CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-29
Junior Member
 
Join Date: 2006-05-23
Posts: 9
Rep Power: 0
infrared013 has an average reputation (10+)
Default machine ARPs for itself

DOes anyone know what it means when a device ARPs for itself? WHen I run a tcpdump on a particular connection it is just nothing but lines and lines and lines of this machine arping for itself.

Im not sure if this one is something that can be answered as it is or if more info is needed. Just happened to think about it tonight at home and thought I would throw it out there, I can provide more info such as exact output from the tcpdump and what not if it might help get me somewhere. This partcular connection is a site to site encrypted tunnel where we are also using NAT (to complicate things further). The connection originates from a non-routable address destined for the remote end, is NAT'ed to a public IP and on the other end the same thing and also vice versa. I see the public IP come in and be accepted by the FW but it is when I do the tcpdump on the private IP of the receiving machine to see if the NAT is working properly that I noticed this.

If this makes any sense at all and I havnt gone rabling on aimlessly I would appreciate any of your expert analysis! Sometimes I enjoy asking the folks on here my questions rather than my own co-workers! for multiple reasons!
Reply With Quote
  #2 (permalink)  
Old 2007-10-30
Junior Member
 
Join Date: 2007-08-29
Posts: 15
Rep Power: 0
laril has an average reputation (10+)
Default Re: machine ARPs for itself

This is a feature called gratuitous arp. Not sure about your special situation, but CheckPoint utilizes this at least with clustering.

For more information see e.g.

Gratuitous ARP - The Ethereal Wiki

-laril-
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:58.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0