Solved

Is frequent ARPing normal?

Posted on 2004-08-11
11
411 Views
Last Modified: 2010-04-08
I have a network where clients randomly drop their internet connection behind a cisco pix 501.   Random clients randomly drop their connection for random periods of time.  I'm not sure yet if it is a switch or the firewall.   I am guessing it is the firewall..  Anyway, I am doing some arp debugging on the pix and i notice it keeps rearping the same clients.. should it be doing this?  It will arp the same clients sometimes 5-10 times in minute.. shouldnt it cache the arp and be done with it?


0
Comment
Question by:Brent92663
  • 6
  • 3
11 Comments
 

Author Comment

by:Brent92663
ID: 11774885
also i as an interesting symptom.. when the clients internet goes down, he can ping the pix.. but not telnet to it..
0
 
LVL 36

Expert Comment

by:grblades
ID: 11775530
Hi Brent92663,
Can you post the PIX configuration and I will have a look to see if there is anything wrong.
0
 

Author Comment

by:Brent92663
ID: 11775546
im not thinking there is a config problem, but maybe instead the interface is going bad..  the config has been in place for months,, and has been fine.
0
 
LVL 36

Expert Comment

by:grblades
ID: 11775659
What is in your 'global' command on the PIX?
One common problem is if you have a range of IP addresses suppled. This uses standard NAT so if you have a renge of 20 IP addresses then 20 machines can simultaneously use the internet at any time. Adding new machines or different user behavious (running MSN for example) could mean there are more than 20 machines trying to gain access.
You normally have a mixed NAT/PAT or just a PAT setup.

The PIX should cache the ARP responses but if it stops getting a response from a machine it might decide to issue another ARP.
0
 

Author Comment

by:Brent92663
ID: 11775894
just a normal old global (outside) 1

we use a global nat for all the clients, and static nats for the servers

0
Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

 
LVL 36

Expert Comment

by:grblades
ID: 11776479
You just have a single IP address listed and not a range?
0
 

Author Comment

by:Brent92663
ID: 11776710
global (outside) 1 interface

so all clients inside that do not have a static nat use the globalnat of the ip address of the external interface
0
 

Author Comment

by:Brent92663
ID: 11777803
well i found the problem.. proxyarp was enabled.. turned it off, and boom, were all good in the hood..
0
 

Author Comment

by:Brent92663
ID: 11816319
Case requested closed
0
 

Accepted Solution

by:
ee_ai_construct earned 0 total points
ID: 11934829
Closed, 500 points refunded.
ee_ai_construct (replacement part #xm34)
Community Support Moderator
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

To setup a SonicWALL for policy based routing to be used with the Websense Content Gateway there are several steps that need to be completed. Below is a rough guide for accomplishing this. One thing of note is this guide is intended to assist in the…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

24 Experts available now in Live!

Get 1:1 Help Now