<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Proxy Arp in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-proxy-arp/m-p/1431771#M692026</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I kind of guessed it would be something like that - I would like to turn Proxy arp off on the management interface but i'm a little bit worried about disconnecting myself and not being able to fix it quickly -&amp;nbsp; this is&amp;nbsp; on a live network. I think common sense would tell me to do it out of office hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks for the information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Apr 2010 08:32:34 GMT</pubDate>
    <dc:creator>KeithN123</dc:creator>
    <dc:date>2010-04-26T08:32:34Z</dc:date>
    <item>
      <title>ASA Proxy Arp</title>
      <link>https://community.cisco.com/t5/network-security/asa-proxy-arp/m-p/1431769#M691946</link>
      <description>&lt;P&gt;Is it normal for traffic between hosts on the same subnet&lt;/P&gt;&lt;P&gt;to&amp;nbsp; be "Proxied" by the ASA interface ? If I turn off proxy arp it breaks the configured NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:37:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-proxy-arp/m-p/1431769#M691946</guid>
      <dc:creator>KeithN123</dc:creator>
      <dc:date>2019-03-11T17:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Proxy Arp</title>
      <link>https://community.cisco.com/t5/network-security/asa-proxy-arp/m-p/1431770#M691989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;KeithN123 wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it normal for traffic between hosts on the same subnet&lt;/P&gt;&lt;P&gt;to&amp;nbsp; be "Proxied" by the ASA interface ? If I turn off proxy arp it breaks the configured NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic between hosts in the same subnet should not need to go via the ASA. It is often a good idea to turn off proxy-arp when not needed but as you have found it can break nat statements. Generally speaking you need proxy-arp on the outside interface of the ASA most of the time but whether or not you need it on the other interfaces all depends on which nat translations you have setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note also that the ASA might well be responding to the arp but so will/should the destination host in the same subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 08:18:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-proxy-arp/m-p/1431770#M691989</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-04-26T08:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Proxy Arp</title>
      <link>https://community.cisco.com/t5/network-security/asa-proxy-arp/m-p/1431771#M692026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I kind of guessed it would be something like that - I would like to turn Proxy arp off on the management interface but i'm a little bit worried about disconnecting myself and not being able to fix it quickly -&amp;nbsp; this is&amp;nbsp; on a live network. I think common sense would tell me to do it out of office hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;many thanks for the information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keith&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2010 08:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-proxy-arp/m-p/1431771#M692026</guid>
      <dc:creator>KeithN123</dc:creator>
      <dc:date>2010-04-26T08:32:34Z</dc:date>
    </item>
  </channel>
</rss>

