šŗUnderstanding Proxy ARP | How Firewalls Use It to Respond to Multiple IPsāļø


What is Proxy ARP?
Proxy ARP (Address Resolution Protocol) is a technique where a deviceātypically a firewall, router, or Layer 3 switchāresponds to ARP requests on behalf of another device. This allows multiple IP addresses to appear as if they exist on the same subnet, even when they are actually routed elsewhere.
Itās commonly used to:
ā Extend subnets beyond their physical boundaries
ā Allow a firewall to handle multiple IP addresses on a single interface
ā Enable network segmentation without requiring additional router interfaces
How Does ARP Normally Work?
In a standard ARP request-response process:
1ļøā£ A device (Host A) wants to send a packet to another device (Host B).
2ļøā£ Host A broadcasts an ARP request: "Who has IP 192.168.1.10? Tell me your MAC address!"
3ļøā£ If Host B owns 192.168.1.10, it replies with its MAC address.
4ļøā£ Host A then sends traffic directly to Host Bās MAC.
How Proxy ARP Changes the Game
With Proxy ARP enabled on a firewall (or router):
1ļøā£ Host A sends an ARP request for 192.168.1.10.
2ļøā£ The firewall (which has Proxy ARP enabled) sees the request and responds on behalf of 192.168.1.10, using its own MAC address.
3ļøā£ Host A now sends all traffic for 192.168.1.10 to the firewall, which forwards the packets to the correct destination.
This makes it seem like all these IPs exist on the firewallās subnetāeven if they donāt.
How Firewalls Use Proxy ARP for Multiple IPs on One Interface
Firewalls often use Proxy ARP to host multiple IP addresses on a single network interface. This is useful for:
ā
Public IP allocation: ISPs often assign multiple public IPs to a business, but they only provide a single physical connection. A firewall with Proxy ARP can respond to ARP requests for all those public IPs.
ā
One-to-one NAT: Firewalls can map external IPs to internal servers while making the external IPs appear locally reachable.
ā
Load balancing & failover: A firewall can respond to multiple IPs and distribute traffic between different backend servers.
Example: Firewall with Multiple Public IPs
Imagine an ISP assigns a business a block of public IPs (196.10.10.1ā196.10.10.5) but only provides a single physical connection to the firewall.
š Without Proxy ARP:
Only the firewallās primary IP (e.g., 196.10.10.1) would be accessible.
The remaining IPs would need additional interfaces or static routes.
š With Proxy ARP:
The firewall can respond to ARP requests for 196.10.10.2ā196.10.10.5, even though they donāt exist on a separate interface.
It then performs NAT or routing to forward traffic accordingly.
Is Proxy ARP a Security Risk?
Only in a LAN ā Not on Firewalls or SD-WAN Devices
ā ļø Security concerns arise when Proxy ARP is used in a LAN.
In a local network, an attacker can use ARP spoofing (a Man-in-the-Middle (MITM) attack) to trick devices into sending traffic to the wrong destination.
This can allow eavesdropping, traffic interception, or redirection to a malicious host.
š On public-facing firewalls, SD-WAN devices, or edge routers, Proxy ARP is NOT a risk.
The firewall is the legitimate owner of the public IPs and is expected to respond on behalf of them.
There are no untrusted users inside the network who can manipulate ARP tables.
Firewalls only respond to the correct requests, preventing spoofing attacks.
In fact, Proxy ARP is crucial for public IP address management, allowing firewalls and SD-WAN devices to efficiently handle multiple addresses on a single WAN link.
Why Fusionās SD-WAN Uses Proxy ARP Correctly
š Fusion's SD-WAN optimises multiple connections while correctly implementing Proxy ARP for public IPs. Unlike traditional firewall-based SD-WAN solutions that struggle with NAT complexities, Fusionās SD-WAN:
ā
Ensures proper public IP mapping without breaking sessions
ā
Handles multi-WAN failover seamlessly without reconfiguration
ā
Avoids common NAT headaches seen in Mikrotik, pfSense, and other budget firewalls
š Bottom line: If youāre dealing with public IPs, Proxy ARP is a necessityānot a risk. The real danger lies in cheap firewalls that mishandle ARP and NAT. For a secure, resilient, and intelligent solution, Fusionās SD-WAN is the right choice.
Subscribe to my newsletter
Read articles from Ronald Bartels directly inside your inbox. Subscribe to the newsletter, and don't miss out.
Written by

Ronald Bartels
Ronald Bartels
Driving SD-WAN Adoption in South Africa