Mark,

The router will ARP for the IP address of the firewall only when it
needs to route something to it. It is possible that the Windows box is
doing something that triggers this while the SPLAT box does not. That is
why I suggested routing some traffic from the firewall (or behind it)
through the router, so that the return traffic will cause the router to
ARP for the firewall's IP. Depending on the router, you may even be able
to trigger a manual ARP request.

Connecting the firewall will, by itself, not cause the router to update
its ARP table.

Utsav

Sheffield wrote:

Utsav -

Thanks for your reply. Since the router configuration works with my FP3
firewall, I assumed it would work with a splat R55 firewall without making
any router configuration changes.

When I connect the NG FP3 (Windows 2000) firewall to the router, ARP happens
on both devices almost immediately. The R55 splat firewall has the same IP
address as the FP3 firewall. When I remove the FP3 firewall, clear the
router ARP cache, and connect the R55 splat firewall to the router, ARP
updates only happen on the firewall.

Is there something about splat and/or R55 that would cause ARP updates not
to happen on the router, even though windows 2000 FP3 ARP updates work?

-mark

-----Original Message-----
From: Utsav Ratti [mailto:[EMAIL PROTECTED]
Sent: Monday, July 12, 2004 4:48 PM
To: [EMAIL PROTECTED]
Subject: Re: [FW-1] Splat R55 not updating router arp table

Mark,

You haven't elucidated all the details, so I will assume that the router
has an interface in the same broadcast domain as that of the external
interface of the firewall.

The router will ARP for the IP address associated with that interface
the first time it tries to route traffic to it.

The reason the SPLAT box has got an entry right after bootup is because
the router is probably defined as that interface's default gateway, so
the SPLAT box will ARP for it on bootup assuming that the IP associated
with that router's interface is defined correctly.

Send some traffic from the firewall through the router. If there is no
response, make sure that the router doesn't have another interface in
another network that offers a preferred path back to the source network
of your original traffic and that there are no ACLs on the router that
may be dropping the return traffic. Other possibilities exist, but I
know too little about your setup so there's no point to go into all of
them here.

Utsav



Sheffield wrote:


I am attempting to move a splat R55 (intel) box from our test lab into
production to replace a windows 2000 FP3 box. In the past the normal
procedure has been to clear the arp cache on the router and boot the
firewall. Very shortly after booting the FP3 box, the router arp cache
contains a complete entry for the firewall external interface.

However, with the splat r55 box, the router arp cache never gets updated
with a complete entry for the external interface of the router. The arp
cache on the splat box does get updated with a complete entry for the

router

NIC, though.

What needs to be done to allow the router arp table to get updated with a
complete entry for the external interface of a splat r55 firewall?

Thanks in advance for your assistance.

-mark

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================



=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================


================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================

Reply via email to