Proxy ARP and DHCP Relay Overwrite
Redirect device traffic through the firewall using Proxy ARP and DHCP Relay
Overwrite for intra-VLAN and inter-VLAN scenarios to enforce granular security
policy.
| Where Can I Use This? | What Do I Need? |
|
|
- PAN-OS 12.2.2 or a later release
- One of these licenses when using Strata Cloud Manager
- Strata Cloud Manager Essentials
- Strata Cloud Manager Pro
|
Proxy ARP and DHCP Relay Overwrite redirect traffic through the firewall for inspection
and policy enforcement. For scenarios where devices share same Layer 2 broadcast domain,
they communicate at Layer 2 without passing through a Layer 3 gateway, which means the
firewall lacks visibility into or control over that traffic. This lack of visibility
creates a security enforcement gap that allows unrestricted lateral movement between
devices. This is particularly concerning in flat network environments, such as
operational technology (OT) networks, industrial control systems, and manufacturing
environments, where devices like programmable logic controllers, sensors, and
engineering workstations share a single broadcast domain.
The following two mechanisms address this gap but work differently depending on how
devices obtain their IP addresses:
- Proxy ARP (Address Resolution Protocol) is a technique where a network
device (usually a router) answers ARP queries on behalf of another device.
- DHCP Relay Overwrite modifies the subnet mask and default gateway values in
DHCP responses before the firewall forwards them to clients.
Once traffic passes through the firewall, the full range of security capabilities is
available for enforcement, including App-ID™, User-ID™, Device-ID, Threat Prevention,
WildFire®, and Device Security.
To implement this feature, configure
Proxy
ARP on the Layer 3 interface and configure
DHCP Relay Overwrite on the DHCP relay
interface. After configuration,
verify that the traffic is passing through the firewall and
matching your security policy rules.