- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I have general questions about the below,
we have enabled Object Static NAT for one internal server to access the internet and expose the internet internal services, not added proxy ARP and arp.local manual file.
when I put fw ctl arp
I can see NAT public IP and MAC in the list. its okay to show as normal.
but when i put expert mode #arp, it's showing incomplete.
we have configured more than 10 Objects the same as that (static object nat), but #arp only shows this incomplete entry.
Kindly share your knowledge to understand, what is the deferent why it's incomplete.
Thank you,
Duminda Lakmal.
Is this a single gateway or cluster and are you running the commands on the active member?
Which gateway version and is the NAT working or not?
Yes. This is Cluster. I ran this on Active Gateway.
This is R80.20, NAT working fine. This is for my knowledge.
In early R80.20 JHF there were cosmetic differences between some ARP commands but not of this nature (sk112753).
Is this JHF T190 or higher?
Take 190 - Released on 28 February 2021 and declared as General Availability on 12 April 2021
PRJ-21242,PRHF-12746
Security Gateway: In rare scenarios, proxy ARP entries may be deleted when installing a policy.
Take 187 - Released on 17 November 2020
PRJ-13693,PMTR-55510
Security Gateway: Proxy arp change is applied only after the second policy installation.
*Note: R80.20 is End of Support and upgrading is recommended.
If I'm understanding your description correctly, this is expected behavior. The firewall won't get its own ARP requests, so it won't respond to itself.
Normally, the firewall shouldn't be talking to an address which it translates. It should talk to the real address. What are you trying to do?
I assume the OP is trying to follow the likes of sk30197 which states:
To display the ARP Proxy table entries on the Security Gateway, use these commands in Expert mode:
[Expert@HostName:0]# fw ctl arp
[Expert@HostName:0]# fw ctl arp -n
[Expert@HostName:0]# arp -a
[Expert@HostName:0]# arp -e
Thanks for pointing out all of them, I just always did fw ctl arp.
Thanks a lot for the clarification.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 20 | |
| 8 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY