Configure Check Point proxy ARP for manual NAT
More actions
Configure and verify Proxy ARP when using manual IPv4 NAT rules on Check Point Security Gateways.
When Proxy ARP is required
Check Point automatically handles Proxy ARP for applicable automatic NAT configurations.
For manual NAT rules, Check Point documentation states that Proxy ARP entries must be configured so that the translated IPv4 address is associated with the MAC address of the Security Gateway interface on the same network as the translated address.
add arp proxy example. Current Check Point documentation describes manual-NAT Proxy ARP through the local.arp mechanism and verifies it with fw ctl arp. The ordinary Gaia add arp static command configures a normal static ARP table entry and is not a replacement for the documented manual-NAT Proxy ARP workflow.Configure the manual Proxy ARP entry
Current Check Point CLI documentation states that configured Proxy ARP entries are based on:
$FWDIR/conf/local.arp
The exact Proxy ARP entry and cluster/scalable-platform handling should follow Check Point sk30197 for the target topology.
A traditional entry associates the translated IPv4 address with the gateway MAC address that should answer ARP requests:
192.0.2.100 00:11:22:33:44:55
Use the actual translated address and the correct gateway/cluster MAC for the relevant external network.
Verify configured Proxy ARP entries
fw ctl arp
Use -n when hostname resolution is not required:
fw ctl arp -n
Validate the NAT path
After the manual NAT rule and Proxy ARP configuration are in place:
- Install the applicable Access Control/NAT policy.
- Confirm
fw ctl arpshows the intended Proxy ARP entry. - Confirm the upstream device can resolve the translated address to the intended gateway/cluster MAC.
- Test the translated traffic in both directions.
- Review NAT and firewall logs if the session still fails.