Symptoms: Proxy ARP Causing Unexpected Routing Behavior¶
- Hosts on different subnets can communicate even though no explicit route exists between them.
- ARP table on hosts shows the router's MAC address for IP addresses on remote subnets.
- Traceroute between hosts on different VLANs shows what appears to be a direct path (single hop).
- Network segmentation policies are being bypassed; hosts in the "restricted" VLAN can reach the "production" VLAN.
- Security audit flagged unexpected cross-subnet traffic that should be blocked.
- The router CPU utilization is higher than expected due to ARP processing.
- Some hosts experience intermittent ARP table corruption or stale entries.
- The issue exists on all subnets connected to the same router.