<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA not proxy ARPing remote IP address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462843#M654218</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot, static NAT allows me to gain remote access to the swit&lt;/P&gt;&lt;P&gt;ch and I am able to configure default route on the switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 17 Jul 2010 20:55:46 GMT</pubDate>
    <dc:creator>oldcreek12</dc:creator>
    <dc:date>2010-07-17T20:55:46Z</dc:date>
    <item>
      <title>ASA not proxy ARPing remote IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462839#M654189</link>
      <description>&lt;P&gt;Hi, I am setting up a simple site2site VPN between ASA5520 at HQ and ASA5505 in remote office, HQ uses 10.0.0.0/8 network while remote office use 172.30.16.0/20 network, ASA5505's inside IP is 172.30.16.0.254/24, there is a C3560 connect to ASA's inside interface with IP 172.30.16.252/24. IPsec tunnel is fine, however when I ping from 10.1.1.108 from HQ, echo request is sent to C3560 by ASA 5505, but I can not get echo reply back from remote C3560 switch, debug on ASA5505 shows that when C3560 tries to ARP for 10.1.1.108,&amp;nbsp; ASA5505 does not proxy-ARP it. I have default proxy-arp turned on. I can set C3560's default gateway to ASA5505's inside IP address to avoide proxy-arp, but I don't have network connection to C3560, classical chicken-egg problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug arp&amp;nbsp; enabled at level 1&lt;BR /&gt;asa5505# arp-in: request at inside from 172.30.16.252 001e.1477.4f40 for 10.1.1.108 0000.0000.0000&lt;BR /&gt;arp-set: added arp inside 172.30.16.252 001e.1477.4f40 and updating NPs at 301045040&lt;/P&gt;&lt;P&gt;arp-in: request at inside from 172.30.16.252 001e.1477.4f40 for 10.1.1.108 0000.0000.0000&lt;BR /&gt;arp-set: added arp inside 172.30.16.252 001e.1477.4f40 and updating NPs at 301048040&lt;BR /&gt;b arp-in: request at inside from 172.30.16.252 001e.1477.4f40 for 10.1.1.108 0000.0000.0000&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462839#M654189</guid>
      <dc:creator>oldcreek12</dc:creator>
      <dc:date>2019-03-11T18:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA not proxy ARPing remote IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462840#M654202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the default gateway on the 3560? Can you ensure that the 3560 has&lt;/P&gt;&lt;P&gt;the default gateway set to the inside of 5505. Also, if you have turned on&lt;/P&gt;&lt;P&gt;routing on 3560, then you should use "ip route 0.0.0.0 0.0.0.0 " form to set the default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Jul 2010 18:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462840#M654202</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-07-17T18:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA not proxy ARPing remote IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462841#M654211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but that is not the point, I don't have to set C3560's default-gateway, ASA5505 is supposed to proxy-arp any ARP requestion coming from C3560. (Beside, as I mentioned, I don't have network connectivity to C3560)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Jul 2010 19:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462841#M654211</guid>
      <dc:creator>oldcreek12</dc:creator>
      <dc:date>2010-07-17T19:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA not proxy ARPing remote IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462842#M654214</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA will not Proxy-ARP for every destination unless you have configured NAT&lt;/P&gt;&lt;P&gt;on that interface. If you have configured something like "static&lt;/P&gt;&lt;P&gt;(outside,inside) 10.0.0.0 10.0.0.0 255.0.0.0", then ASA will ARP for it. It&lt;/P&gt;&lt;P&gt;will not Proxy-arp in general as it could lead to catastrophic network&lt;/P&gt;&lt;P&gt;issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Jul 2010 19:30:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462842#M654214</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-07-17T19:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA not proxy ARPing remote IP address</title>
      <link>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462843#M654218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot, static NAT allows me to gain remote access to the swit&lt;/P&gt;&lt;P&gt;ch and I am able to configure default route on the switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Jul 2010 20:55:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-not-proxy-arping-remote-ip-address/m-p/1462843#M654218</guid>
      <dc:creator>oldcreek12</dc:creator>
      <dc:date>2010-07-17T20:55:46Z</dc:date>
    </item>
  </channel>
</rss>

