Cisco ASA ARP Behavior

The Cisco ASA can exhibit some non-standard ARP behavior depending on the OS version and system configuration. Here are some notes to remember this by.

NOTE: Do not confuse this with sysopt noproxyarp command which is off by default. The proxy arp on the ASA is important to allow the ASA to answer ARP requests for NAT hosted private servers appearing as a separate public IP on the ASA outside interface. Leave the sysopt command for proxy arp set to the default so that NAT proxy arp will function correctly.

