- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
We have noticed with newer appliances (standard cluster members, not VSX or Maestro) that we do not get a response to "arping" requests as we do with older appliances, open servers, and CG IaaS on VMware. The issue is present for both standard and bond interfaces. We are definitely getting a response as running a tcpdump in another window for ARP traffic for the address in the arping command shows the reply.
We use arping extensively for simple connectivity testing (ping is often blocked by firewalls), has anyone else seen this or have any workarounds? The tcpdump approach is a pretty ugly workaround as it needs another command (in another window or as a background task) for each arping.
Cheers
Interesting... any specific model?
Andy
I've only noticed it on 9100 Plus appliances so far.
Code version? The Gaia kernel has been updated numerous times in recent releases, and arping may have been touched by those updates as it is a Linux utility.
That could be, for sure. I had not seen this on new 3920 models though.
Andy
R81.20 JHF 105
When you say you don't get a response, what exactly do you mean? As you said, you must be getting ARP replies, otherwise traffic wouldn't work. Is the arping command telling you it got no responses?
[Expert@DallasSC]# arping -I eth1 -c 1 10.0.1.252
ARPING 10.0.1.252 from 10.0.1.251 eth1
Unicast reply from 10.0.1.252 [00:12:C1:10:01:FC] 0.802ms
Sent 1 probes (1 broadcast(s))
Received 1 response(s)
[Expert@DallasSC]# cpinfo -y all 2>&1 | grep JUMBO_HF_MAIN | uniq
HOTFIX_R82_JUMBO_HF_MAIN Take: 41
BUNDLE_R82_JUMBO_HF_MAIN Take: 41
I just did tcpdump -enni any arp in my lab and gave results. Not sure what was exact command ran by @Paul_Hagyard , but even any arp command I did was fine too.
Andy
Correct, arping shows no responses but tcpdump shows the reply is seen.
Seen on 9100 Plus appliances.
What about just arp or arp -a?
Andy
Those are both passive, so you need to ping first (or something) to generate an ARP request then check the arp table (arp -an). arping is a quick way to confirm that all the devices you could see before (e.g. platform migration) are still visible after.
Odd...just tried in the lab, even R82 has same issue.
Andy
That's bizarre. I would open a TAC case at this point. arping definitely works in general on Check Point's software.
Might be a quirk with the 9100. I don't have one to test to be sure, but I doubt that's it. Check Point's branded hardware is pretty vanilla amd64 gear, just with weird, proprietary card slots. It's normal enough you can run Windows on it.
Just tried on customer's 6200, same issue.
Andy
Same behaviour on 9300 Plus with R82 JHF 39
I would open TAC case for this.
Andy
Please open a TAC case for this
I've raised a SR and the latest response included:
"The R&D team is actively working on it under case ID TM-89261."
Thanks for letting us know, Paul.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
13 | |
12 | |
11 | |
10 | |
9 | |
8 | |
7 | |
6 | |
5 | |
5 |
Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY