I am getting a LOT of ARP requests on my internal network from IP addresses that are on my WAN subnet. Current setup: Cable Modem -> PowerConnect 5524 port 1 VLAN 4000 -> Ubiquiti Switch (vlan 4000) -> ESXi Cluster w/ Distributed Switch, vlan 4000 -> pfsense -> LAN

Outbound NAT — pfSense Documentation A Proxy ARP VIP subnet (ex: shows up in the drop-down for translation target; An alias of IP addresses can be chosen from the drop-down list (note: See limitations below) By choosing Other Subnet from the drop-down list, any arbitrary subnet can be used.

Then the settings of my DMZ (called OPT1 by pfSense) : Setup the Proxy ARP. For packet coming or coming back from internet, the firewall will never answer to address on the WAN side ! To force it to reply to ARP request for this address I have to add a Proxy ARP entry in my Virtual IP addresses. The address is attached to the WAN

