> Source: [sk84480](https://support.checkpoint.com/results/sk/sk84480)

# sk84480 - Security Gateway on Gaia OS does not send ARP Replies to the directly connected network after adding a Policy-Based Route (PBR) for that network

| Property | Value |
|----------|-------|
| Solution ID | sk84480 |
| Date Created | 2012-09-11 |
| Last Modified | 2022-09-01 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81 (EOS) |
| OS | Gaia |

## Symptoms

- Security Gateway on Gaia OS does not send ARP Replies to the directly connected network after adding a Policy-Based Route (PBR) for that directly connected network.

## Cause

When ARP Filtering feature is enabled (via 'sysctl'), the Linux OS does not reply to ARP Requests if ARP Replies are supposed to be sent via interfaces other than the interface, on which ARP Requests were received.

*Example*:

1. Security Gateway has an internal interface eth**X** and an external interface eth**Y**.
2. A Policy-Based Route (PBR) rule is added, so that all traffic coming from network x.x.x.0/24 that is directly connected behind internal interface eth**X** is routed to y.y.y.0/24 behind external interface eth**Y**.
3. When a host on the directly connected network x.x.x.0/24 sends an ARP Request for Security Gateway's IP address on eth**X** interface, the Security Gateway does not send ARP Replies, because based on PBR rule, all traffic from/for that network (including ARP Replies) should be sent via eth**Y** (via interface other than the one, on which ARP Requests were received).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
