Forum Discussion
Bill_Hoffman_11
Nimbostratus
Jun 18, 2007Proxy ARP Issues with FirePass v6.01
Anyone have any issues with Proxy ARP being enabled with FirePass v6.01? It would be interesting to hear if anyone is having any problems with this. We have setup two separate ingresses and egresses so that we can have separate portals to allow for segmentation of our un-trusted off-shore vendor traffic from our trusted employee traffic. The un-trusted egress is connected to our partner DMZ, and the trusted egress is connected to another network segment. The partner DMZ is separated from our core network by a pix firewall, and the trusted egress is also connected to the same core network as the pix. It appears that if an ARP request is submitted for the un-trusted internal egress on the FirePass device that the trusted internal egress responds and proxys the un-trusted egresses address.
- OwenH_68783
Nimbostratus
I can't tell from the details you posted, but are you sure it's the Firepass doing the proxy-arp? I've had many problems with PIX proxy arp'ing in scenarios where two machines are on the same PIX interface and both have static translations. When they try to talk to each other, the PIX responds with it's MAC. If you're translating the Firepass on the PIX (and I would assume you are), then you might need to hard code the arp table entries for it in the PIX. - Bill_Hoffman_11
Nimbostratus
I have been working with F5's technical support, to help them reproduce the problem that we have been seeing. They were ultimately able to reproduce it thanks to one of their technicians who stuck with us. They will resolve the issue in the next cumulative hotfix for 5.5.2. a description of the Linux kernal option that is causing the problem is documented below.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects