cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
189
Views
0
Helpful
1
Replies

Secondary WAN IP Proxy ARP problem

I have Cisco Firepower with FMC and 3 ISP public IP in one subnet /24. First IP is in firewalls interface, second IP in dedicated PC, third IP I want to 1 to 1 NAT to my DMZ network IP from firewall, but ISP has IP-MAC binding and he can't see my arp respond from my third IP, I think it is because Firepower answers to ARP respond with his own MAC adress for the first and third IP and ISP have some one mac to one ip policy. Can we change MAC address for third IP responds? I tried to add ARP response on interface for IP MAC but it haven't help.

111.png

 

 

 

 

In screenshot you can see that firewalls and third IP mac are same from arp table of second dedicated PC 

222.png

1 Accepted Solution

Accepted Solutions

The problem was that ISP requesting ARP from different subnet and Cisco doesn't answering to different subnet, solution is to create flexconfig object "arp permit-nonconnected"

View solution in original post

1 Reply 1

The problem was that ISP requesting ARP from different subnet and Cisco doesn't answering to different subnet, solution is to create flexconfig object "arp permit-nonconnected"

Review Cisco Networking for a $25 gift card