<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX 515E arp problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515e-arp-problem/m-p/710224#M1035626</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX ?arp problem? that is somewhat strange. In a network used solely for Internet access there are three PIX firewalls, one 506e and two 515e failover pairs, total five boxes. All use PIX OS 6.3(5) and the only other unit in this network is the ISP router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The network is connected using two C3750 stacks separated by a fiber (different locations). The 506e and one pair of 515e is located on one side/switch, and one 515e pair and the ISP router is located on the other side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes the 515e on the same side/switch that 506e cannot reach the 506e. Ping doesn?t work and VPN is down etc. Connections from the other side/Internet to 506e still works indicating that the 506e is OK.  Normally, the connection is working again after about four hours (arp timeout). If I clear the arp cache manually in the ?failing? 515e it works immediately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought that a static arp entry would solve the problem but it didn?t. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping output?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX ON THE SAME SIDE:&lt;/P&gt;&lt;P&gt;fwgbg001# ping x.x.x.x&lt;/P&gt;&lt;P&gt;        x.x.x.x NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;        x.x.x.x NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;        x.x.x.x NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;fwgbg001#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX ON THE OTHER SIDE:&lt;/P&gt;&lt;P&gt;fw01# ping x.x.x.x&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwgbg001# clear arp&lt;/P&gt;&lt;P&gt;fwgbg001# ping x.x.x.x&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;fwgbg001#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw01# ping x.x.x.x&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;fw01#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 09:09:07 GMT</pubDate>
    <dc:creator>afredriksson</dc:creator>
    <dc:date>2019-03-11T09:09:07Z</dc:date>
    <item>
      <title>PIX 515E arp problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-arp-problem/m-p/710224#M1035626</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX ?arp problem? that is somewhat strange. In a network used solely for Internet access there are three PIX firewalls, one 506e and two 515e failover pairs, total five boxes. All use PIX OS 6.3(5) and the only other unit in this network is the ISP router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The network is connected using two C3750 stacks separated by a fiber (different locations). The 506e and one pair of 515e is located on one side/switch, and one 515e pair and the ISP router is located on the other side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes the 515e on the same side/switch that 506e cannot reach the 506e. Ping doesn?t work and VPN is down etc. Connections from the other side/Internet to 506e still works indicating that the 506e is OK.  Normally, the connection is working again after about four hours (arp timeout). If I clear the arp cache manually in the ?failing? 515e it works immediately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought that a static arp entry would solve the problem but it didn?t. Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping output?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX ON THE SAME SIDE:&lt;/P&gt;&lt;P&gt;fwgbg001# ping x.x.x.x&lt;/P&gt;&lt;P&gt;        x.x.x.x NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;        x.x.x.x NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;        x.x.x.x NO response received -- 1000ms&lt;/P&gt;&lt;P&gt;fwgbg001#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PIX ON THE OTHER SIDE:&lt;/P&gt;&lt;P&gt;fw01# ping x.x.x.x&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwgbg001# clear arp&lt;/P&gt;&lt;P&gt;fwgbg001# ping x.x.x.x&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;fwgbg001#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw01# ping x.x.x.x&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;        x.x.x.x response received -- 0ms&lt;/P&gt;&lt;P&gt;fw01#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:09:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-arp-problem/m-p/710224#M1035626</guid>
      <dc:creator>afredriksson</dc:creator>
      <dc:date>2019-03-11T09:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515E arp problem</title>
      <link>https://community.cisco.com/t5/network-security/pix-515e-arp-problem/m-p/710225#M1035644</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ran into a similiar problem and sysopt noproxyarp fixed it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More info &lt;A class="jive-link-custom" href="http://cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_chapter09186a00801cd841.html#wp1026942" target="_blank"&gt;http://cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_chapter09186a00801cd841.html#wp1026942&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Dec 2006 17:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515e-arp-problem/m-p/710225#M1035644</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2006-12-15T17:11:25Z</dc:date>
    </item>
  </channel>
</rss>

