- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi,
I have general questions about the below,
we have enabled Object Static NAT for one internal server to access the internet and expose the internet internal services, not added proxy ARP and arp.local manual file.
when I put fw ctl arp
I can see NAT public IP and MAC in the list. its okay to show as normal.
but when i put expert mode #arp, it's showing incomplete.
we have configured more than 10 Objects the same as that (static object nat), but #arp only shows this incomplete entry.
Kindly share your knowledge to understand, what is the deferent why it's incomplete.
Thank you,
Duminda Lakmal.
Is this a single gateway or cluster and are you running the commands on the active member?
Which gateway version and is the NAT working or not?
Yes. This is Cluster. I ran this on Active Gateway.
This is R80.20, NAT working fine. This is for my knowledge.
In early R80.20 JHF there were cosmetic differences between some ARP commands but not of this nature (sk112753).
Is this JHF T190 or higher?
Take 190 - Released on 28 February 2021 and declared as General Availability on 12 April 2021
PRJ-21242,PRHF-12746
Security Gateway: In rare scenarios, proxy ARP entries may be deleted when installing a policy.
Take 187 - Released on 17 November 2020
PRJ-13693,PMTR-55510
Security Gateway: Proxy arp change is applied only after the second policy installation.
*Note: R80.20 is End of Support and upgrading is recommended.
If I'm understanding your description correctly, this is expected behavior. The firewall won't get its own ARP requests, so it won't respond to itself.
Normally, the firewall shouldn't be talking to an address which it translates. It should talk to the real address. What are you trying to do?
I assume the OP is trying to follow the likes of sk30197 which states:
To display the ARP Proxy table entries on the Security Gateway, use these commands in Expert mode:
[Expert@HostName:0]# fw ctl arp
[Expert@HostName:0]# fw ctl arp -n
[Expert@HostName:0]# arp -a
[Expert@HostName:0]# arp -e
Thanks for pointing out all of them, I just always did fw ctl arp.
Thanks a lot for the clarification.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 65 | |
| 18 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 2 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY