<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gratuitous ARP static NAT, 1450-Appliance in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Gratuitous-ARP-static-NAT-1450-Appliance/m-p/9865#M230</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the test! I found a great command. With this command you can force the appliance to send out g-arps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;echo 1 &amp;gt; /proc/sys/net/ipv4/ip_nonlocal_bind --&amp;gt; enable this "feature in the kernel"&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;arping -c 4 -A -I WAN 10.90.186.200 --&amp;gt; here the g-arp will be done for the WAN-Interface and for the IP 10.90.186.200&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;echo 0 &amp;gt; /proc/sys/net/ipv4/ip_nonlocal_bind --&amp;gt; disable this "feature in the kernel"&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;This works great&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Jul 2018 06:38:44 GMT</pubDate>
    <dc:creator>Martin_Peinsipp</dc:creator>
    <dc:date>2018-07-20T06:38:44Z</dc:date>
    <item>
      <title>Gratuitous ARP static NAT, 1450-Appliance</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Gratuitous-ARP-static-NAT-1450-Appliance/m-p/9863#M228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today I migrated a firewall-configuration from a SG80-Appliance to a 1450er-Appliance (configured everything manually, installed the latest firmware 07/2017). We have a lot of auto-static-nats configured there (are terminateing in the WAN-Interface). Just for clarification, the WAN-Inteface is configured with internal-ips (MPLS-Connection).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After activating the new appliance (same&amp;nbsp; ips and static-nat-ips taken from the old SG80-Appliance) the static-nats did not work, because the old MAC-Addresses of the old SG80-Appliance were stored on the router's arp-table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the new MAC of the WAN-Interface was updated immediately. So it seems, that the Firewall does not send out gratuitous arp for static-nat-ips but only for its own IP on the WAN-Interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I said, it was not a problem, but I only want to know, if this is a standard behaviour because today it was the very first time, I did not delete the arp-table for the nat-ips, do not know why. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2018 16:23:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Gratuitous-ARP-static-NAT-1450-Appliance/m-p/9863#M228</guid>
      <dc:creator>Martin_Peinsipp</dc:creator>
      <dc:date>2018-07-17T16:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Gratuitous ARP static NAT, 1450-Appliance</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Gratuitous-ARP-static-NAT-1450-Appliance/m-p/9864#M229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Martin.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the tests I made with&amp;nbsp;a 1470 it seems it does not send gratuitous ARP. It will only respond to ARP requests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems to be the standard behavior.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2018 20:38:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Gratuitous-ARP-static-NAT-1450-Appliance/m-p/9864#M229</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-07-19T20:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: Gratuitous ARP static NAT, 1450-Appliance</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Gratuitous-ARP-static-NAT-1450-Appliance/m-p/9865#M230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for the test! I found a great command. With this command you can force the appliance to send out g-arps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;echo 1 &amp;gt; /proc/sys/net/ipv4/ip_nonlocal_bind --&amp;gt; enable this "feature in the kernel"&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;arping -c 4 -A -I WAN 10.90.186.200 --&amp;gt; here the g-arp will be done for the WAN-Interface and for the IP 10.90.186.200&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;echo 0 &amp;gt; /proc/sys/net/ipv4/ip_nonlocal_bind --&amp;gt; disable this "feature in the kernel"&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;This works great&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;/P&gt;&lt;P lang="en-US" style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jul 2018 06:38:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Gratuitous-ARP-static-NAT-1450-Appliance/m-p/9865#M230</guid>
      <dc:creator>Martin_Peinsipp</dc:creator>
      <dc:date>2018-07-20T06:38:44Z</dc:date>
    </item>
  </channel>
</rss>

