cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
248
Views
5
Helpful
1
Replies

Pix answers DHCP ARP from client connected to VPN3000

harrisn
Level 1
Level 1

I have a PIX 515 running 6.3(3) with 3 zones and a vpn 3000 in one of the zones. everything seems to be functioning properly except that Pix answers DHCP ARP from client connected to VPN3000 this response prevents the client from retaining the address.

1 Reply 1

gfullage
Cisco Employee
Cisco Employee

The PIX will proxy ARP for addresses that it has statics/globals defined in its config.

You can stop this with the command:

sysopt noproxyarp

on the PIX, but monitor access to other devices after issuing this (it shouldn't cause any problems). Worst case add static routes on your devices connected to the PIX for networks on the other side of it, so that the PIX doesn't need to proxy ARP.

Review Cisco Networking for a $25 gift card