<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834909#M174486</link>
    <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;Proxy ARP is enabled for your nat statements.&lt;/P&gt;
&lt;P&gt;please add "no-proxy-arp route-lookup" keywords at the end of these statements.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;Remember to rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 28 Nov 2015 15:41:18 GMT</pubDate>
    <dc:creator>Akshay Rastogi</dc:creator>
    <dc:date>2015-11-28T15:41:18Z</dc:date>
    <item>
      <title>proxyarp</title>
      <link>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834908#M174485</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As in&amp;nbsp; the picture &amp;nbsp;attached &amp;nbsp;ASA dmz&amp;nbsp; also replying&amp;nbsp; the ARP request. And the host 1 update arp cache with the&amp;nbsp; ASA interface mac address .&lt;/P&gt;
&lt;P&gt;This stops the communication between HOST 1 and&amp;nbsp; HOST 2 .&lt;/P&gt;
&lt;P&gt;How can i solve this issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;other related configuration for the proxyarp&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;no sysopt noproxyarp Outside&lt;/P&gt;
&lt;P&gt;no sysopt noproxyarp DMZ&lt;/P&gt;
&lt;P&gt;no sysopt noproxyarp Inside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;object network DMZ-Network&lt;/P&gt;
&lt;P&gt;subnet 172.16.20.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;no proxyarp configured in the below statement&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;nat (DMZ,any) source static DMZ-Network DMZ-Network destination static VPN-POOLSALES&amp;nbsp;&amp;nbsp; VPN-POOLSALES&lt;/P&gt;
&lt;P&gt;nat (DMZ,any) source static DMZ-Network DMZ-Network destination static&amp;nbsp; VPN-POOLEMP VPN-POOLEMP&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834908#M174485</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2019-03-12T06:57:35Z</dc:date>
    </item>
    <item>
      <title>Hi.</title>
      <link>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834909#M174486</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;
&lt;P&gt;Proxy ARP is enabled for your nat statements.&lt;/P&gt;
&lt;P&gt;please add "no-proxy-arp route-lookup" keywords at the end of these statements.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;Remember to rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2015 15:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834909#M174486</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-28T15:41:18Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834910#M174487</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;How does the &amp;nbsp;below &amp;nbsp;statement&amp;nbsp;casue a problem&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;nat (DMZ,any) source static DMZ-Network DMZ-Network destination static VPN-POOLSALES VPN-POOLSALES&lt;BR /&gt;nat (DMZ,any) source static DMZ-Network DMZ-Network destination static VPN-POOLEMP VPN-POOLEMP&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;VPN-POOLSALES&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;172.16.128.65-172.16.128.78 mask 255.255.255.240&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; VPN-POOLEMP&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;172.16.128.33-172.16.128.46 mask 255.255.255.240&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;so how does it affect&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 03:08:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834910#M174487</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2015-11-29T03:08:41Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834911#M174488</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;As you have 'source static DMZ-Network DMZ-Network' on your nat statment, so ASA is supposed to respond to ARP request coming on it. Therefore it affects your traffic. Also proxy arp is enabled by default 'no sysopt noproxyarp DMZ'.&amp;nbsp; this says 'no' to 'noproxyarp' which means enable proxy arp.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it answers your queries.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 03:39:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834911#M174488</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-29T03:39:47Z</dc:date>
    </item>
    <item>
      <title>Hi Akshay </title>
      <link>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834912#M174489</link>
      <description>&lt;P&gt;Hi Akshay&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your answer.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have one more &amp;nbsp;PAT statement like below&amp;nbsp;&lt;/P&gt;
&lt;P&gt;nat (DMZ,Outside) after-auto source dynamic DMZ-Network interface .&lt;/P&gt;
&lt;P&gt;Does it statement also impact the traffic ? .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What if i disable proxyarp in&amp;nbsp;the &amp;nbsp;DMZ interface , does it solve the problem instead of adding &amp;nbsp;&lt;SPAN&gt;no-proxy-arp route-lookup" &amp;nbsp;each and every nat statement .&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Disabling proxy arp cause another issue ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 03:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834912#M174489</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2015-11-29T03:52:13Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834913#M174490</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;ASA does not perform proxy arp for dynamic statement. It should not cause any issue.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;Remember to rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 04:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834913#M174490</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-29T04:42:18Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834914#M174491</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Thank you .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to conclude ,&amp;nbsp;what about the below&amp;nbsp;command causes the asa respond to arp request?&lt;/P&gt;
&lt;P&gt;object network webserver&lt;BR /&gt; host 172.16.20.50&lt;BR /&gt;object network webserver&lt;BR /&gt; nat (DMZ,Outside) static 2.2.2.2&lt;/P&gt;
&lt;P&gt;Thank &amp;nbsp;you&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 06:04:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834914#M174491</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2015-11-29T06:04:28Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834915#M174492</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;This statement is for traffic going to leaving Outside interface or traffic coming from Outside hosts to IP 2.2.2.2&lt;/P&gt;
&lt;P&gt;ASA would respond to ARP request for destination IP 2.2.2.2 coming on its Outside Interface.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Akshay Rastogi&lt;/P&gt;
&lt;P&gt;Remember to rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 06:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/proxyarp/m-p/2834915#M174492</guid>
      <dc:creator>Akshay Rastogi</dc:creator>
      <dc:date>2015-11-29T06:26:35Z</dc:date>
    </item>
  </channel>
</rss>

