How can I make DNAT host respond to ARP requests?

I have a ubuntu server host with nftables set up to NAT incoming ssh connections on a group of IP addresses and ports to certain other IP addresses and ports connected on certain other interfaces. See illustration.

DNAT host illustration

I initially only configured 192.168.1.10 on eth0. This seems to work, packages to 192.168.1.11-13 on the configured NAT source ports are really forwarded as intended. However, occasionally it stops working and the ssh clients get error message “no route to host”. I figured out it has to do with arp: when some client on my 192.168.1.0 subnet wants to connect with ssh to 192.168.1.12 it first sends an “Who has 192.168.1.12” arp request (unless that information already exists in some cache). And my NAT host doesn’t answer since it is configured as 192.168.1.10.

If I also configure the other IP addresses (192.168.1.11, 192.168.1.12, 192.168.1.13) on eth0 on my NAT host it works, now the arp requests are answered.

But it feels wrong. Why should I configure those IP addresses on eth0 when I never do anything else than NAT-forward incoming connections? The only thing I need is for the NAT host to answer ARP requests. Is there some other way to make it do that? Could “net.ipv4.conf.eth0.proxy_arp=1” help me somehow? Or some fancy ARP table rule in nftables on that NAT host?

Many thanks.