<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: clusterxl vmac and proxy arp in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37430#M7936</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume your clusterXL configuration is with Virtual Mac&lt;/P&gt;&lt;P&gt;In this case in the proxy arp configuration you have to create entries where the MAC is the virtual as well.&lt;/P&gt;&lt;P&gt;By CLI on the gateway, you can run "cphaprob -a if" and next to each virtual IP you see the virtual MAC set.&lt;/P&gt;&lt;P&gt;In case you won't use virtual MAC, the CLI command output won't show any MAC because you will use the physical MAC for the VIP.&lt;/P&gt;&lt;P&gt;in this last scenario in the proxy arp you have to configure the physical mac related of interface where Manual NAT is applied and the MAC on the other cluster member will be different than the other one.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 13 Jul 2018 15:46:46 GMT</pubDate>
    <dc:creator>GG27</dc:creator>
    <dc:date>2018-07-13T15:46:46Z</dc:date>
    <item>
      <title>clusterxl vmac and proxy arp</title>
      <link>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37424#M7930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi team.&lt;/P&gt;&lt;P&gt;I have a question about clusterxl vmac option and nat with proxy arp.&lt;BR /&gt;What mac should be in proxy arp configuration for manual and automatic static nat?&lt;BR /&gt;I think that in both cases should be a virtual mac.&lt;BR /&gt;I'm I right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 11:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37424#M7930</guid>
      <dc:creator>Dmitry_Barantse</dc:creator>
      <dc:date>2018-07-11T11:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: clusterxl vmac and proxy arp</title>
      <link>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37425#M7931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Automatic Static NAT should be handled automatically (i.e. you don't need to add any proxy arp) unless you've disabled Automatic ARP configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/67014_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Manual NAT rules you would use the cluster VMAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 13:00:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37425#M7931</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-11T13:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: clusterxl vmac and proxy arp</title>
      <link>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37426#M7932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Automatic ARP would be created with cluster virtual mac, isn't it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 13:22:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37426#M7932</guid>
      <dc:creator>Dmitry_Barantse</dc:creator>
      <dc:date>2018-07-11T13:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: clusterxl vmac and proxy arp</title>
      <link>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37427#M7933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 13:31:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37427#M7933</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-11T13:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: clusterxl vmac and proxy arp</title>
      <link>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37428#M7934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also keep in mind that on an R80.10+ gateway you can enable automatic handling of Proxy ARP for manual NAT rules and not have to worry about what MAC address it is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114395&amp;amp;partition=Advanced&amp;amp;product=Security" style="max-width: 840px;"&gt;sk114395: Automatic creation of &lt;STRONG&gt;Proxy&lt;/STRONG&gt; &lt;STRONG&gt;ARP&lt;/STRONG&gt; for Manual &lt;STRONG&gt;NAT&lt;/STRONG&gt; rules on Security Gateway R80.10&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2018 14:44:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37428#M7934</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-07-11T14:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: clusterxl vmac and proxy arp</title>
      <link>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37429#M7935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, but it's only for source NAT, so it's not usable for scenario, the connection from the Internet to public IP, which is not configured on any CP interfaces and I need to do DNAT from the public to private towards inside of my web server with 10.1.1.1.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2018 06:54:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37429#M7935</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2018-07-12T06:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: clusterxl vmac and proxy arp</title>
      <link>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37430#M7936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume your clusterXL configuration is with Virtual Mac&lt;/P&gt;&lt;P&gt;In this case in the proxy arp configuration you have to create entries where the MAC is the virtual as well.&lt;/P&gt;&lt;P&gt;By CLI on the gateway, you can run "cphaprob -a if" and next to each virtual IP you see the virtual MAC set.&lt;/P&gt;&lt;P&gt;In case you won't use virtual MAC, the CLI command output won't show any MAC because you will use the physical MAC for the VIP.&lt;/P&gt;&lt;P&gt;in this last scenario in the proxy arp you have to configure the physical mac related of interface where Manual NAT is applied and the MAC on the other cluster member will be different than the other one.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 15:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37430#M7936</guid>
      <dc:creator>GG27</dc:creator>
      <dc:date>2018-07-13T15:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: clusterxl vmac and proxy arp</title>
      <link>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37431#M7937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do keep in mind that in cluster configs using the real-ip part of the statement needs to contain the real IP of the member for that interface.&lt;/P&gt;&lt;P&gt;Also you can see all advertised proxy arp's by using the 'fw ctl arp' command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jul 2018 21:22:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/37431#M7937</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-07-13T21:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: clusterxl vmac and proxy arp</title>
      <link>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/65265#M13344</link>
      <description>&lt;P&gt;Hi Sir,&lt;/P&gt;&lt;P&gt;I believe that it should be configured using Virtual Mac Address but I opened a ticket with TAC and they told me that it must be configured using Physical Mac Address.&lt;/P&gt;&lt;P&gt;Are you that the Proxy ARP must be set using Virtual MAC Address?&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2019 03:12:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/clusterxl-vmac-and-proxy-arp/m-p/65265#M13344</guid>
      <dc:creator>Robert_M_Nubile</dc:creator>
      <dc:date>2019-10-18T03:12:44Z</dc:date>
    </item>
  </channel>
</rss>

