- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-22-2017 11:47 PM
Hello,
08-23-2017 02:19 AM
the firewall needs to determine to which interface the IP address belongs for it to be able to send out proxy arp (else it could flood out all interfaces). therefore you should add the subnet to the external interface (or use individual loopbacks)
if you don't want to add the subnet or use loopbacks, you can create static ARP entries on the upstream router that point to your firewall interface for the desired IPs also
08-23-2017 02:03 AM
Is the public IP address you used in the translation part of the subnet that's configured on the WAN interface ?
If you add the subnet to the external interface, this will simplify proxy-arp broadcasts. Else, a loopback interface in the wan zone will do the trick
08-23-2017 02:15 AM
Hi Reaper,
No, the public IP address is not part of the WAN interface subnet. We have already added the loopback in the WAN zone and it works. Ques is: is there a solution wherein the NATing works without adding loopback or is it that loopbacks are mandatory for NATing?
08-23-2017 02:19 AM
the firewall needs to determine to which interface the IP address belongs for it to be able to send out proxy arp (else it could flood out all interfaces). therefore you should add the subnet to the external interface (or use individual loopbacks)
if you don't want to add the subnet or use loopbacks, you can create static ARP entries on the upstream router that point to your firewall interface for the desired IPs also
08-23-2017 02:24 AM
I just feel expertise in your responses @reaper
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!