cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Cyber Elite
Cyber Elite

there should not be a routing loop if you add at least 1 IP (e.g. 110.1.1.1/24) with the appropriate subnet to your public interface

from that moment forward, the firewall can proxy-arp for all ip addresses in the subnet if needed (and per the NAT configuration) and will also account for reply packets from any outbound sessions using that nat pool

 

Your NAT pool will trigger that proxy-arp so you wouldn't even need a static route on your ISP router

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
Who rated this post