23:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195429#M36390</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-17T14:23:50Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195470#M36401</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This is what I get from the command "cphaprob -a if".&lt;/P&gt;
&lt;P&gt;The IP of the Cluster VIP is 38.43.131.133&lt;/P&gt;
&lt;P&gt;This is the IP that is manually added in the ARP TABLE (Proxy ARP), and it is something that does not make much sense to me.&lt;/P&gt;
&lt;P&gt;If I remove that entry from the ARP TABLE, the client is left without Internet.&lt;/P&gt;
&lt;P&gt;Any idea "why" this happens?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 21:49:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195470#M36401</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-17T21:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195471#M36402</link>
      <description>&lt;P&gt;Can you show the actual arp entry?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 21:50:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195471#M36402</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-17T21:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195484#M36403</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This is how it is currently observed, in each GW of the Cluster.&lt;/P&gt;
&lt;P&gt;I attach it in a txt, so that it can be more understandable.&lt;/P&gt;
&lt;P&gt;The Cluster VIP IP is the one ending in x.x.x.x.133, and for some strange reason, they configured it as another entry in the PROXY ARP.&lt;/P&gt;
&lt;P&gt;If we delete this entry, the client will no longer have Internet.&lt;/P&gt;
&lt;P&gt;We have found that when we delete the entry, the client can still ping public IPs, such as 8.8.8.8.8 or 1.1.1.1.1, but it no longer has DNS resolution.&lt;/P&gt;
&lt;P&gt;Simply put, it can no longer "surf" to web pages.&lt;/P&gt;
&lt;P&gt;Instead when you add the entry, where you put the IP of the VIP, the client has a full Internet service.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 01:26:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195484#M36403</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-18T01:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195485#M36404</link>
      <description>&lt;P&gt;Ok, I get the whole picture now. But, here is the way I would approach this. I get its probably not possible without replicating it (meaning deleting that entry), but it would be interesting to see if they can access any webpages by an IP address when that ARP entry is deleted....ie, can they acess whatever IP &lt;A href="http://www.google.com" target="_blank" rel="noopener"&gt;www.google.com&lt;/A&gt;&amp;nbsp;resolves to?&lt;/P&gt;
&lt;P&gt;Also, keep in mind, it would be impossible for TAC to troubleshoot this, unless the issue is present during the call.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 01:36:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195485#M36404</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-18T01:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195486#M36405</link>
      <description>&lt;P&gt;No.&lt;/P&gt;
&lt;P&gt;What we have validated, is that, when we remove the entry from the ARP TABLE (Proxy ARP)&lt;/P&gt;
&lt;P&gt;Any PC on the LAN can still ping public IPs, such as 1.1.1.2 or 8.8.4.4.4, but what stops working is the DNS resolution itself.&lt;/P&gt;
&lt;P&gt;That is, if the PC does a "ping facebook.com" or "ping yahoo.com", it simply does not resolve.&lt;/P&gt;
&lt;P&gt;Obviously the pages don't load, and everyone runs around, shouting "I HAVE NO INTERNET" "THE INTERNET IS DOWN"&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I don't understand why that entry is configured there, and the worst thing is that when the GW restarts, well that line is deleted, and the "internet down" problem starts.&lt;/P&gt;
&lt;P&gt;I have never seen such an entry, in the sense of LAN -&amp;gt; WAN.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 01:40:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195486#M36405</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-18T01:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195487#M36406</link>
      <description>&lt;P&gt;I know...when people shout in Spanish, it sounds kind of funny lol&lt;/P&gt;
&lt;P&gt;Anyway, my question was NOT about the ping, but can they access any site by an IP address?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 01:42:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195487#M36406</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-18T01:42:33Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195488#M36407</link>
      <description>&lt;P&gt;We have not been able to perform this test.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 01:56:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195488#M36407</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-18T01:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195489#M36408</link>
      <description>&lt;P&gt;Here is logic behind why Im asking you that question. Say, for example, lets take simple home setup. Person says they cant access the Internet, but, if they can access any site by the IP it resolves to, then it 100% means its DNS issue. Same goes here...so I think it would be helpful to confirm that in the next window, that if customer is willing to let you troubleshoot.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 02:07:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195489#M36408</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-18T02:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195493#M36410</link>
      <description>&lt;P&gt;I would need to know the Public IP of any domain on the Internet.&lt;BR /&gt;Something I don't know now &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Suddenly you know the Public IP of https://&amp;lt;IP_Public_CheckPoint&amp;gt;, to do the test.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 02:52:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195493#M36410</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-10-18T02:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: Use of Proxy ARP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195495#M36412</link>
      <description>&lt;P&gt;Bro, you are too funny &lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thats what nslookup command is for lol...even ping would give you an IP address, regardless if its successful or not.&lt;/P&gt;
&lt;P&gt;nslookup google.com or any fqdn&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 03:06:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Use-of-Proxy-ARP/m-p/195495#M36412</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-18T03:06:03Z</dc:date>
    </item>
  </channel>
</rss>

