D-Link DFL-2500 User Manual

Page 97

Advertising
background image

IP address of host B on another separate network. The proxy ARP feature means that NetDefendOS
responds to this ARP request instead of host B. The NetDefendOS sends its own MAC address
instead in reply, essentially pretending to be the target host. After receiving the reply, Host A then
sends data directly to NetDefendOS which, acting as a proxy, forwards the data on to host B. In the
process the device has the opportunity to examine and filter the data.

The splitting of an Ethernet network into two distinct parts is a common application of D-Link
Firewall's Proxy ARP feature, where access between the parts needs to be controlled. In such a
scenario NetDefendOS can monitor and regulate all traffic passing between the two parts.

Note

It is only possible to have Proxy ARP functioning for Ethernet and VLAN interfaces.

4.2.4. Proxy ARP

Chapter 4. Routing

97

Advertising