- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi all,
We did have an issue with the Automatic Proxy ARP configuration.
After all troubleshooting we decided to put the Manuel Proxy arp configuration and it worked right away.
Im still confused on how to configure the Automatic Proxy configuration for manuel NAT rules :
Server Manager --> NAT -- > Automatic NAT configuration -- > Merge Manuel Proxy ARP configuration :
or
Using the sk114395 where you have to modify the file : $CPDIR/tmp/.CPprofile.sh
Thanks
Let's do this from the start.
sk30197 describes multiple procedures to create manual ARP entries for different implementation cases.
sk114395 provides you with a new way to create manual ARP entries in a limited case of Source NAT only. Not in any circumstances should you consider sk114395 being a replacement of "Merge manual proxy ARP" option. Even if you are using sk114395, you should still enable that option in case you have both manual and automatic ARP entries on you FW.
Did you look into sk30197 before anything else?
Hi @Hamza ,
When you mention Automatic Proxy ARP, are you referring to Proxy ARP entries being automatically created for Manual NAT rules (manually defined in the NAT policy) or are you referring to Automatic NAT rules? (where you set the NAT properties within the properties of the network object itself)
Yes im refering to Proxy ARP entries bieng automatically created for manual rules defines in NAT Policy.
So my question is to know the difference between the two configuration. And which is the right one to use :
following the sk114395
or from the SMS by checking the boxes Automatic NAT configuration -- > Merge Manuel Proxy ARP
Hi @Hamza , I'm by no means an expert, but from my understanding, "Merge Manual Proxy ARP" will combine manually created ARP entries (created in GAiA WebUI or cli or previously via $FWDIR/conf/local.arp) with the Proxy ARP entries created by using Automatic NAT (where you define the NAT on the network object rather than a manual NAT rule which automatically adds a Proxy ARP entry) and allows you to use both methods simultaneously.
My understanding of sk114395, is that this feature now creates these previously manual Proxy ARP entries automatically (at least for Source Manual NAT). If I'm correct, this would mean that you wouldn't have to manually add the Proxy ARP entry as you mentioned you did in order to make it work.
@_Val_ is vastly more experienced than myself however so maybe he can confirm or correct this understanding
@Reevsie147
Before commenting on the sk114395 procedure, I need to understand if @Hamza actually read and followed the default recommended procedure from sk30197.
"Merge Manual Proxy Arp" will not lead to creating automatic entries for manual NAT rules. sk114395 is only applicable to specific scenarios and for source NAT rules exclusively. It is not an ultimate replacement of manual proxy ARP method.
Hello VAL,
I did read the sk114395 and sk30197.
from what i understand; these options are doing the same thing :
Automatic ARP Configuration
sk114395 (source NAT) : by modifying the file $CPDIR/tmp/.CPprofile.sh : but Most cases where we use Proxy ARP in our Production is for source NAT
Manual proxy ARP configuration
This is based on the Note on the sk30197 :
If "Automatic ARP configuration" setting is enabled, but "Merge manual proxy ARP configuration" setting is not enabled, then the Security Gateway ignores the Proxy ARP entries in the $FWDIR/conf/local.arp fil"
Still cannot see the difference between these options. Or maybe there are 3 oprions to configure Proxy ARP ?
Hamza
Absolutely not the same thing.
Let's do this from the start.
sk30197 describes multiple procedures to create manual ARP entries for different implementation cases.
sk114395 provides you with a new way to create manual ARP entries in a limited case of Source NAT only. Not in any circumstances should you consider sk114395 being a replacement of "Merge manual proxy ARP" option. Even if you are using sk114395, you should still enable that option in case you have both manual and automatic ARP entries on you FW.
Hello Val,
This is much more clear now : The option " Automatic creation of Proxy ARP entries option in the SMS is applicable only for Automatic rules)
For me and it make sense with the response that i received from TAC today :
" If we want automatic proxy arp creation for manuel NAT rule we need to modify the file $CPDIR/tmp/.CPprofile.sh "
The LAST points under investigation with TAC team : is why automatic creation of proxy ARP is working for manuel NAT rules without editing the file $CPDIR/tmp/.CPprofile.sh and without entries in local.arp in one of our firewalls (VSX R80.40 / 7000 appliance)
Hamza
Hello,
Actually automatic creation of proxy ARP was not working for manuel NAT at all, i discovered that we were Nating to the IP address of the interface , and the incoming NAT was not working too.
Thank you Val for all explanations.
Hamza
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
15 | |
12 | |
8 | |
6 | |
6 | |
6 | |
5 | |
5 | |
4 | |
3 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY