cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
922
Views
0
Helpful
1
Replies

PIX Arp issue

hossk
Level 1
Level 1

I have setup a pair of PIX(failover). I have no problem ping across the firewall to remote subnet. But When i try to ping within the same subnet, it fails.

When I do show arp on one of the machine. The mac addresses of the machines in the local subnet is showing mac address on the PIX firewall interface.

When I do a no sysopt noproxyarp on the affected interface.

The problem goes away.

I am puzzled. Anyone has any ideas

1 Reply 1

yusuff
Cisco Employee
Cisco Employee

The PIX is proxyarping for your inside addresses because you might have "alias" command configured, its a known issue, below is the bug ID, remove the alias command and you'll see the problem is gone, PIX will no longer prozyarp for inside addresses.

CSCdt01825

HTH

R/Yusuf

Review Cisco Networking for a $25 gift card