šŸ•ŗUnderstanding Proxy ARP | How Firewalls Use It to Respond to Multiple IPsā‰ļø

Ronald BartelsRonald Bartels
4 min read

What is Proxy ARP?

Proxy ARP (Address Resolution Protocol) is a technique where a deviceā€”typically a firewall, router, or Layer 3 switchā€”responds to ARP requests on behalf of another device. This allows multiple IP addresses to appear as if they exist on the same subnet, even when they are actually routed elsewhere.

Itā€™s commonly used to:
āœ” Extend subnets beyond their physical boundaries
āœ” Allow a firewall to handle multiple IP addresses on a single interface
āœ” Enable network segmentation without requiring additional router interfaces

How Does ARP Normally Work?

In a standard ARP request-response process:
1ļøāƒ£ A device (Host A) wants to send a packet to another device (Host B).
2ļøāƒ£ Host A broadcasts an ARP request: "Who has IP 192.168.1.10? Tell me your MAC address!"
3ļøāƒ£ If Host B owns 192.168.1.10, it replies with its MAC address.
4ļøāƒ£ Host A then sends traffic directly to Host Bā€™s MAC.

How Proxy ARP Changes the Game

With Proxy ARP enabled on a firewall (or router):
1ļøāƒ£ Host A sends an ARP request for 192.168.1.10.
2ļøāƒ£ The firewall (which has Proxy ARP enabled) sees the request and responds on behalf of 192.168.1.10, using its own MAC address.
3ļøāƒ£ Host A now sends all traffic for 192.168.1.10 to the firewall, which forwards the packets to the correct destination.

This makes it seem like all these IPs exist on the firewallā€™s subnetā€”even if they donā€™t.


How Firewalls Use Proxy ARP for Multiple IPs on One Interface

Firewalls often use Proxy ARP to host multiple IP addresses on a single network interface. This is useful for:
āœ… Public IP allocation: ISPs often assign multiple public IPs to a business, but they only provide a single physical connection. A firewall with Proxy ARP can respond to ARP requests for all those public IPs.
āœ… One-to-one NAT: Firewalls can map external IPs to internal servers while making the external IPs appear locally reachable.
āœ… Load balancing & failover: A firewall can respond to multiple IPs and distribute traffic between different backend servers.

Example: Firewall with Multiple Public IPs

Imagine an ISP assigns a business a block of public IPs (196.10.10.1ā€“196.10.10.5) but only provides a single physical connection to the firewall.

šŸ›œ Without Proxy ARP:

  • Only the firewallā€™s primary IP (e.g., 196.10.10.1) would be accessible.

  • The remaining IPs would need additional interfaces or static routes.

šŸ›œ With Proxy ARP:

  • The firewall can respond to ARP requests for 196.10.10.2ā€“196.10.10.5, even though they donā€™t exist on a separate interface.

  • It then performs NAT or routing to forward traffic accordingly.


Is Proxy ARP a Security Risk?

Only in a LAN ā€“ Not on Firewalls or SD-WAN Devices

āš ļø Security concerns arise when Proxy ARP is used in a LAN.

  • In a local network, an attacker can use ARP spoofing (a Man-in-the-Middle (MITM) attack) to trick devices into sending traffic to the wrong destination.

  • This can allow eavesdropping, traffic interception, or redirection to a malicious host.

šŸ”’ On public-facing firewalls, SD-WAN devices, or edge routers, Proxy ARP is NOT a risk.

  • The firewall is the legitimate owner of the public IPs and is expected to respond on behalf of them.

  • There are no untrusted users inside the network who can manipulate ARP tables.

  • Firewalls only respond to the correct requests, preventing spoofing attacks.

In fact, Proxy ARP is crucial for public IP address management, allowing firewalls and SD-WAN devices to efficiently handle multiple addresses on a single WAN link.


Why Fusionā€™s SD-WAN Uses Proxy ARP Correctly

šŸš€ Fusion's SD-WAN optimises multiple connections while correctly implementing Proxy ARP for public IPs. Unlike traditional firewall-based SD-WAN solutions that struggle with NAT complexities, Fusionā€™s SD-WAN:
āœ… Ensures proper public IP mapping without breaking sessions
āœ… Handles multi-WAN failover seamlessly without reconfiguration
āœ… Avoids common NAT headaches seen in Mikrotik, pfSense, and other budget firewalls

šŸ”‘ Bottom line: If youā€™re dealing with public IPs, Proxy ARP is a necessityā€”not a risk. The real danger lies in cheap firewalls that mishandle ARP and NAT. For a secure, resilient, and intelligent solution, Fusionā€™s SD-WAN is the right choice.

1
Subscribe to my newsletter

Read articles from Ronald Bartels directly inside your inbox. Subscribe to the newsletter, and don't miss out.

Written by

Ronald Bartels
Ronald Bartels

Driving SD-WAN Adoption in South Africa