<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GW ARP reply.. in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/gw-arp-reply/m-p/1220672#M5553</link>
    <description>&lt;DIV class="slds-form-element__control slds-scrollable_y"&gt;
&lt;DIV class="slds-form-element__control"&gt;From the tcpdump output, the device with the MAC address b4:0c:25:e0:40:10(FW being the GW) is repeatedly broadcasting ARP requests, asking for the MAC addresses of multiple IPs within the 10.248.8.x range. It is sending these requests to identify the MAC addresses of devices associated with those IP addresses. This is resulting connectivity issues in the network. FW is managed by panorama. one host which has IP 10.248.15.226 is getting ARP resolved by the GW mac. and this IP is not pinging.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;fr2-oob-106-sw01...12:10:36:(vrf:MGMT)#sh ip arp&lt;BR /&gt;Address Age (sec) Hardware Addr Interface&lt;BR /&gt;10.248.8.1 0:00:00 b40c.25e0.4010 Vlan2008, Port-Channel106&lt;BR /&gt;10.248.8.200 0:00:00 000c.29be.2221 Vlan2008, Port-Channel106&lt;BR /&gt;10.248.8.254 0:00:00 5254.0070.1722 Vlan2008, Port-Channel106&lt;BR /&gt;10.248.15.57 0:23:53 000c.29ac.6fe8 Vlan2008, Port-Channel106&lt;BR /&gt;10.248.15.58 0:05:22 000c.291f.727d Vlan2008, Port-Channel106&lt;BR /&gt;10.248.15.226 0:06:37 b40c.25e0.4010 Vlan2008, Port-Channel106&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;12:40:20.465309 00:0c:29:1f:72:7d &amp;gt; 2c:dd:e9:57:9d:d8, ethertype ARP (0x0806), length 60: Request who-has 10.248.8.20 tell 10.248.15.58, length 46&lt;BR /&gt;12:40:21.802244 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.15.57 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:23.802144 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.10.86 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:28.801900 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.9.238 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:28.801954 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.9.26 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:28.801975 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.15.18 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:28.801995 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.10.21 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:28.802019 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.10.11 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:29.169272 00:0c:29:1f:72:7d &amp;gt; 2c:dd:e9:57:8d:e0, ethertype ARP (0x0806), length 60: Request who-has 10.248.8.19 tell 10.248.15.58, length 46&lt;BR /&gt;12:40:29.226796 2c:dd:e9:57:9d:d8 &amp;gt; 00:0c:29:3c:51:b6, ethertype ARP (0x0806), length 60: Request who-has 10.248.15.61 (00:0c:29:3c:51:b6) tell 10.248.8.20,&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 17 Feb 2025 15:46:58 GMT</pubDate>
    <dc:creator>R.Lingwal</dc:creator>
    <dc:date>2025-02-17T15:46:58Z</dc:date>
    <item>
      <title>GW ARP reply..</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/gw-arp-reply/m-p/1220672#M5553</link>
      <description>&lt;DIV class="slds-form-element__control slds-scrollable_y"&gt;
&lt;DIV class="slds-form-element__control"&gt;From the tcpdump output, the device with the MAC address b4:0c:25:e0:40:10(FW being the GW) is repeatedly broadcasting ARP requests, asking for the MAC addresses of multiple IPs within the 10.248.8.x range. It is sending these requests to identify the MAC addresses of devices associated with those IP addresses. This is resulting connectivity issues in the network. FW is managed by panorama. one host which has IP 10.248.15.226 is getting ARP resolved by the GW mac. and this IP is not pinging.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;fr2-oob-106-sw01...12:10:36:(vrf:MGMT)#sh ip arp&lt;BR /&gt;Address Age (sec) Hardware Addr Interface&lt;BR /&gt;10.248.8.1 0:00:00 b40c.25e0.4010 Vlan2008, Port-Channel106&lt;BR /&gt;10.248.8.200 0:00:00 000c.29be.2221 Vlan2008, Port-Channel106&lt;BR /&gt;10.248.8.254 0:00:00 5254.0070.1722 Vlan2008, Port-Channel106&lt;BR /&gt;10.248.15.57 0:23:53 000c.29ac.6fe8 Vlan2008, Port-Channel106&lt;BR /&gt;10.248.15.58 0:05:22 000c.291f.727d Vlan2008, Port-Channel106&lt;BR /&gt;10.248.15.226 0:06:37 b40c.25e0.4010 Vlan2008, Port-Channel106&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;12:40:20.465309 00:0c:29:1f:72:7d &amp;gt; 2c:dd:e9:57:9d:d8, ethertype ARP (0x0806), length 60: Request who-has 10.248.8.20 tell 10.248.15.58, length 46&lt;BR /&gt;12:40:21.802244 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.15.57 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:23.802144 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.10.86 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:28.801900 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.9.238 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:28.801954 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.9.26 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:28.801975 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.15.18 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:28.801995 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.10.21 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:28.802019 b4:0c:25:e0:40:10 &amp;gt; Broadcast, ethertype ARP (0x0806), length 56: Request who-has 10.248.10.11 (Broadcast) tell 10.248.8.1, length 42&lt;BR /&gt;12:40:29.169272 00:0c:29:1f:72:7d &amp;gt; 2c:dd:e9:57:8d:e0, ethertype ARP (0x0806), length 60: Request who-has 10.248.8.19 tell 10.248.15.58, length 46&lt;BR /&gt;12:40:29.226796 2c:dd:e9:57:9d:d8 &amp;gt; 00:0c:29:3c:51:b6, ethertype ARP (0x0806), length 60: Request who-has 10.248.15.61 (00:0c:29:3c:51:b6) tell 10.248.8.20,&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 17 Feb 2025 15:46:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/gw-arp-reply/m-p/1220672#M5553</guid>
      <dc:creator>R.Lingwal</dc:creator>
      <dc:date>2025-02-17T15:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: GW ARP reply..</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/gw-arp-reply/m-p/1221058#M5563</link>
      <description>&lt;P&gt;Hi &lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/969002133"&gt;@R.Lingwal&lt;/a&gt;&lt;/SPAN&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you still experiencing issues?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Compare the output of "show arp all | match 10.248.15.226" on the Palo with where your switch has 10.248.15.226 mapped to. What does it look like? Are multiple devices showing up?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you tried clearing the arp cache on the palo and switch?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 01:57:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/gw-arp-reply/m-p/1221058#M5563</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-02-20T01:57:35Z</dc:date>
    </item>
  </channel>
</rss>

