CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-11-30
Junior Member
 
Join Date: 2005-11-29
Posts: 2
Rep Power: 0
mbracale has an average reputation (10+)
Default NAT + Proxy ARP problem

I'm having a 'problem' with my FW1 NG R55 running in a Solaris 8. We have a class C network which we use about 15 IPs to do Hide NAT. They are working fine, but the fact that they use only 1 physical interface (1 MAC address) for several IPs address is causing several messages (about 100 per sec) in my syslog like this one:

ip: [ID 388441 kern.warning] WARNING: IP: Proxy ARP problem? Hardware address '<My MAC Address>' thinks it is <One of my NATed IPs>

This messages, even being just warnings, are consuming my hardware (I/O, disk, processor, etc).

This is a CheckPoint message ou a Solaris message? In the first case, is there any way that I can disable this? I've already tried to run "fw ctl debug -m fw - warning" and nothing happened.

Thanks
Reply With Quote
  #2 (permalink)  
Old 2005-11-30
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: NAT + Proxy ARP problem

It shouldn't be using proxy arp unless you are doing static nat. Make sure that you don't have any proxy arps hard coded on the firewall.

You can also try disabling the Auto Arp feature in Check Point. I have seen some weird things happen with this enabled. You can find it in Global Properties > NAT > Third checkbox from top. Uncheck that and push policy and see if you still see the same problem.
Reply With Quote
  #3 (permalink)  
Old 2005-11-30
Junior Member
 
Join Date: 2005-11-29
Posts: 2
Rep Power: 0
mbracale has an average reputation (10+)
Default Re: NAT + Proxy ARP problem

Lackie, when you say "proxy arps hard coded", you mean in a file, loaded at boot time? In this case, the answer is no!!!
About disabling the "Automatic ARP configuration"; doing this will not mess with our Static NATs?? Yes, we have both Hide and Static NATs running in this box.
Thanks again.
Reply With Quote
  #4 (permalink)  
Old 2005-11-30
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: NAT + Proxy ARP problem

I have seen some weird things happen when using the automatic arp in CheckPoint. Alot of the time it will work without a problem but then the odd time (without any cause) it will stop working or fail in some sort. At that point I tell anyone to have the Operating System do the proxy arps (Usually Nokia IPSO in my cases) and remove the automatic arp in Check Point.

As you do have static nats then removing the automatic arp without having proxy arps in place will break the static nats that you have.
Reply With Quote
  #5 (permalink)  
Old 2005-12-01
Junior Member
 
Join Date: 2005-08-19
Posts: 14
Rep Power: 0
Claer has an average reputation (10+)
Default Re: NAT + Proxy ARP problem

I have a counter example.

The problem was reproduced on SecurePlatform NG AI R55 and NGx R60.
The Linux Proxy arp feature seems to be broken in recent kernels and didn't work either on my linux workstation with kernel 2.6.13. ( OS proxy arp worked fine on NG FP3)

In order to have proxy arp working, I had to use the Checkpoint one.

Do you guys have a working configuration with proxy arp under SecurePlatform?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 13:48.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0