4200 User Manual Edgewater Networks, Inc.
Version 3.0 34
Proxy ARP
Proxy ARP is used to create a bridge between two interfaces on the system.
Proxy ARP allows the system to respond to ARP requests for the IP address on
the interface specified. Without an ARP response, external devices would be
unable to communicate with the requested IP address.
Even though the system responds to ARP requests, it is transparent to the
external device and the system using the proxied address. Because the
system is transparent, the firewall and NAT features do not affect traffic to
and from the proxied address.
WARNING!! If an address is proxied, the system using the address
should have a firewall or it should be not be on the public network.
In addition to proxying individual addresses, a range of addresses can
be proxied by specifying a network netmask rather than a host
netmask.
⇒
Select System --
Select Proxy ARP --
Proxy ARP is used to create a
bridge between the WAN and the LAN for an IP address or network.
Addresses and networks that are bridged bypass the firewall and NAT,
allowing complete unprotected access to the systems using the addresses.
o Edit Proxy ARP List --
In addition to proxying individual addresses,
a range of addresses can be proxied by specifying a network netmask
rather than a host netmask.
o IP Address/Bitmask --
The IP address and netmask of the subnet
to be proxied e.g. 67.40.40.1/32 for this single address.
o On Interface --
On which interface of the system is the proxy
target connected. When VLAN (4300 only) is not enabled, this is
always the LAN interface. When VLAN (4300 only) is enabled, user
should choose the VLAN interface that the target is connected to.
o Gateway --
The IP address of the gateway for the proxy target. The
IP address should belong to the subnet of the target's interface that is
connected to EdgeMarc device. EdgeMarc uses this IP address as the
source IP for the ARP requests to the proxy target. This ensures that
Proxy ARP works for devices that require ARP request’s source IP
address belong to its receiving interface. Note the gateway does not
necessarily exist physically. User only needs to choose a logical IP
address that belongs to the proxy target's subnet and also does not
conflict with existing IP address.
o Respond To ARP Requests From --
The interface that the system
will use to respond to ARP requests. The interface to use is the one
that does not have access to the host system using the proxied
address. Currently this interface must be the WAN interface of the
system.