The Security Director Cloud deletes the proxy-arp config in the Preview Config.
Config seen in the Preview Config:
This will happen even if the "Manage auto-proxy ARP" configuration on the policy's global config is enabled, under:
NAT policies >> Edit the Policy >> Enable Manage auto-proxy ARP
Ideally, if the "Manage auto-proxy ARP" is enabled, the SDC should be able to detect the proxy-arp config from the device and enable it globally for the rules in that policy.
This config can be seen in 2 cases:
This is a known issue for which the engineering has found the root cause and the fix for the issue. The fix will be pushed out to the SDC in the second week of July, 2024.