Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sota
New Contributor

Proxy ARP Necessary?

Hello, 

We recently updated our FortiOS from 6.2.3 to 7.0.1.

 

6.2.3: Proxy-ARP was "disabled", but SSL-VPN worked.  VPN clients and servers could connect to each other.

7.0.1: Proxy-ARP needs to be "enabled".  Otherwise, the SSL-VPN connection doesn't work.

 

7.0.1: Proxy-ARP "enabled" & NAT "enabled" = Ping OK.

7.0.1: Proxy-ARP "enabled" & NAT "disabled" = Ping doesn't work.

 

Does anyone know if there are any system changes for Proxy-ARP between 6.2.3 and 7.0.1?

I'd like to know what are the correct behavior and settings, and why these changes appear between 6.2.3 and 7.0.1.

 

Thank you very much!!

 

Sota

2 REPLIES 2
Kangming
Staff
Staff

Hi

 

Could you post your configuration?

Thanks

Kangming

Sota
New Contributor

Hello, thank you for the reply!

 

Previous Version: 6.2.3 build1066

Current Version: 7.0.1 build0157

-----------------------------------------

config system proxy-arp edit 1 set interface "internal1" set ip 10.24.56.2 set end-ip 10.24.56.254 next end

-----------------------------------------

VPN Client: 10.24.56.2 - 254

FortiGate Internal1: 10.24.0.41

Office Network: 10.24.0.0/16

Servers: 10.24.0.XXX

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors