Skip to content

Symptoms: Proxy ARP Causing Unexpected Routing Behavior

  • Hosts on different subnets can communicate even though no explicit route exists between them.
  • ARP table on hosts shows the router's MAC address for IP addresses on remote subnets.
  • Traceroute between hosts on different VLANs shows what appears to be a direct path (single hop).
  • Network segmentation policies are being bypassed; hosts in the "restricted" VLAN can reach the "production" VLAN.
  • Security audit flagged unexpected cross-subnet traffic that should be blocked.
  • The router CPU utilization is higher than expected due to ARP processing.
  • Some hosts experience intermittent ARP table corruption or stale entries.
  • The issue exists on all subnets connected to the same router.