Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Configure Check Point proxy ARP for manual NAT

From Tech-Wiki


Configure and verify Proxy ARP when using manual IPv4 NAT rules on Check Point Security Gateways.

ⓘ
Validation status
Reviewed against the current Check Point R82/R82.10 Security Management and CLI documentation on 27 September 2026.

When Proxy ARP is required

Check Point automatically handles Proxy ARP for applicable automatic NAT configurations.

For manual NAT rules, Check Point documentation states that Proxy ARP entries must be configured so that the translated IPv4 address is associated with the MAC address of the Security Gateway interface on the same network as the translated address.

!
Do not confuse Proxy ARP with a normal static ARP entry
The legacy Tech-Wiki page also showed a Gaia add arp proxy example. Current Check Point documentation describes manual-NAT Proxy ARP through the local.arp mechanism and verifies it with fw ctl arp. The ordinary Gaia add arp static command configures a normal static ARP table entry and is not a replacement for the documented manual-NAT Proxy ARP workflow.

Configure the manual Proxy ARP entry

Current Check Point CLI documentation states that configured Proxy ARP entries are based on:

$FWDIR/conf/local.arp

The exact Proxy ARP entry and cluster/scalable-platform handling should follow Check Point sk30197 for the target topology.

A traditional entry associates the translated IPv4 address with the gateway MAC address that should answer ARP requests:

>_Example local.arp entry format
192.0.2.100 00:11:22:33:44:55

Use the actual translated address and the correct gateway/cluster MAC for the relevant external network.

!
Clusters and scalable platforms require topology-aware configuration
Do not copy a member interface MAC blindly into a clustered deployment. Follow the current Check Point Proxy ARP guidance for ClusterXL, VMAC and scalable platforms.

Verify configured Proxy ARP entries

>_Display configured Proxy ARP
fw ctl arp

Use -n when hostname resolution is not required:

>_Display Proxy ARP without name resolution
fw ctl arp -n

Validate the NAT path

After the manual NAT rule and Proxy ARP configuration are in place:

  • Install the applicable Access Control/NAT policy.
  • Confirm fw ctl arp shows the intended Proxy ARP entry.
  • Confirm the upstream device can resolve the translated address to the intended gateway/cluster MAC.
  • Test the translated traffic in both directions.
  • Review NAT and firewall logs if the session still fails.

Official references

See also