> Source: [sk92996](https://support.checkpoint.com/results/sk/sk92996)

# sk92996 - '...dropped by fwha_select_arp_packet Reason: arp src is from local' drops in kernel debug

| Property | Value |
|----------|-------|
| Solution ID | sk92996 |
| Date Created | 2013-06-06 |
| Last Modified | 2025-01-15 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * Kernel debug (`fw ctl debug -m fw + drop`) shows the following drops:   

  '`fw_log_drop: Packet proto= ... dropped by fwha_select_arp_packet Reason: arp src is from local`'   

* If also cluster debug (`fw ctl debug -m cluster + select`) is enabled, then the following lines appear before the drop log:   

  `FW-1: fwha_select_arp_packet: Arp packet for ip `*IP_ADDRESS*  
  `FW-1: fwha_select_arp_packet: drop ARP packet from ip 0x`*IP_ADDRESS* `, arp `*MAC_ADDRESS*

## Cause

The Sender IP address of the received ARP packet belongs to this cluster member.

Cluster code prevents a situation, in which the Check Point kernel picks broadcast ARP Requests that are arriving from the local machine itself, and forwards them to the operating system, which sees ARP packets from the machine to itself and gets confused.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
