Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Arp response from wrong PIX


I have 2 PIX firewalls on the same LAN, 1 is used for Internet access only.

The other is used to terminate several VPN tunnels.

I've an FTP server on the DMZ LAN, and have static routes on the server to point to the remote LANs across the VPN tunnels, I’ve also a default route via the Internet PIX

However, when the FTP server sends an ARP request to the VPN PIX DMZ IP address to discover its MAC address, the Internet PIX responds instead with, I assume a proxy arp.

I've added a static arp to the FTP server to get around question is..

If the ARP request from the FTP server contained the VPN PIX's IP address and the Internet PIX responds as well, is this normal?

Any help appreciated

Regards Tony

New Member

Re: Arp response from wrong PIX

I don't fully understand your topology; however, ARP's are only for a local LAN segment. So, if the VPN PIX is not connected to the same DMZ segment that the FTP server is on, the FTP server will ARP for its default gateway.

Proxy ARP is usually only a factor if there are inconsistent subnet masks applied. Fo example, if the DMZ network was and the LAN was and the FTP server were configured with a subnet mask of, then it would try to ARP for 172.16.2.X, since it believes that this is local. A device supporting proxy ARP would answer for it instead of having the connection fail.

Since the FTP server is on the DMZ, there must be some sort of static mapping to get back into the inside. The PIX will also answer these ARPs.

Hope this helps.


New Member

Re: Arp response from wrong PIX

Hello Mike,

I appreciate your response and I'll certainly look at the masks on those deivces.

The PIXs are effectively in parallel, with the inside, dmz and outside interfaces all connected to their respective LANs.

Cheers Tony

New Member

Re: Arp response from wrong PIX


Check the forum entry before yours, titled "lost connectivity in dmz (pix) and arp answer". This covers the solution to your problem.

PIX's have proxyarp enabled by default. This can be disabled by using 'sysopt noproxyarp interface_name'.


New Member

Re: Arp response from wrong PIX

Hi Glen,

Thanks for the response but I'm told by the 3rd party administoring this PIX that it needs to have proxy arp enabled as it acts as a gateway to the Internet.

I'm not 100% sure this is correct though

Cheers Tony

CreatePlease to create content