300-710 · Question #337
A network administrator is deploying a new Cisco Secure Firewall Threat Defense (FTD) firewall. After Cisco Secure FTD is deployed, inside clients have intermittent connectivity to each other. When…
The correct answer is B. Review NAT policy and disable incorrect proxy ARP configuration. If inside clients have intermittent connectivity issues and the Cisco Secure FTD is responding to all ARP requests on the inside network, it indicates that there may be an incorrect proxy ARP configuration in the NAT policy. Proxy ARP can cause the FTD to respond to ARP…
Question
A network administrator is deploying a new Cisco Secure Firewall Threat Defense (FTD) firewall. After Cisco Secure FTD is deployed, inside clients have intermittent connectivity to each other. When reviewing the packet capture on the Secure FTD firewall, the administrator sees that Secure FTD is responding to all the ARP requests on the inside network. Which action must the network administrator take to resolve the issue?
Options
- AReview the access policy and verify that ARP is allowed from inside to inside.
- BReview NAT policy and disable incorrect proxy ARP configuration.
- CConvert the FTD to transparent mode to allow ARP requests.
- DHardcode the MAC address of the FTD to IP mapping on client machines.
How the community answered
(32 responses)- A16% (5)
- B72% (23)
- C9% (3)
- D3% (1)
Explanation
If inside clients have intermittent connectivity issues and the Cisco Secure FTD is responding to all ARP requests on the inside network, it indicates that there may be an incorrect proxy ARP configuration in the NAT policy. Proxy ARP can cause the FTD to respond to ARP requests on behalf of other devices, leading to connectivity issues. Steps to resolve: Review the NAT policy on the FTD to identify any incorrect proxy ARP configurations. Disable the proxy ARP setting for the relevant NAT rules that are causing the issue. This ensures that the FTD only responds to ARP requests as needed, preventing it from interfering with normal ARP traffic on the inside network.
Topics
Community Discussion
No community discussion yet for this question.