Skip to main content
epinheiro
Staff
Staff
June 2, 2026

Technical Tip: Proxy-ARP configuration stops working after reboot if the address group is greater than 256

  • June 2, 2026
  • 0 replies
  • 162 views

Description


This article describes a condition where a FortiGate device configured with a proxy-ARP IP range exceeding 256 entries fails to respond to incoming ARP requests following a system reboot.


Scope


FortiGate, Proxy-ARP.


Solution


Older FortiOS versions limited proxy-ARP configurations to a maximum of 256 IP addresses. While in newer versions, larger subnets are supported (like a /23 or /22), these larger ranges do not load properly after the firewall restarts.


However, the system's bootup sequence was not updated to support the extended size limit. Consequently, the firewall fails to load the enlarged proxy-ARP configuration into memory during system initialization, causing the device to silently ignore ARP requests for the affected IP range after a restart.


To workaround this behavior without applying a firmware upgrade, segment the large subnet into multiple, discrete proxy-ARP entries. Ensure that no individual entry exceeds a /24 allocation (maximum of 256 IP addresses).


Note: This behavior is tracked under known issue #1193085. The underlying issue has been resolved in the upcoming FortiOS v7.4.13 release and will be officially addressed in subsequent FortiOS v7.6.x and v8.0.x firmware branches.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!