Reset Search
 

 

Article

IP Destination Subnet Drop Rule Also Drops ARP

« Go Back

Information

 
TitleIP Destination Subnet Drop Rule Also Drops ARP
Symptoms
  • IP Destination Subnet drop rule also drops ARP
  • Users are unable to talk through gateway after applying IP Destination Subnet drop rule for their local subnet
  • Users are unable to ARP resolve gateway after applying L3 drop rule
Environment
  • N-Series
  • K-Series
  • S-Series
  • 7100-Series
  • All firmware
Cause
  • ARPs are dropped by IP Destination Subnet rule
  • This is Functioning As Designed
Resolution
Use either of the following workarounds:
  • Create an Allow rule for MAC Destination FF:FF:FF:FF:FF:FF
  • Modify the Ethertype traffic rule type precedence. The precedence value can be modified using the precedence option of the set policy profile command. The current precedence attribute ID order can be displayed using the show policy profile [policy #] command.
Additional notes
On the SecureStack, ARP is not dropped by the IP Destination Block rule, nor can you change the precedence.

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255