CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-13
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 582
Rep Power: 10
BarryStiefel has disabled reputation
Default local.arp Only Works with NAT

local.arp Only Works with NAT



Others have noticed that the proxy ARP mechanism in FireWall-1 on Windows using the local.arp file only works when there is at least one network address translation rule. If there are no NAT rules, then no proxy ARPs are issued. This is normally not a problem because proxy ARP is typically used together with NAT in order to allow the firewall to "capture" packets sent to the "virtual addresses". However, if you ever try to use proxy ARP for other reasons (like transparent routing) and you don't have any NAT rules, then you'll have problems.

The best way to do proxy arps on NT is with an external device, not relying on local.arp.

-- PhoneBoy - 11 Jan 2004

FAQForm FAQs.Class: FAQs.OS: OsWindows FAQs.Version:
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 12:41.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0