<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ARP Proxy didn't work after PanOS upgrade from 10.1.6 to 11.1.2-h3 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/arp-proxy-didn-t-work-after-panos-upgrade-from-10-1-6-to-11-1-2/m-p/595128#M118437</link>
    <description>&lt;P&gt;Short description:&amp;nbsp; We upgraded to 11.1.2-h3 on an HA pair of PA-820s last night, and the NAT/ARP Proxy that was functioning on PanOS 10.1.6 is no longer functioning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would really prefer a simple solution on 11.1.2-h3 rather than going through a 5 hour downgrade that we would still need to upgrade by the November 18th drop dead date of&amp;nbsp;Advisory:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-expirations-and-new/ta-p/572158" target="_blank"&gt;https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-expirations-and-new/ta-p/572158&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there something we can do like adding the Interface IP to the NAT rule, or setting an explicit ARP Proxy instead of just relying on PanOS to figure it out?&lt;BR /&gt;&lt;BR /&gt;One possible complication is that our interface ae1.xxxx has two IP addresses.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT face="arial black,avant garde" size="5"&gt;&lt;STRONG&gt;TL;DR:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Short Term we have a workaround by talking the Network team into temporarily adding TWELVE static ARP entries.&lt;/P&gt;
&lt;P&gt;- This used to work until last night.&lt;/P&gt;
&lt;P&gt;- The only changes we made to the firewall (PA-820) were to upgrade from 10.1.6 to 10.2.6-h3 to 11.0.4-h2 to 11.1.2-h3.&lt;/P&gt;
&lt;P&gt;- The upgrades took 5 hours (did I mention PA-820?) so I REALLY don't want to have to downgrade, especially since 10.1.6 doesn't have the Device Certificate patches, so we would need to upgrade to SOMETHING before November.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;TIA for any insight!&lt;/P&gt;
&lt;P&gt;Eric Troldahl&lt;/P&gt;
&lt;P&gt;Firewall Lead, Michigan State University.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Aug 2024 17:08:20 GMT</pubDate>
    <dc:creator>Eric_Troldahl</dc:creator>
    <dc:date>2024-08-16T17:08:20Z</dc:date>
    <item>
      <title>ARP Proxy didn't work after PanOS upgrade from 10.1.6 to 11.1.2-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-proxy-didn-t-work-after-panos-upgrade-from-10-1-6-to-11-1-2/m-p/595128#M118437</link>
      <description>&lt;P&gt;Short description:&amp;nbsp; We upgraded to 11.1.2-h3 on an HA pair of PA-820s last night, and the NAT/ARP Proxy that was functioning on PanOS 10.1.6 is no longer functioning.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We would really prefer a simple solution on 11.1.2-h3 rather than going through a 5 hour downgrade that we would still need to upgrade by the November 18th drop dead date of&amp;nbsp;Advisory:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-expirations-and-new/ta-p/572158" target="_blank"&gt;https://live.paloaltonetworks.com/t5/customer-advisories/update-to-additional-pan-os-certificate-expirations-and-new/ta-p/572158&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there something we can do like adding the Interface IP to the NAT rule, or setting an explicit ARP Proxy instead of just relying on PanOS to figure it out?&lt;BR /&gt;&lt;BR /&gt;One possible complication is that our interface ae1.xxxx has two IP addresses.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;FONT face="arial black,avant garde" size="5"&gt;&lt;STRONG&gt;TL;DR:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Short Term we have a workaround by talking the Network team into temporarily adding TWELVE static ARP entries.&lt;/P&gt;
&lt;P&gt;- This used to work until last night.&lt;/P&gt;
&lt;P&gt;- The only changes we made to the firewall (PA-820) were to upgrade from 10.1.6 to 10.2.6-h3 to 11.0.4-h2 to 11.1.2-h3.&lt;/P&gt;
&lt;P&gt;- The upgrades took 5 hours (did I mention PA-820?) so I REALLY don't want to have to downgrade, especially since 10.1.6 doesn't have the Device Certificate patches, so we would need to upgrade to SOMETHING before November.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;TIA for any insight!&lt;/P&gt;
&lt;P&gt;Eric Troldahl&lt;/P&gt;
&lt;P&gt;Firewall Lead, Michigan State University.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 17:08:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-proxy-didn-t-work-after-panos-upgrade-from-10-1-6-to-11-1-2/m-p/595128#M118437</guid>
      <dc:creator>Eric_Troldahl</dc:creator>
      <dc:date>2024-08-16T17:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: ARP Proxy didn't work after PanOS upgrade from 10.1.6 to 11.1.2-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-proxy-didn-t-work-after-panos-upgrade-from-10-1-6-to-11-1-2/m-p/595286#M118464</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227268"&gt;@Eric_Troldahl&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Have you reviewed &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGZCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGZCA0&lt;/A&gt; and attempted any of the standard fixes to this issue? Since you don't detail how your NAT policies were configured previously or if you have the secondary addresses on the interfaces directly it's a bit difficult to troubleshoot what could have possibly changed in your upgrade.&lt;/P&gt;
&lt;P&gt;I personally just prefer to make routes whenever possible instead of configuring the address on the interface as a secondary address, but that also works perfectly fine. Just gets a bit tedious if working with a lot of addresses.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 22:08:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-proxy-didn-t-work-after-panos-upgrade-from-10-1-6-to-11-1-2/m-p/595286#M118464</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-08-19T22:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: ARP Proxy didn't work after PanOS upgrade from 10.1.6 to 11.1.2-h3</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-proxy-didn-t-work-after-panos-upgrade-from-10-1-6-to-11-1-2/m-p/595631#M118522</link>
      <description>&lt;P&gt;The range defined for NAT was directly attached to an interface.&amp;nbsp; It turns out that the object that was used to define the interface IP on one of the two subnets on the VLAN had a /32 mask, so none of the other IPs on that Subnet were getting ARP resolution.&amp;nbsp; We currently changed to a hardcoded IP/mask (that can cause a "Ghost"), but we are discussing an architecture naming convention change that would require separate objects for Interface addresses, using a name like "vlan3100-subnet-192-168-1-0-interface" so no one would use it except in a context that needs to change if the IP or VLAN changes.&amp;nbsp; &lt;BR /&gt;&lt;BR /&gt;NOTE:&amp;nbsp; We have a very large network with not just RFC1918 private IPs, but also a public /13 range, and some of the RFC 1918 addresses need to NAT to the public range even within the campus to be allowed to route from Server and DMZ zones out to VPN tunnels, local Untrust zones, and even Internet Untrust ranges.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Aug 2024 14:53:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-proxy-didn-t-work-after-panos-upgrade-from-10-1-6-to-11-1-2/m-p/595631#M118522</guid>
      <dc:creator>Eric_Troldahl</dc:creator>
      <dc:date>2024-08-22T14:53:30Z</dc:date>
    </item>
  </channel>
</rss>

