Proxy ARP option on USG to work like L3 switch






This was tested on my VPN300 but likely holds true for current models
The following setup works on my XS1930-10
XS1930-10 interface IP 192.168.255.233 / 255.255.255.192
Two clients
IP 192.168.255.193
subnet 255.255.255.255
gateway 192.168.255.233
IP 192.168.255.194
subnet 255.255.255.255
gateway 192.168.255.233
As the subnets of the clients is 255.255.255.255 it can only ARP to the gateway never to each other but due to XS1930-10 when you ping 192.168.255.194 from 192.168.255.193 it works.
on VPN300 with interface general 192.168.255.247 / 255.255.255.192 and proxy ARP 192.168.255.193-192.168.255.194
Two clients
IP 192.168.255.193
subnet 255.255.255.255
gateway 192.168.255.247
IP 192.168.255.194
subnet 255.255.255.255
gateway 192.168.255.247
The clients try to ping each other they go to the VPN300 gateway but the proxy ARP does not work the same way as L3 switch.
Comments
-
Hi @PeterUK,
Thank you for sharing this idea and for providing such a detailed test scenario.
We understand your point — on the XS1930 L3 switch the gateway interface can handle the ARP and forwarding in a way that allows two clients to communicate, while on the VPN300 with proxy ARP does not behave in the same way.We really appreciate your input and the time you spent testing this behavior.
However, since the VPN300 has already reached End of Life, we are unable to make changes or add new features on this model.
Zyxel Tina
0 -
Yes I know the VPN is EOL but the idea is for current models.
The idea would work if the DHCP server give out subnet 255.255.255.255 to client this would then force client to go to the gateway only and to connect to each other you can then firewall/BWM between clients on a LAN to LAN setting.
0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 196 Nebula Ideas
- 121 Nebula Status and Incidents
- 6.3K Security
- 475 USG FLEX H Series
- 312 Security Ideas
- 1.6K Switch
- 82 Switch Ideas
- 1.3K Wireless
- 45 Wireless Ideas
- 6.8K Consumer Product
- 284 Service & License
- 446 News and Release
- 88 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 93 Security Highlight