06-01-2024 11:47 AM
I have Cisco Firepower with FMC and 3 ISP public IP in one subnet /24. First IP is in firewalls interface, second IP in dedicated PC, third IP I want to 1 to 1 NAT to my DMZ network IP from firewall, but ISP has IP-MAC binding and he can't see my arp respond from my third IP, I think it is because Firepower answers to ARP respond with his own MAC adress for the first and third IP and ISP have some one mac to one ip policy. Can we change MAC address for third IP responds? I tried to add ARP response on interface for IP MAC but it haven't help.
In screenshot you can see that firewalls and third IP mac are same from arp table of second dedicated PC
Solved! Go to Solution.
06-01-2024 12:26 PM
The problem was that ISP requesting ARP from different subnet and Cisco doesn't answering to different subnet, solution is to create flexconfig object "arp permit-nonconnected"
06-01-2024 12:26 PM
The problem was that ISP requesting ARP from different subnet and Cisco doesn't answering to different subnet, solution is to create flexconfig object "arp permit-nonconnected"
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide