<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FTD 1120 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-1120/m-p/4717843#M1094850</link>
    <description>&lt;P&gt;Hey! Currently working on FTD 1120 which is managed by FDM, and my query is.&lt;/P&gt;
&lt;P&gt;FDM-6.6.1-91 VDB-336.0&lt;/P&gt;
&lt;P&gt;- Configured Two ISP links on FDM with sla monitor.&lt;/P&gt;
&lt;P&gt;-Basic configuration one access-list for Lan users to access internet and Nat policy which is in auto nat with dynamic.&lt;/P&gt;
&lt;P&gt;-everything is working fine for certain time and after that lan users are not able to access internet after checking logs observed that ARP cache is getting filled. when i clear arp table manually then again started working. Please explain for this type of behaviour.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: LAN user is directly connected to FW, no n/w devices are their b/w firewall and Lan.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Nov 2022 11:44:41 GMT</pubDate>
    <dc:creator>Mani G</dc:creator>
    <dc:date>2022-11-08T11:44:41Z</dc:date>
    <item>
      <title>FTD 1120</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120/m-p/4717843#M1094850</link>
      <description>&lt;P&gt;Hey! Currently working on FTD 1120 which is managed by FDM, and my query is.&lt;/P&gt;
&lt;P&gt;FDM-6.6.1-91 VDB-336.0&lt;/P&gt;
&lt;P&gt;- Configured Two ISP links on FDM with sla monitor.&lt;/P&gt;
&lt;P&gt;-Basic configuration one access-list for Lan users to access internet and Nat policy which is in auto nat with dynamic.&lt;/P&gt;
&lt;P&gt;-everything is working fine for certain time and after that lan users are not able to access internet after checking logs observed that ARP cache is getting filled. when i clear arp table manually then again started working. Please explain for this type of behaviour.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note: LAN user is directly connected to FW, no n/w devices are their b/w firewall and Lan.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 11:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120/m-p/4717843#M1094850</guid>
      <dc:creator>Mani G</dc:creator>
      <dc:date>2022-11-08T11:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120/m-p/4732752#M1095656</link>
      <description>&lt;P&gt;When you look at the arp cache, do you see a bunch of the same MAC addresses? I've seen this in the past, where a device was proxy arping for everything. If this is the case, track down what is doing the proxy arp.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 17:47:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120/m-p/4732752#M1095656</guid>
      <dc:creator>ABaker94985</dc:creator>
      <dc:date>2022-12-05T17:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120/m-p/4732772#M1095657</link>
      <description>&lt;P&gt;you use nat without add keyword no proxy arp&lt;BR /&gt;add this keyword and everything will be fine.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/116154-qanda-ASA-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-appliance-asa-software/116154-qanda-ASA-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 19:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120/m-p/4732772#M1095657</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-12-05T19:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 1120</title>
      <link>https://community.cisco.com/t5/network-security/ftd-1120/m-p/4732802#M1095660</link>
      <description>&lt;P&gt;Hi Mani,&lt;BR /&gt;I would say verify the interface status and then check ARP status.&lt;BR /&gt;Also clear arp entry and take captures to verify if there is any MAC in particualr thats causing the issue.&lt;BR /&gt;&lt;BR /&gt;As a temporary solution you can configure static ARP.&lt;BR /&gt;&lt;BR /&gt;There could be many reasons that could cause this issue. - incorrect config issue, proxy arp config issue, &amp;nbsp;ARP cahce timeout value etc.&lt;BR /&gt;&lt;BR /&gt;Try to take captures, and see the behaviour. If the issue still persists maybe try to take help from TAC and trouleshoot further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;-----------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;If you find my reply solved your question or issue, kindly click the 'Accept as Solution' button and vote it as helpful.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;You can also learn more about Secure Firewall (formerly known as NGFW) through our live Ask the Experts (ATXs) session. Check out Cisco Network Security ATXs Resources [&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/cisco-network-security-ask-the-experts-resources/ta-p/4416493&lt;/A&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;] to view the latest schedule for upcoming sessions, as well as the useful references, e.g. online guides, FAQs.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="background-color:rgb(255,255,255);color:rgb(24,24,24);font-size:14px;"&gt;-----------------------------------------&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;Reagrds&lt;BR /&gt;Divya Jain&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 20:04:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-1120/m-p/4732802#M1095660</guid>
      <dc:creator>Divya Jain</dc:creator>
      <dc:date>2022-12-05T20:04:40Z</dc:date>
    </item>
  </channel>
</rss>

