Well everything looks correct here, has anything in the config of the underlying Gaia eth8 interface been changed on the fly at all since the last boot? Try tcpdump again, but this time with the -p option to suppress promiscuous mode as shown below, do you still see the ARP requests for 85.21.100.105 coming in:
tcpdump -p -eni eth8 arp
If you don't seem them coming in any more it is a network problem. If you do still see them coming in, try running
fw ctl zdebug drop
Is it logging any kind of drop or other difficulty handling ARP in the zdebug?
Next try reinstalling policy, then try this next from expert mode:
ifdown eth8;ifup eth8
If that still doesn't work only thing I can suggest at this point is a reboot, lame as that sounds.
--
My book "Max Power: Check Point Firewall Performance Optimization"
now available via http://maxpowerfirewalls.com.
Gaia 4.18 (R82) Immersion Tips, Tricks, & Best Practices Video Course
Now Available at https://shadowpeak.com/gaia4-18-immersion-course