Can this ARPing be stopped?

PeterUK
PeterUK Posts: 3,799  Guru Member
100 Answers 2500 Comments Friend Collector Seventh Anniversary
edited April 7 in USG FLEX H Series

With FLEX H it tries to ARP on a WAN interface outside the given IP WAN it should not be needed to be done and my ISP does ignore them but best not to have them sent out also ARP broadcast when doing ping check ever 5 seconds plus more if you do another ping check rule in routing it would be best to only do a ARP broadcast when ping does not get a reply.

Note Cisco MAC is my ISP and GigaByteTech is my MAC set in FLEX H

Is their a SSH command that can stop this please thanks

Screenshot 2025-03-10 165148.png Screenshot 2025-04-07 012642.png

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,277  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @PeterUK,

    Our engineer wants to check this symptom via CLI. Could you allow SSH for the remote access policy rule so we can use the domain you have provided to access? Thanks!

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 3,799  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited April 22

    So did see why this is a problem? it also happen on the FLEX 200 non H the more routing rules you have like this.

    Screenshot 2025-04-22 152834.png

    The worse and more ARP happens

    My take on ARP is on finding IP within the subnet that has not been looked up is of course broadcast ARP then from then on every 30-60 seconds random do a unicast ARP and if that fails back to broadcast ARP then with Zyxel doing ping checks it uses that stored ARP for the gateway or IP in subnet to send ping but if ping fails on timeout then do broadcast ARP for the gateway or IP in subnet.

  • PeterUK
    PeterUK Posts: 3,799  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    So is this still being looked into?

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,277  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @PeterUK,

    Yes, we are still checking. I'm sorry for the delayed update.

    In the meantime, may I check with you if this issue still occurs in V1.32 firmware? Because I tried adding policy routes in my lab and monitoring for 20 minutes, I didn't see the strange ARP packet as you marked in the post. Could you also help to confirm if this issue happens at any time? If so, I will ask our engineer to check this issue directly.

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 3,799  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary
    edited May 26

    yes happen with  V1.32 firmware

    So  policy routes if doing it every 5 seconds for ping check period will cause ARP every 5 seconds

    as for the other ARP I think you need to setup DDNS

  • Zyxel_Melen
    Zyxel_Melen Posts: 3,277  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @PeterUK,

    Our engineer has checked this issue. Since the IP addresses are from Zyxel services, they tried to connect related domain from your USG FLEX 200HP, but query was failed. Based on your network structure, could you help to allow specific domains on the uplink device? We assume this issue is because the service was blocked and cause the firewall tried to find the related IP addresses.

    I will send the domain list to you via private message.

    Zyxel Melen


  • PeterUK
    PeterUK Posts: 3,799  Guru Member
    100 Answers 2500 Comments Friend Collector Seventh Anniversary

    Its seem the DNS cache on FLEX H failed in some way and had to do a

    cmd dns proxy clear-cache

    which is another issue as to why that happened but still ARP to IP's outside the subnet still happens for Zyxel services which is not needed because it should use the gateway