Cisco ASA allowed Arp alias , can Paloalto do arp alias?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Cisco ASA allowed Arp alias , can Paloalto do arp alias?

L1 Bithead

HI ,

 

I need my Palo Alto to respond to ARP requests as if it were the owner of both the specified IP address and hardware address.

 

My ASA was able to do it, can't figure out how to do it with Palo Alto.

 

Thanks

Marianne 

 

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Destination NAT rules make Palo to perform Proxy ARP.

A bit clumsy solution but following would work.

 

Let's assume that Palo interface IP is 10.0.0.1 but you want it to reply also on 10.0.0.2

Set up DNAT rule to translate .2 to .1

In this case Palo will start replying to ARP requests looking for .2

 

If you also add random service that won't be used (udp/123 in my case) then you can avoid Palo actually performing NAT for this traffic.

 

Raido_Rattameister_5-1695833886519.png

 

 

 

You can also add multiple IP addresses on Palo interface.

 

Assuming interface IP is 10.0.0.1/24 you can add 10.0.0.2/32 as secondary IP.

 

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

Destination NAT rules make Palo to perform Proxy ARP.

A bit clumsy solution but following would work.

 

Let's assume that Palo interface IP is 10.0.0.1 but you want it to reply also on 10.0.0.2

Set up DNAT rule to translate .2 to .1

In this case Palo will start replying to ARP requests looking for .2

 

If you also add random service that won't be used (udp/123 in my case) then you can avoid Palo actually performing NAT for this traffic.

 

Raido_Rattameister_5-1695833886519.png

 

 

 

You can also add multiple IP addresses on Palo interface.

 

Assuming interface IP is 10.0.0.1/24 you can add 10.0.0.2/32 as secondary IP.

 

 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

L1 Bithead

thanks a million for the answer 

  • 1 accepted solution
  • 1176 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!