When to enable / disable proxy-arp

Cooky

Golden Member
Apr 2, 2002
1,408
0
76
So the definition I've seen is basically the router would answer the arp requests on behalf of a remote host on different subnet.

Exactly what are the pros & cons if you have it enabled?
I'm told it's better to have it disabled due to security & performance...is that true?
When would you want to have it enabled?
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
There's no need in this day and age to have it enabled. It is a security risk.

It was used for hosts that didn't understand the concept of a default gateway. Not needed these days.
 

p0lar

Senior member
Nov 16, 2002
634
0
76
Originally posted by: Cooky
So the definition I've seen is basically the router would answer the arp requests on behalf of a remote host on different subnet.

Exactly what are the pros & cons if you have it enabled?
I'm told it's better to have it disabled due to security & performance...is that true?
When would you want to have it enabled?

+1 disable in all circumstances unless you have an explicit need and no other options. My last such occurrence was earlier this year for an ethernet-managed PRI->GSM channel bank manufactured by 2N (Ateus Stargate) that relied on proxy-arp to be accessible. Such occurrences are rare.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Then there's the story of a linksys router taking down a data center because of proxy arp.
 

p0lar

Senior member
Nov 16, 2002
634
0
76
Originally posted by: spidey07
Then there's the story of a linksys router taking down a data center because of proxy arp.

Ugh.. <shudder>

Heads would ROLL..
 

Cooky

Golden Member
Apr 2, 2002
1,408
0
76
Why does Cisco have proxy-arp enabled by default on their routers, if it's not desirable to have it on?
 

cmetz

Platinum Member
Nov 13, 2001
2,296
0
0
Many things in cisco land are done that way because that's always they way they did it, and they don't want to confuse you by changing the defaults. They have done just that a few times, though, when there's a security reason and not much downside to changing. But there are enough brain-damaged networks that depend on proxy ARP without really knowing it that they can't flip this default easily.

Proxy ARP is evil and should be disabled unless you know exactly what you're doing.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Originally posted by: Cooky
Why does Cisco have proxy-arp enabled by default on their routers, if it's not desirable to have it on?

It's still a standard AFAIK.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |