<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Proxy arp issue - automatic NAT rule in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261382#M44209</link>
    <description>&lt;P&gt;Hi Chris, yes and yes&lt;/P&gt;</description>
    <pubDate>Thu, 30 Oct 2025 08:53:15 GMT</pubDate>
    <dc:creator>carl_t</dc:creator>
    <dc:date>2025-10-30T08:53:15Z</dc:date>
    <item>
      <title>Proxy arp issue - automatic NAT rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261369#M44204</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;We had an issues yesterday whereby we created a static NAT on the object but it didnt work.&lt;/P&gt;&lt;P&gt;We found that we needed to manually put the proxy arp entry on the gateway.&lt;/P&gt;&lt;P&gt;We have the global properties set to automatic arp configuration and merge manual proxy arp configuration set.&lt;/P&gt;&lt;P&gt;I thought that when doing automatic rules such as on the object you dont need to add it manually on the gateway? why would this not have worked ?&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 08:11:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261369#M44204</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2025-10-30T08:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy arp issue - automatic NAT rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261373#M44205</link>
      <description>&lt;P&gt;Automatic static NAT rules should add a proxy arp entry into the kernel running config.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The command to check it on the gateway/s after the policy installation is:&lt;/P&gt;
&lt;P&gt;fw ctl arp&lt;/P&gt;
&lt;P&gt;Was it a Host object and a standard configuration? Meaning nothing complicated, just a normal host static NAT.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 08:25:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261373#M44205</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-10-30T08:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy arp issue - automatic NAT rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261374#M44206</link>
      <description>&lt;P&gt;Hi, yes it was a host object with the static NAT config applied, it only seemed to work if we added the manual proxy arp entry on Gaia.&lt;/P&gt;&lt;P&gt;If i removed the manual proxy arp entry and typed fw ctl arp, it was actually showing in there&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 08:28:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261374#M44206</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2025-10-30T08:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy arp issue - automatic NAT rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261379#M44208</link>
      <description>&lt;P&gt;Did you install policy after making the change?&lt;/P&gt;
&lt;P&gt;Was the mac-address the expected one for the given cluster member?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 08:36:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261379#M44208</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-10-30T08:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy arp issue - automatic NAT rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261382#M44209</link>
      <description>&lt;P&gt;Hi Chris, yes and yes&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 08:53:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261382#M44209</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2025-10-30T08:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy arp issue - automatic NAT rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261383#M44210</link>
      <description>&lt;P&gt;The automatic static NAT rule adds the proxy arp during policy install and as long as there are no typos then the expected behaviour is that the gateway/cluster 'takes responsibility' for the static NAT IP address. Meaning that it replies to the ARP WHO HAS with the interface in the relevant subnet.&lt;/P&gt;
&lt;P&gt;If you double checked everything, which I am sure you did, and maybe some packet captures to see the behaviours on the network (looking for ARP WHO HAS and ARP IS AT), then it may be a problem with the software (bug).&lt;/P&gt;
&lt;P&gt;The fact that it worked with a Gaia level proxy arp seems to point to a software of config error.&lt;/P&gt;
&lt;P&gt;Sounds like one for TAC if you have done all the checks.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 08:57:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261383#M44210</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2025-10-30T08:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy arp issue - automatic NAT rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261479#M44249</link>
      <description>&lt;P&gt;share screenshot to make sure no mistakes are made from the host object&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 20:11:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261479#M44249</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-10-30T20:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Proxy arp issue - automatic NAT rule</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261504#M44255</link>
      <description>&lt;P&gt;Hey Carl,&lt;/P&gt;
&lt;P&gt;I would agree with Don on this one. If you checked everything, TAC case sounds like the best idea at this point.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 23:06:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Proxy-arp-issue-automatic-NAT-rule/m-p/261504#M44255</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-30T23:06:26Z</dc:date>
    </item>
  </channel>
</rss>

