Static ARP entry

Answered Question
Nov 27th, 2007
User Badges:

Hey all,


A customer has a network that looks like the attached diagram.


Their Sidewinder firewalls are set up in active-active mode for load-balancing and redundancy. On the Inside router's config, I noticed this line:


arp 10.52.0.4 00XX.b3XX.bcXX ARPA


Where 10.52.0.4 is the Virtual IP of the firewall cluster, and 00XX.b3XX.bcXX is the MAC address of the firewalls virtual adapter.


Can anyone tell me why that command is there, how does it help, or what does it do?


Thanks,

SM



Attachment: 
Correct Answer by Edison Ortiz about 9 years 5 months ago

Perhaps they had an issue where the Sidewinder FWs weren't advertising the MAC addresses correctly or it wasn't populating in the router's arp table.


This process is done dynamically and seldom is done statically in routers.


I've seen it more often implemented in switches for security purposes but it doesn't scale very well for large amount of host devices.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Correct Answer
Edison Ortiz Tue, 11/27/2007 - 11:29
User Badges:
  • Super Bronze, 10000 points or more
  • Hall of Fame,

    Founding Member

Perhaps they had an issue where the Sidewinder FWs weren't advertising the MAC addresses correctly or it wasn't populating in the router's arp table.


This process is done dynamically and seldom is done statically in routers.


I've seen it more often implemented in switches for security purposes but it doesn't scale very well for large amount of host devices.

Actions

This Discussion