skip to content

While an IPv4 ARP resolution is pending, what must a host or router do with waiting packets, and when may it report failure?

level: middleimportance: nice to knowfreq 15%

answer

  1. the first packet of an exchange
  2. keep at least the latest one
  3. one request per second
  4. no error just for a missing entry
  5. Host Unreachable only after giving up

basics

~20 s

RFC 1122: keep at least the latest packet per unresolved address, send it once resolved, rate-limit requests, and never report Destination Unreachable just for a missing entry. RFC 1812: a router reports Host Unreachable only after resolution fails.

solid answer

~40 s

Between the first packet and the ARP reply the entry is unresolved. RFC 1122 §2.3.2.2 says the link layer SHOULD save at least one packet, the latest, per unresolved address and send it once the address resolves; otherwise the first packet of every exchange is lost, which inflates TCP's initial round-trip estimate and hurts UDP protocols like DNS more. §2.3.2.1 requires flood prevention, recommending at most one request per second per destination. A missing entry alone MUST NOT produce a Destination Unreachable. For routers, RFC 1812 §3.3.2 says to queue a few datagrams briefly and report unreachable only when resolution proves fruitless, which §5.2.7.1 maps to ICMP Destination Unreachable code 1, Host Unreachable.

go deeper

for a junior

Know that a missing ARP entry triggers a request, the packet waits rather than failing, and a router only reports Host Unreachable when ARP gets no answer.

for a middle

Cite the rules: RFC 1122 keeps at least the latest packet, rate-limits requests to about one per second per destination, and forbids an error just for a missing entry; RFC 1812 maps fruitless resolution to type 3 code 1.

for a senior

Use the difference in production: Host Unreachable from the last router means ARP failed, while silence for a host with an entry suggests a wrong cached MAC. Explain slow first requests from the queueing rule.

for a principal

Weigh queue depth and resolution retries against memory and broadcast load on routers that face large or flaky segments, and keep IPv4 and IPv6 failure signalling distinct in tooling and alerts.

## The window nobody notices until it bites When a host or router has a packet for a next hop with no ARP cache entry, it broadcasts an ARP request and waits for the reply. On a healthy LAN that window is short, but it is real, and it is the first thing that happens at the start of almost every conversation after an entry has expired. The specifications say what to do with traffic that arrives during it, and what to tell the sender if the answer never comes. ## What host requirements say RFC 1122 sets three rules for this window: | Section | Rule | Strength | |---|---|---| | §2.3.2.2 | save at least one (the latest) packet of each set destined to the same unresolved IPv4 address, and transmit it once resolved | SHOULD | | §2.3.2.1 | prevent ARP flooding; recommended maximum 1 request per second per destination | MUST include a mechanism | | §2.4 | do not report Destination Unreachable to IP solely because there is no ARP cache entry | MUST NOT | The queue can be tiny. "At least one (the latest)" means a host that keeps only the newest packet and drops earlier ones still complies; what it must not do is throw every unresolved packet away. ## Why the first packet matters RFC 1122's discussion spells out the cost of discarding: - the first packet of **every** exchange is lost whenever the entry had to be resolved; - for TCP, losing the opening segment means a retransmission timeout, and it inflates the initial round-trip time estimate; - for UDP protocols such as DNS the damage is worse, because the application itself has to notice the silence and retry. This is the protocol-level explanation for a familiar symptom: the very first request to a rarely contacted local host is noticeably slower than the rest, or a single UDP query times out and the retry succeeds. An implementation that queues correctly hides almost all of this; one that discards turns every expired entry into a lost packet, and the busier the link's turnover of entries, the more often users feel it. ## What router requirements add RFC 1812 §3.3.2 restates the same duty for routers forwarding to a directly connected network: 1. Do not report the destination unreachable just because there is no entry yet. 2. Queue up to a small number of datagrams briefly while the request and reply run. 3. Report the destination unreachable for one of the queued datagrams only when resolution proves fruitless. The ICMP message for that case is **Destination Unreachable (type 3), code 1, Host Unreachable**. RFC 1812 §5.2.7.1 describes code 1 as generated by a router when the forwarding path to a host on a directly connected network is not available, "does not respond to ARP". Compare code 0, Network Unreachable, for a destination with no route at all, and code 3, Port Unreachable, which comes from the destination host itself. ## A stale entry is a different failure Pending resolution fails **loudly**: the router knows it never got an answer and can say so. An entry that resolved to a MAC that no longer exists fails **silently**: the frame is handed to Ethernet, which has no delivery acknowledgement, and nobody reports anything. Telling the two apart is a large part of many "one host is unreachable" investigations: - Host Unreachable arriving from the last router means ARP got no answer on the destination's link; - timeouts with no ICMP at all, for a host that clearly holds an entry, point to a wrong cached MAC. ## The IPv6 contrast IPv6 has no ARP, but Neighbor Discovery makes the same rules stronger. RFC 4861 says a node MUST queue at least one packet per neighbour awaiting resolution and SHOULD replace the oldest on overflow, and when resolution fails it MUST return ICMPv6 Destination Unreachable with **code 3, Address Unreachable**, for each queued packet. Same idea, different message and different code; do not carry the IPv6 code over to IPv4. ## Misconceptions - "A missing ARP entry makes the host answer Destination Unreachable at once" is exactly what RFC 1122 forbids. - "Packets are dropped while ARP runs" describes a non-compliant implementation, not the rule. - "The switch sends Host Unreachable" misplaces the message; an IPv4 router, which knows it tried ARP, generates it.

  • Why does RFC 1122 rate-limit ARP requests even while a packet is waiting?
    A host with traffic for an address that never answers would otherwise broadcast a request for every queued packet, and every host on the link must process each broadcast. The flood-prevention MUST, with a recommended ceiling of one request per second per destination, bounds that load while still letting resolution retry.
  • A client gets ICMP Host Unreachable from a router for a server on the router's own LAN. What does that tell you?
    The router has a route and tried to deliver, but its ARP requests for the server's IPv4 address got no reply: the server is down, disconnected, on the wrong VLAN or not configured with that address. It is a link-level failure at the last hop, not a routing or firewall problem.

saying these in an interview costs you the question

  • A host reports Destination Unreachable as soon as it finds no ARP entry.
  • Packets are always dropped while an ARP request is outstanding.
  • The Ethernet switch sends ICMP Host Unreachable when ARP fails.
  • ARP failure on an IPv4 link produces Destination Unreachable code 3.
  • Hosts may resend ARP requests as fast as packets arrive.