cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
156
Views
1
Helpful
4
Replies

I Can't See ARP for VLAN1 On Subnet interface in FTD

Essa_Rahemi
Level 1
Level 1

I am moving the SVI from switch to FTD for vlan1 and using it sub interface, but i dont see arp entry for vlan1. I noticed this at least for 3 different sites and 6 firewalls. it works for other VLANs except VLAN1.

Any idea why is this the issue ? 

4 Replies 4

Change native of trunk connect to FTD to be other vlan not valn1 and check. 

Issue I think because of native of trunk

MHM

this is what i was thinking too. So i will try to change this in MW. i believe this should resolve the issue. 

balaji.bandi
Hall of Fame
Hall of Fame

I generally avoid VLAN 1  for security reason. and add native vlan as new vlan.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

wajidhassan
Level 4
Level 4
Hi @Essa_Rahemi 
The missing ARP entries for VLAN1 on FTD subinterfaces can be due to:
  • VLAN1 reserved behavior: Some Cisco devices treat VLAN1 differently, sometimes limiting features like ARP on subinterfaces.

  • Subinterface configuration: Ensure the VLAN tagging and encapsulation on the subinterface is correctly configured for VLAN1.

  • Security policies or inspection: Check if any access control or inspection rules on FTD are blocking ARP or related traffic on VLAN1.

  • Software versions: Verify if this is a known issue in your FTD version and consider updating to the latest recommended release.

Review these areas; this should help resolve or narrow down the cause.

Hope this helps.

Review Cisco Networking for a $25 gift card