> Source: [sk122696](https://support.checkpoint.com/results/sk/sk122696)

# sk122696 - Security Gateway sends ARP reply when it should not

| Property | Value |
|----------|-------|
| Solution ID | sk122696 |
| Date Created | 2018-02-12 |
| Last Modified | 2018-02-14 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * When running arping from Client to any Server behind Security Gateway/VSX, the arp reply is received both from the server MAC address and the Security Gateway/VSX MAC address.
* The command 'arp -a' does not show the entries being answered, however 'fw ctl arp' has the entries of all the servers with the issue but were not configured in $FWDIR/conf/local.arp

## Cause

Configuration mismatch. A network object is configured with automatic hide NAT to a single address. For example:

![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk122696/n11802140109.jpg)

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk122696/n21802140110.jpg)

The Security Gateway does not make a difference between subnets and singular addresses in this case and it automatically assign for the NAT 256 addresses starting from the IP address configured as the hide NAT address.

The 256 addresses are added to the proxy arp_table.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
