The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Network outage due to unresolved ARP traffic

Prev Next

Scenario

Sudden outage in the network due to unresolved ARP traffic

Applicable to Sensor models: NS-series and Virtual IPS Sensors.

Sensor software version:10.1, 11.1

Problem type to be solved

Resolve the ARP traffic which is dropped by the Sensor due to heuristic web application server protection configuration setting.

Data/Information Collection

Steps:

  1. Check if the attack ARP MAC Address Flip-Flop is disabled from the policy.

    Go to Policy → Intrusion Prevention → Policy Types → IPS. Double-click Default Prevention listed in IPS name column.

    Check the policy on the entire device interfaces and make sure ARP flip flop alert is either disabled or not included in the policy on the entire device interfaces.

    GUID-28AAAB06-5F09-4DCB-A7E5-34DDE3EAA169-low.png
  2. Check if the Heuristic Web Application Server Protection is enabled.

    Go to Policy → Intrusion Prevention → Policy Types → Inspection Options. Double-click <Policy Name> listed in Inspection Options page.

    Note

    Check each interface of the device individually.

    GUID-910469F7-5852-4F20-9663-767C89770374-low.png
  3. Check if ARP spoofing is enabled on the Sensor. Use the command show arp spoof status.

    GUID-0521E805-89F5-4313-A778-2C71DE39FCE9-low.png

Explanation

When heuristic web application server protection is enabled, the Manager caching is disabled and only selected attacks are pushed to the Sensor. If the MAC Flip-Flop attack is not part of the attacks chosen by the user, the Sensor drops the ARP packets. This happens in scenarios such as the following:

  • Assignment of dynamic MAC address in the network (vmac)

  • For the firewall in failover mode which uses the Virtual MAC address, the IP address remains the same but the MAC address will change

Troubleshooting Steps

  1. Disable ARP spoofing on the Sensor. Use the command arp spoof to disable ARP spoofing.

  2. Disable Heuristic Web Application Server Protection on the device’s individual interfaces.

    If the problem still persists, contact Trellix Support for further assistance.