<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273135#M4055</link>
    <description>&lt;P&gt;Yes, the policy was installed after configuring the NAT.&lt;/P&gt;&lt;P&gt;The screenshots were taken after the policy installation, and I also switched to the relevant VS context before running "fw ctl arp".&lt;/P&gt;</description>
    <pubDate>Wed, 11 Mar 2026 13:49:11 GMT</pubDate>
    <dc:creator>OriN</dc:creator>
    <dc:date>2026-03-11T13:49:11Z</dc:date>
    <item>
      <title>Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273021#M4044</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm working in a Check Point environment that uses &lt;STRONG&gt;VSX running on Maestro&lt;/STRONG&gt;, and I have a question regarding &lt;STRONG&gt;Automatic NAT and Proxy ARP behavior&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;When creating an object in SmartConsole, there is an option to enable &lt;STRONG&gt;Automatic NAT&lt;/STRONG&gt; and select &lt;STRONG&gt;"Hide behind IP address"&lt;/STRONG&gt;, which automatically creates the NAT rule.&lt;/P&gt;&lt;P&gt;However, after enabling this option, when I check the &lt;STRONG&gt;Proxy ARP table on the gateway&lt;/STRONG&gt;, I do not see any entry for the NAT IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should &lt;STRONG&gt;Proxy ARP be created automatically&lt;/STRONG&gt; when using Automatic NAT with "Hide behind IP address"?&lt;/P&gt;&lt;P&gt;Or do I need to &lt;STRONG&gt;configure Proxy ARP manually&lt;/STRONG&gt; for these addresses?&lt;/P&gt;&lt;P&gt;Does the behavior change in &lt;STRONG&gt;VSX environments or when using Maestro&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any clarification or official documentation references would be appreciated.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2026 17:04:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273021#M4044</guid>
      <dc:creator>OriN</dc:creator>
      <dc:date>2026-03-10T17:04:55Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273022#M4045</link>
      <description>&lt;P&gt;Hide behind IP address is what I suspect the IP of the firewall itself, so then you do not need to proxy arp because the firewall ''owns'' this IP.&lt;/P&gt;
&lt;P&gt;If you want you create proxy arp there is a special procedure for VSX + Maestro. You have to change this in gclish and in the correct VS. (Not vs0). After that the arp file will only be on the SMO and needs to be copied to the other gateways in the sec group.&lt;/P&gt;
&lt;P&gt;These steps you can find here, check this &lt;A href="https://support.checkpoint.com/results/sk/sk30197" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk30197&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Under section:&amp;nbsp;&lt;/P&gt;
&lt;H2 id="Procedures"&gt;Procedures&lt;/H2&gt;
&lt;UL&gt;
&lt;LI id="Procedure_for_Scalable_Platforms"&gt;&lt;A class="checkpoint_toggle" target="_blank"&gt;Procedure for Scalable Platforms (Maestro / Scalable Chassis / ElasticXL)&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 10 Mar 2026 17:35:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273022#M4045</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-03-10T17:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273062#M4051</link>
      <description>&lt;P&gt;If the IP that you're NAT'ing behind is not the gateway itself but is an IP from a directly connected subnet then you should see it when you move to that VS context and look at 'fw ctl arp'. yes.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 00:08:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273062#M4051</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-03-11T00:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273123#M4053</link>
      <description>&lt;P&gt;As shown in the screenshots I attached:&lt;/P&gt;&lt;P&gt;The object is created with Automatic NAT ("Hide behind IP address").&lt;/P&gt;&lt;P&gt;The automatic NAT rule is created in the policy.&lt;/P&gt;&lt;P&gt;I switched to the relevant VS context and ran "fw ctl arp".&lt;/P&gt;&lt;P&gt;However, the&amp;nbsp;"fw ctl arp" output does not show any entry for the NAT IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing any additional step, or should the Proxy ARP entry be created automatically in this case?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 12:33:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273123#M4053</guid>
      <dc:creator>OriN</dc:creator>
      <dc:date>2026-03-11T12:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273130#M4054</link>
      <description>&lt;P&gt;Have you installed policy after configuring the NAT?&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 13:29:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273130#M4054</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-03-11T13:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273135#M4055</link>
      <description>&lt;P&gt;Yes, the policy was installed after configuring the NAT.&lt;/P&gt;&lt;P&gt;The screenshots were taken after the policy installation, and I also switched to the relevant VS context before running "fw ctl arp".&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2026 13:49:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273135#M4055</guid>
      <dc:creator>OriN</dc:creator>
      <dc:date>2026-03-11T13:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273200#M4057</link>
      <description>&lt;P&gt;Is the IP you are NAT'ing behind in the same subnet as one of the gateway's interface IPs?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 01:37:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273200#M4057</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-03-12T01:37:49Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273212#M4060</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;wrote... If the NAT'ing IP is not in the same subnet as the interfaces IP there is no need for a proxy ARP entry.&amp;nbsp; The packets are sent with the NAT'ing IP as source and if the answer get routed back to your gateway they are doing NAT to the real IP. No need for proxy, only NAT and routing.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 07:28:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273212#M4060</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2026-03-12T07:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273231#M4065</link>
      <description>&lt;P&gt;No, the IP I'm NAT'ing behind is not in the same subnet as any of the gateway interface IPs.&lt;/P&gt;&lt;P&gt;However, I also tested using an IP from the same subnet as one of the gateway interfaces, and the output still did not show any entry for that IP.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 09:19:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273231#M4065</guid>
      <dc:creator>OriN</dc:creator>
      <dc:date>2026-03-12T09:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273232#M4066</link>
      <description>&lt;P&gt;In this case we rely on routing for packets to arrive to the firewall not proxy-ARP.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 11:02:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273232#M4066</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-03-12T11:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273249#M4068</link>
      <description>&lt;P&gt;I initially misunderstood your answer, but now I understand what you meant.&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2026 11:02:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273249#M4068</guid>
      <dc:creator>OriN</dc:creator>
      <dc:date>2026-03-12T11:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Maestro + VSX - Proxy ARP behavior when using Automatic NAT</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273347#M4074</link>
      <description>&lt;P&gt;OK yea, if the IP is not part of an interface subnet it definitely won't proxy ARP, as it wouldn't be a valid configuration. If the NAT IP is part of the interface subnet and it's not there after you install policy then.. not sure, would have to investigate more.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2026 10:37:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/Maestro-VSX-Proxy-ARP-behavior-when-using-Automatic-NAT/m-p/273347#M4074</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2026-03-13T10:37:52Z</dc:date>
    </item>
  </channel>
</rss>

