Proxy ARP and DHCP Relay Overwrite
Focus
Focus
Next-Generation Firewall

Proxy ARP and DHCP Relay Overwrite

Table of Contents

Proxy ARP and DHCP Relay Overwrite

Redirect device traffic through the firewall using Proxy ARP and DHCP Relay Overwrite for intra-VLAN and inter-VLAN scenarios to enforce granular security policy.
Where Can I Use This?What Do I Need?
  • NGFW
  • PAN-OS 12.2.2 or a later release
  • One of these licenses when using Strata Cloud Manager
    • Strata Cloud Manager Essentials
    • Strata Cloud Manager Pro
Proxy ARP and DHCP Relay Overwrite redirect traffic through the firewall for inspection and policy enforcement. For scenarios where devices share same Layer 2 broadcast domain, they communicate at Layer 2 without passing through a Layer 3 gateway, which means the firewall lacks visibility into or control over that traffic. This lack of visibility creates a security enforcement gap that allows unrestricted lateral movement between devices. This is particularly concerning in flat network environments, such as operational technology (OT) networks, industrial control systems, and manufacturing environments, where devices like programmable logic controllers, sensors, and engineering workstations share a single broadcast domain.
The following two mechanisms address this gap but work differently depending on how devices obtain their IP addresses:
  • Proxy ARP (Address Resolution Protocol) is a technique where a network device (usually a router) answers ARP queries on behalf of another device.
  • DHCP Relay Overwrite modifies the subnet mask and default gateway values in DHCP responses before the firewall forwards them to clients.
Once traffic passes through the firewall, the full range of security capabilities is available for enforcement, including App-ID™, User-ID™, Device-ID, Threat Prevention, WildFire®, and Device Security.
To implement this feature, configure Proxy ARP on the Layer 3 interface and configure DHCP Relay Overwrite on the DHCP relay interface. After configuration, verify that the traffic is passing through the firewall and matching your security policy rules.