<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ARP table cache &amp;quot;incomplete&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128668#M46714</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks! l cannot understand how then it is working:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ARP.PNG" style="width: 551px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6484iD43DABF4DECBF520/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ARP.PNG" alt="ARP.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;Let's say on .77 IP we got web server hosted on premise where 1x1 NAT is configured for outside host when they hitting .77&lt;/P&gt;&lt;P&gt;So essentially for half of these IPs&amp;nbsp;1x1 NAT is in place .126 is a default gateway&amp;nbsp;where .122 is a test PC.&lt;/P&gt;&lt;P&gt;Another&amp;nbsp;thing when l send a gratuitous&amp;nbsp;ARP how the Palo decides to which host to send. Why l don't&amp;nbsp;see other IP, as we got /26 for outside? Palo must know that these are alive&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Nov 2016 08:09:42 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2016-11-24T08:09:42Z</dc:date>
    <item>
      <title>ARP table cache "incomplete"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128411#M46693</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need some clarification on ARP table. For some reason, once we swapped the devices from 2020&amp;gt;3020 &amp;nbsp;our ARP table is seen as incomplete but services are working fine withing on that particular external subnet (before they did but we use gratuitous arp) . Also the time out of the "incomplete" entries pretty&amp;nbsp;much a second (&amp;nbsp;ttl&amp;nbsp;=1):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ARP entries_hidden.PNG" style="width: 595px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6473i975FDDA12AA5FE6C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ARP entries_hidden.PNG" alt="ARP entries_hidden.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2016 18:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128411#M46693</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-23T18:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table cache "incomplete"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128646#M46710</link>
      <description>&lt;P&gt;Incomplete means that PA didn't get ARP reply to his ARP query.&lt;/P&gt;&lt;P&gt;Or in other words there are no devices with those IPs in the network configured on this interface.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 07:21:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128646#M46710</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-11-24T07:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table cache "incomplete"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128668#M46714</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks! l cannot understand how then it is working:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ARP.PNG" style="width: 551px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/6484iD43DABF4DECBF520/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="ARP.PNG" alt="ARP.PNG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;Let's say on .77 IP we got web server hosted on premise where 1x1 NAT is configured for outside host when they hitting .77&lt;/P&gt;&lt;P&gt;So essentially for half of these IPs&amp;nbsp;1x1 NAT is in place .126 is a default gateway&amp;nbsp;where .122 is a test PC.&lt;/P&gt;&lt;P&gt;Another&amp;nbsp;thing when l send a gratuitous&amp;nbsp;ARP how the Palo decides to which host to send. Why l don't&amp;nbsp;see other IP, as we got /26 for outside? Palo must know that these are alive&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 08:09:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128668#M46714</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-24T08:09:42Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table cache "incomplete"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128671#M46715</link>
      <description>&lt;P&gt;Ahh, those are IPs used for DNAT on PA?&lt;/P&gt;&lt;P&gt;PA doesn't need those in its table. But he replies to other devices with its MAC address for them. So if you look ARP tables on surrounding devices you will see entries for those IPs with PA mac address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why are they in the PA table and displayed as incomplete I don't know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 08:23:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128671#M46715</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-11-24T08:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: ARP table cache "incomplete"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128720#M46719</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the very good point! So if the DNAT configured for the&amp;nbsp;86.xx.xx.72,&amp;nbsp;&lt;SPAN&gt;86.xx.xx.77 etc PA will reply for the&amp;nbsp;ARP request.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That is why when we changed a PA to the new one, old ARP cache ( old&amp;nbsp;PA MAC address) still was present &amp;nbsp;in ARP table of external DG withing the same subnet, hence no services we available as DG had wrong MAC for these IPs. Will confirm ARP table on the&amp;nbsp;test PC and let you know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Myky&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Nov 2016 17:17:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/arp-table-cache-quot-incomplete-quot/m-p/128720#M46719</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-11-24T17:17:57Z</dc:date>
    </item>
  </channel>
</rss>

