<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ARP Issue in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211388#M10507</link>
    <description>&lt;P&gt;Duration aside for the moment this is expected since the interface state on the Check Point didn't change.&lt;/P&gt;
&lt;P&gt;ARP timeout is currently not configurable, separately from DHCP lease time etc.&lt;/P&gt;
&lt;P&gt;What value do you see with this?&lt;/P&gt;
&lt;P&gt;[Expert@1500]# cat /proc/sys/net/ipv4/neigh/&amp;lt;interface_name&amp;gt;/gc_stale_time&lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2024 12:16:04 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2024-04-16T12:16:04Z</dc:date>
    <item>
      <title>ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211363#M10500</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have&amp;nbsp;Check Point's 1570 Appliance R80.20.50 - Build 773&lt;/P&gt;&lt;P&gt;I have issue with ARP entries.&lt;/P&gt;&lt;P&gt;After I move computers from one network to another (I change VLAN in my Switch for example&lt;BR /&gt;from VLAN 30 to VLAN 44) I get duplicate entries.&lt;/P&gt;&lt;P&gt;Sometime check point delete it quickly sometime it is there for day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;[Expert@Test]# arp -n | grep a1&lt;BR /&gt;? (10.40.30.10) at e3:75:aa:aa:bb:a1 [ether] on LAN8.30&lt;BR /&gt;? (10.40.44.10) at e3:75:aa:aa:bb:a1 [ether] on LAN8.44&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to get rid of duplicate entries?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 08:08:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211363#M10500</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2024-04-16T08:08:31Z</dc:date>
    </item>
    <item>
      <title>Re: ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211369#M10501</link>
      <description>&lt;P&gt;Did you try a reboot ? I would also suggest to update to R81.10.10 as your current firmware will be out of support in Jun-24.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 09:11:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211369#M10501</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-04-16T09:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211375#M10503</link>
      <description>&lt;P&gt;Restart helping but in my organization I have a lot of IP chage on daily basis, I can't reboot each time it is hapening.&lt;/P&gt;&lt;P&gt;I will try to upgrade and see if it will help.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 10:29:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211375#M10503</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2024-04-16T10:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211381#M10504</link>
      <description>&lt;P&gt;Afaik clearing the arp cache is only possible in GAiA, not in GAiA Embedded.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 11:19:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211381#M10504</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-04-16T11:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211382#M10505</link>
      <description>&lt;P&gt;Can you describe the issue in more detail, you have multiple hosts on the same VLAN with conflicting ARP entries or just stale entries for ARP/DHCP triggered by the move?&lt;/P&gt;
&lt;P&gt;Also for awareness per sk166552 all interfaces will share the same mac unless you overwrite this.&amp;nbsp;&lt;SPAN&gt;Most switches with per-vlan learning shouldn't have an issue with this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 11:26:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211382#M10505</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-04-16T11:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211385#M10506</link>
      <description>&lt;P&gt;I have very simple lab, firewall connected to swtich.&lt;/P&gt;&lt;P&gt;I have a lot of sub interfaces on the firewall.&lt;/P&gt;&lt;P&gt;I have PC connected to switch with VLAN X.&lt;/P&gt;&lt;P&gt;After I change VLAN on the switch to VLAN Y,&lt;/P&gt;&lt;P&gt;My PC get new IP from VLAN Y address pool (Check Point is DHCP Server for all sub intefaces).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On Check Point in ARP table we will see two entries, same MAC diffrenet IPs.&lt;/P&gt;&lt;P&gt;This ARP entries remain in ARP table a lot of time (sometime more then 12 hours).&lt;/P&gt;&lt;P&gt;This behabiour is unwanted.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 11:48:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211385#M10506</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2024-04-16T11:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211388#M10507</link>
      <description>&lt;P&gt;Duration aside for the moment this is expected since the interface state on the Check Point didn't change.&lt;/P&gt;
&lt;P&gt;ARP timeout is currently not configurable, separately from DHCP lease time etc.&lt;/P&gt;
&lt;P&gt;What value do you see with this?&lt;/P&gt;
&lt;P&gt;[Expert@1500]# cat /proc/sys/net/ipv4/neigh/&amp;lt;interface_name&amp;gt;/gc_stale_time&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 12:16:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211388#M10507</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-04-16T12:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211390#M10508</link>
      <description>&lt;P&gt;Everthing by default is 60&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 12:39:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211390#M10508</guid>
      <dc:creator>leonid1890</dc:creator>
      <dc:date>2024-04-16T12:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: ARP Issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211404#M10509</link>
      <description>&lt;P&gt;Since this is a lab it's definitely worth checking if R81.10.10 changes your symptoms, else you will need to review with TAC.&lt;/P&gt;
&lt;P&gt;In parallel I would suggest discussing the need for the configurable ARP timeout with your local CP SE as an RFE.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2024 13:19:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ARP-Issue/m-p/211404#M10509</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-04-16T13:19:02Z</dc:date>
    </item>
  </channel>
</rss>

