<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proxy ARP on GAIA in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55038#M4154</link>
    <description>If you use Automatic NAT rules, the Proxy ARPs will be created for you.&lt;BR /&gt;Manual NAT rules still require proxy ARPs to be created.&lt;BR /&gt;In R80.x, automatic ARPs for Manual Source NAT rules can be created but this is not enabled by default.&lt;BR /&gt;See: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114395" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114395&lt;/A&gt;</description>
    <pubDate>Wed, 05 Jun 2019 01:43:21 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-06-05T01:43:21Z</dc:date>
    <item>
      <title>Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/54986#M4149</link>
      <description>&lt;P&gt;Hi community, I've tried to google the topic but didn't find the answer.&lt;/P&gt;&lt;P&gt;The question is why it is required to add the entries to the Proxy ARP on GAIA to make the NAT work? Is there a possibility to enable dynamic arp so that no configuration is required to make an public IP reachable?&lt;/P&gt;&lt;P&gt;Thanks, Harpreet S.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jun 2019 09:19:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/54986#M4149</guid>
      <dc:creator>Harpreet_Singh1</dc:creator>
      <dc:date>2019-06-04T09:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55038#M4154</link>
      <description>If you use Automatic NAT rules, the Proxy ARPs will be created for you.&lt;BR /&gt;Manual NAT rules still require proxy ARPs to be created.&lt;BR /&gt;In R80.x, automatic ARPs for Manual Source NAT rules can be created but this is not enabled by default.&lt;BR /&gt;See: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114395" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114395&lt;/A&gt;</description>
      <pubDate>Wed, 05 Jun 2019 01:43:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55038#M4154</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-05T01:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55055#M4156</link>
      <description>&lt;P&gt;Harpreet,&lt;/P&gt;&lt;P&gt;ther's another way to add a proxy arp entry to a gateway without configuring via the GAiA portal.&lt;/P&gt;&lt;P&gt;Add a host object with your external IP to your rulebase and configure automatic NAT (static). As NAT-IP use the same external IP, add the relevant gateway and do a policy install. With this host object the gateway adds an proxy arp entry to the the gateway.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="proxy_arp1.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1454i10A4C6D3BF812A66/image-size/medium?v=v2&amp;amp;px=400" role="button" title="proxy_arp1.PNG" alt="proxy_arp1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="proxy_arp2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1453i023F09B024A907E2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="proxy_arp2.PNG" alt="proxy_arp2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 05:58:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55055#M4156</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-06-05T05:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55063#M4157</link>
      <description>&lt;P&gt;Thank you. sk114395 answer's what I was after.&lt;/P&gt;&lt;P&gt;Why the feature is not enable by default? For more security?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 08:36:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55063#M4157</guid>
      <dc:creator>Harpreet_Singh1</dc:creator>
      <dc:date>2019-06-05T08:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55065#M4158</link>
      <description>&lt;P&gt;We create the specific NAT rules but trying to configure the object will be interesting.&amp;nbsp;Thank you&amp;nbsp;Wolfgang!&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 08:39:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55065#M4158</guid>
      <dc:creator>Harpreet_Singh1</dc:creator>
      <dc:date>2019-06-05T08:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55124#M4160</link>
      <description>&lt;P&gt;It's a change from the default behavior which people are accustomed to, thus why it is not the default.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2019 19:58:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/55124#M4160</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-05T19:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/86888#M6690</link>
      <description>&lt;P&gt;Hi Wolfgang,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do i validate the proxy arp has been created successfully after the below steps has been ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nirvs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 19:02:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/86888#M6690</guid>
      <dc:creator>Nirvs</dc:creator>
      <dc:date>2020-05-31T19:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/86898#M6691</link>
      <description>On the cli of the gateway type: fw clt arp</description>
      <pubDate>Mon, 01 Jun 2020 05:48:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/86898#M6691</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-06-01T05:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/110528#M15190</link>
      <description>&lt;P&gt;Hi Wolfgang,&lt;/P&gt;&lt;P&gt;Will it work when Gateway external IP and NATED IP are from a different pool ??? I have tried to add the Proxy ARP entries as well but still unable to access the NATTEd server IP.&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;CSR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 10:11:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/110528#M15190</guid>
      <dc:creator>CSR</dc:creator>
      <dc:date>2021-02-11T10:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/110531#M15192</link>
      <description>&lt;P&gt;If they are from a different Pool/Subnet you would need to create a route that points to the firewall. ARP is not enough in this case.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 10:48:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/110531#M15192</guid>
      <dc:creator>D_Schimanski</dc:creator>
      <dc:date>2021-02-11T10:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/110543#M15193</link>
      <description>&lt;P&gt;No -&lt;/P&gt;&lt;P&gt;You cant arp for a subnet that isnt attached to the actual interface. How would it route?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are you trying to do?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 12:51:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/110543#M15193</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2021-02-11T12:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/117960#M16689</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Let say you real external interface IP is &lt;STRONG&gt;10.10.10.2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mac address of external interface is &lt;STRONG&gt;00:AC:00:AC:00:AC&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You are trying to use 20.20.20.2 a NAT IP for one of internal hosts.&lt;/P&gt;&lt;P&gt;So your local.arp should look like :&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;20.20.20.2&amp;nbsp;00:AC:00:AC:00:AC&amp;nbsp;10.10.10.2&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In GAiA web UI you have a way to configure that&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To validate run &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;fw ctl arp&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 May 2021 02:35:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/117960#M16689</guid>
      <dc:creator>Alexander_Grois</dc:creator>
      <dc:date>2021-05-08T02:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/117974#M16691</link>
      <description>&lt;P&gt;I know this is an old post, but personally, I see LOTS of customers using manual static nats and we never had to do proxy arp either in clish or web GUI. Its possible this was more needed pre R80, but I dont see if often any more.&lt;/P&gt;</description>
      <pubDate>Sat, 08 May 2021 20:52:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/117974#M16691</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-05-08T20:52:01Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/117978#M16692</link>
      <description>&lt;P&gt;It depends on where the NAT IP address for manual static NAT comes from.&lt;/P&gt;
&lt;P&gt;If they are "plucked" from an directly attached network adjacent to the firewall (such as the "dirty" segment between the firewall's external interface and the Internet perimeter router), a manual static proxy ARP must be created on the firewall.&amp;nbsp; If however the NAT address is taken from a separate subnet that is explicitly routed to the firewall over a transit network (such as the dirty segment) then proxy ARP is not required, as the Internet perimeter router must already have a static route for that separate NAT subnet and will send traffic bound for it directly to the firewall as the next hop.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 May 2021 02:09:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/117978#M16692</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-05-09T02:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/117988#M16695</link>
      <description>&lt;P&gt;Honestly, I never see people having to do this regardless where traffic comes from. Many times, even TAC is confused whether it should be done or not...&lt;/P&gt;</description>
      <pubDate>Sun, 09 May 2021 11:53:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/117988#M16695</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-05-09T11:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/121974#M17433</link>
      <description>&lt;P&gt;I think I need some help as to 'if' a static ARP is going to be needed, after reading this.&amp;nbsp;&lt;BR /&gt;Here's my scenario (IP's and interfaces are made up)&lt;BR /&gt;I have a site to site VPN with traffic being both source and destination natted. The destination device 10.100.100.1 is on a valid network segment routed on the inside of the firewall on interface ETH1.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Source device 202.15.15.1 this is source natted to 10.200.200.1&lt;BR /&gt;Destination 202.16.16.1 which is destination natted to 10.100.100.1&lt;BR /&gt;&lt;BR /&gt;Traffic arrives to the cluster on interface ETH0. (207.195.233.1 cluster with .4 and .5 for the cluster members. The point to point VPN is operational and traffic is flowing - most of the time.&amp;nbsp;&lt;BR /&gt;My actual issue relates to the VPN not re-establishing when the cluster fails over to the secondary member. It has been suggested that proxy ARP entries are created as it might help.&amp;nbsp;&lt;BR /&gt;So my configuration would be:&lt;BR /&gt;add arp proxy ipv4-address 10.100.100.1 interface ETH0 real ipv4-address 207.195.233.4 (on member 1, and .5 on member 2).&lt;BR /&gt;&lt;BR /&gt;Two questions then.&amp;nbsp;&lt;BR /&gt;1) do I have the configuration line correct in terms of the IP addresses to achieve the desired result, adding the natted destination address?&lt;BR /&gt;2) As the 10.100.100.1 network is valid and routed is the proxy arp actually needed?&lt;BR /&gt;Thanks Matt&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 05:25:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/121974#M17433</guid>
      <dc:creator>nzmatto</dc:creator>
      <dc:date>2021-06-24T05:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/122061#M17454</link>
      <description>&lt;P&gt;ARP (proxy or otherwise) can only be configured for IP addresses on the same subnet.&lt;BR /&gt;Therefore, you can only do a proxy arp (meaning the gateway will respond to ARP requests for this IP address) if the address in question is on the same subnet as one of the firewall interfaces.&amp;nbsp;&lt;BR /&gt;Also, proxy arps in general are created automatically by the gateway when NAT rules are created.&lt;BR /&gt;One almost never has to actually create these anymore.&lt;/P&gt;
&lt;P&gt;What you're describing sounds like an issue where other devices on the same subnet don't know which member currently has the VIP.&lt;BR /&gt;That sounds like issues related to gratuitous ARP:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120495" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk120495&lt;/A&gt;&lt;BR /&gt;We send these by default on failover, but it sounds like other things on the network aren't updating their ARP tables in response (as they should).&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 15:12:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/122061#M17454</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-24T15:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP on GAIA</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/122126#M17465</link>
      <description>&lt;P&gt;Thank you for that most excellent response! I do think the issue is tied to GARP, though have been looking into all suggestions. I think I shall proceed through resolving the GARP issue first as opposed to doing both.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 21:52:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-on-GAIA/m-p/122126#M17465</guid>
      <dc:creator>nzmatto</dc:creator>
      <dc:date>2021-06-24T21:52:03Z</dc:date>
    </item>
  </channel>
</rss>

