> Source: [sk103732](https://support.checkpoint.com/results/sk/sk103732)

# sk103732 - "Dropped by fwlinux_nfarpin Reason: unknown interface" messages in /var/log/messages

| Property | Value |
|----------|-------|
| Solution ID | sk103732 |
| Date Created | 2014-12-16 |
| Last Modified | 2019-07-03 |
| Technical Level | Advanced |
| Products | Security Gateway, Cloud Firewall |
| Versions | R82.10, R82, R81.20, R82.10, R81.20, R82 |

## Symptoms

- * Traffic latency in several scenarios.  

* Kernel debug (When -m fw + drop is used) shows numerous drops of the following format:  

  ```
  ...fw_log_drop: Packet proto=28 X.X.X.X:1 -> Y.Y.Y.Y:2048 dropped by fwlinux_nfarpin Reason: unknown interface;
  ...fw_log_drop: Packet proto=28 X.X.X.X:1 -> Y.Y.Y.Y:2048 dropped by fwlinux_nfarpin Reason: unknown interface;
  ```

  <br />

* The `/var/log/messages` file contains the same logs as the kernel debugs.

## Cause

This message indicates that the firewall kernel dropped an ARP packet received on an unknown interface. There are 2 possible reasons for an interface to be considered as unknown:

1. The interface is connected, has a link but is not part of the defined topology.
2. The interface is a part of the topology but for a brief period the firewall regards it as being down.

If the messages are witnessed in a very high frequency, they might indicate a ARP flood on a particular network segment. In systems where SecureXL is enabled, this drop is taking place on the SND cores. When in extremely high frequency, such events might increase the load on SecureXL.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
