<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proxy ARP for Manual NAT – (local.arp file) rewritten after restart in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104477#M8259</link>
    <description>&lt;P&gt;&lt;FONT face="courier new,courier"&gt;$FWDIR/conf/local.arp&lt;/FONT&gt; is always rewritten on boot or configuration change by confd (except on VSX virtual systems &amp;gt;0). It should say so in the first three lines of the file ("&lt;FONT face="courier new,courier"&gt;# This file was AUTOMATICALLY GENERATED&lt;/FONT&gt;"...). Here are the things I would do:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Compare the content of local.arp with the clish configuration ("&lt;FONT face="courier new,courier"&gt;show arp proxy all&lt;/FONT&gt;")&lt;/LI&gt;&lt;LI&gt;Make sure the local.arp on both gateways do not have the immutable flag (&lt;FONT face="courier new,courier"&gt;lsattr $FWDIR/conf/local.arp&lt;/FONT&gt; should not show the "i" flag)&lt;/LI&gt;&lt;LI&gt;Check for custom boot configurations in &lt;FONT face="courier new,courier"&gt;/etc/rc.d/rc.local&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;/etc/rc.d/rc.local.user&lt;/FONT&gt;)&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Mon, 07 Dec 2020 09:55:14 GMT</pubDate>
    <dc:creator>Axel_Engeland</dc:creator>
    <dc:date>2020-12-07T09:55:14Z</dc:date>
    <item>
      <title>Proxy ARP for Manual NAT – (local.arp file) rewritten after restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104469#M8258</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We are running R80.30 in a clustered environment, and have&amp;nbsp;Proxy ARP for Manual NAT – (local.arp file) in place.&lt;/P&gt;&lt;P&gt;I have noticed recently noticed that the local.arp file is written over with other information after every restart of one of the Firewall. The other Firewall is not affected.&lt;/P&gt;&lt;P&gt;I know that a former colleague that has since moved onto another employer had been testing setting up &amp;nbsp;Logical server, and had been experimenting with Proxy Arp for manual NAT (local.arp file).&lt;/P&gt;&lt;P&gt;Does anyone have a clue on where this setting is that rewrites the local.arp file on restart of the Firewall?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;P_M&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 09:07:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104469#M8258</guid>
      <dc:creator>P_M</dc:creator>
      <dc:date>2020-12-07T09:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP for Manual NAT – (local.arp file) rewritten after restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104477#M8259</link>
      <description>&lt;P&gt;&lt;FONT face="courier new,courier"&gt;$FWDIR/conf/local.arp&lt;/FONT&gt; is always rewritten on boot or configuration change by confd (except on VSX virtual systems &amp;gt;0). It should say so in the first three lines of the file ("&lt;FONT face="courier new,courier"&gt;# This file was AUTOMATICALLY GENERATED&lt;/FONT&gt;"...). Here are the things I would do:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Compare the content of local.arp with the clish configuration ("&lt;FONT face="courier new,courier"&gt;show arp proxy all&lt;/FONT&gt;")&lt;/LI&gt;&lt;LI&gt;Make sure the local.arp on both gateways do not have the immutable flag (&lt;FONT face="courier new,courier"&gt;lsattr $FWDIR/conf/local.arp&lt;/FONT&gt; should not show the "i" flag)&lt;/LI&gt;&lt;LI&gt;Check for custom boot configurations in &lt;FONT face="courier new,courier"&gt;/etc/rc.d/rc.local&lt;/FONT&gt; or &lt;FONT face="courier new,courier"&gt;/etc/rc.d/rc.local.user&lt;/FONT&gt;)&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 07 Dec 2020 09:55:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104477#M8259</guid>
      <dc:creator>Axel_Engeland</dc:creator>
      <dc:date>2020-12-07T09:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP for Manual NAT – (local.arp file) rewritten after restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104478#M8260</link>
      <description>&lt;P&gt;Hello Axel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I run &lt;SPAN&gt;("&lt;/SPAN&gt;&lt;FONT face="courier new,courier"&gt;show arp proxy all&lt;/FONT&gt;&lt;SPAN&gt;") then I see that is the content from the output, that is written over to local.arp during restarts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How can I now fix this issue?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;P_M&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 10:17:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104478#M8260</guid>
      <dc:creator>P_M</dc:creator>
      <dc:date>2020-12-07T10:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP for Manual NAT – (local.arp file) rewritten after restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104479#M8261</link>
      <description>&lt;P&gt;Forgot to mention, that is only on one of the cluster members that local.arp is written over during restart.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;P_M&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 10:19:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104479#M8261</guid>
      <dc:creator>P_M</dc:creator>
      <dc:date>2020-12-07T10:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP for Manual NAT – (local.arp file) rewritten after restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104480#M8262</link>
      <description>&lt;P&gt;Hello P_M,&lt;/P&gt;&lt;P&gt;I'd recommend setting up proxy arp according to &lt;A title="sk30197" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30197&amp;amp;partition=Advanced&amp;amp;product=ClusterXL," target="_blank" rel="noopener"&gt;sk30197&lt;/A&gt; on both nodes so local.arp is rewritten at boot, but with correct content. If I have the option to configure something in clish instead of some config file I always prefer clish.&lt;/P&gt;&lt;P&gt;Alternatively, you can write your local.arp manually and protect it from being overwritten by using "&lt;FONT face="courier new,courier"&gt;chattr +i $FWDIR/conf/local.arp&lt;/FONT&gt;", but this is neither recommended nor supported, I guess.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 10:29:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104480#M8262</guid>
      <dc:creator>Axel_Engeland</dc:creator>
      <dc:date>2020-12-07T10:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy ARP for Manual NAT – (local.arp file) rewritten after restart</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104836#M8289</link>
      <description>&lt;P&gt;Hello Axel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response and help!&lt;/P&gt;&lt;P&gt;I removed the Proxy Arp entry and this solved the problem with the local.arp being written over.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;P-M&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 19:32:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Proxy-ARP-for-Manual-NAT-local-arp-file-rewritten-after-restart/m-p/104836#M8289</guid>
      <dc:creator>P_M</dc:creator>
      <dc:date>2020-12-09T19:32:11Z</dc:date>
    </item>
  </channel>
</rss>

