<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FSWM problem Large ARP table in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881695#M437906</link>
    <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm expreiencing a problem in the FWSM on the company. The virtual context stops doing NATs suddenly and the servers behind it get no access to anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall has several static policy nats with port forwarding configured on the Inside interface, and we have figured out that the ARP table becomes really large and it's crating an entry for each host in the outside, that's a lot of hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example NAT:&lt;/P&gt;&lt;P&gt;access-list Lilian-Inside_nat_static_4 extended permit tcp host 192.168.5.118 eq www any&lt;/P&gt;&lt;P&gt;static (Lilian-Inside,Lilian-Outside) tcp LISIM-WAN 8080 access-list Lilian-Inside_nat_static_4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ARP TABLE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lilian-Outside 173.193.106.10 0024.c4c0.b980 &lt;/P&gt;&lt;P&gt; Lilian-Outside 66.77.186.30 0024.c4c0.b980 &lt;/P&gt;&lt;P&gt; Lilian-Outside 201.245.171.190 0024.c4c0.b980 &lt;/P&gt;&lt;P&gt; Lilian-Outside 190.66.208.211 0024.c4c0.b980 &lt;/P&gt;&lt;P&gt; Lilian-Outside 105.136.70.251 0024.c4c0.b980 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... and the list continues up to 450 hosts in this moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't know the reason why the FW creates the Arp entries this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help and thank you in advanc&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 22:59:58 GMT</pubDate>
    <dc:creator>diego.israel</dc:creator>
    <dc:date>2019-03-11T22:59:58Z</dc:date>
    <item>
      <title>FSWM problem Large ARP table</title>
      <link>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881695#M437906</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm expreiencing a problem in the FWSM on the company. The virtual context stops doing NATs suddenly and the servers behind it get no access to anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall has several static policy nats with port forwarding configured on the Inside interface, and we have figured out that the ARP table becomes really large and it's crating an entry for each host in the outside, that's a lot of hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example NAT:&lt;/P&gt;&lt;P&gt;access-list Lilian-Inside_nat_static_4 extended permit tcp host 192.168.5.118 eq www any&lt;/P&gt;&lt;P&gt;static (Lilian-Inside,Lilian-Outside) tcp LISIM-WAN 8080 access-list Lilian-Inside_nat_static_4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ARP TABLE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lilian-Outside 173.193.106.10 0024.c4c0.b980 &lt;/P&gt;&lt;P&gt; Lilian-Outside 66.77.186.30 0024.c4c0.b980 &lt;/P&gt;&lt;P&gt; Lilian-Outside 201.245.171.190 0024.c4c0.b980 &lt;/P&gt;&lt;P&gt; Lilian-Outside 190.66.208.211 0024.c4c0.b980 &lt;/P&gt;&lt;P&gt; Lilian-Outside 105.136.70.251 0024.c4c0.b980 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... and the list continues up to 450 hosts in this moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don't know the reason why the FW creates the Arp entries this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help and thank you in advanc&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881695#M437906</guid>
      <dc:creator>diego.israel</dc:creator>
      <dc:date>2019-03-11T22:59:58Z</dc:date>
    </item>
    <item>
      <title>FSWM problem Large ARP table</title>
      <link>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881696#M437910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I mistyped the title, it should be FWSM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Apr 2012 19:31:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881696#M437910</guid>
      <dc:creator>diego.israel</dc:creator>
      <dc:date>2012-04-30T19:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: FSWM problem Large ARP table</title>
      <link>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881697#M437911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well seems each ARP entry has the same MAC address. Also the MAC address belongs a Cisco device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the MAC addres belong to some interface on the FWSM?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess the amount of ARP entries is due to some NAT configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you only have one public IP address at your disposal? Are all public NAT configurations using the same IP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there some specific reason that you havent done the above NAT configuration for example in the following way&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (Lilian-Inside,Lilian-Outside) tcp LISIM-WAN 8080 192.168.5.118 80 netmask 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2012 16:08:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881697#M437911</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-05-01T16:08:30Z</dc:date>
    </item>
    <item>
      <title>FSWM problem Large ARP table</title>
      <link>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881698#M437912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The mac 0024.c4c0.b980 belongs to a 7600 cisco router, the topology is like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Servers---FW---7609----INTERNET&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Connection to office&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are 2 IPs availables, and both of them are used with port forwarding.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The nats are created that way by the ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have realized that this context uses most of the CPU of the entire FWSM, so we limited the number of xlates alowed in order to avoid affecting performance on other contexts, but the problems with our customer continues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 14:20:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881698#M437912</guid>
      <dc:creator>diego.israel</dc:creator>
      <dc:date>2012-05-02T14:20:38Z</dc:date>
    </item>
    <item>
      <title>FSWM problem Large ARP table</title>
      <link>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881699#M437913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Diego&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems a routing problem regadless to the default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please look oput the default gateway of your FWSM context&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel Gómez&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 22:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fswm-problem-large-arp-table/m-p/1881699#M437913</guid>
      <dc:creator>danielalbertog</dc:creator>
      <dc:date>2012-05-02T22:03:53Z</dc:date>
    </item>
  </channel>
</rss>

