skip to content

Beyond covering for a wrong subnet mask, where is IPv4 proxy ARP still a deliberate part of a network design?

level: middleimportance: nice to knowfreq 10%

answer

  1. address owned but not present
  2. a node that left home
  3. a pool nobody else answers for
  4. isolated ports sharing one subnet

basics

~20 s

Proxy ARP is designed in wherever hosts will ARP for an address that is deliberately not on their segment: Mobile IPv4 home agents, Basic NAT pools from the LAN's subnet, private VLANs, VPN pools numbered from the LAN, and historic transparent subnetting.

solid answer

~40 s

The common thread is an address that hosts treat as local but that by design is not on the segment. A Mobile IPv4 home agent (RFC 5944 §4.6) answers ARP for an away mobile node's home address and tunnels its traffic, using gratuitous ARP to switch caches at each move. A Basic NAT router whose public pool comes from its LAN-facing subnet must answer ARP for those pool addresses (RFC 3022 §6.2), because nobody else owns them. Private VLANs (RFC 5517) need proxy-ARP-like routing so isolated hosts in one subnet can reach each other through the router, and a VPN gateway giving clients LAN-subnet addresses answers for them on the LAN. RFC 1027's transparent subnetting is the historic origin.

go deeper

for a junior

Recall that proxy ARP is not only a workaround: some designs need a device to answer for addresses that are not on the segment.

for a middle

Name the designs and say for each who proxies, for which addresses, and why nobody else could answer.

for a senior

Use these designs to tell deliberate proxy ARP from accidental before disabling it, and document the deliberate cases on the interfaces that need them.

for a principal

Ask whether a design that relies on proxy ARP could use routing instead, weighing host transparency against hidden layer-2 dependencies.

## Accidental versus designed proxy ARP Most proxy ARP seen in the field is accidental: a default-on router covering for hosts with wrong masks. But the technique is also written into several designs on purpose. In each one, the proxying device is meant to receive the traffic, and the reason is the same: hosts on a segment will ARP for an address that, by design, is not on that segment. | Design | Who proxies | For which addresses | Where it is described | |---|---|---|---| | Transparent subnetting | the subnet gateway | hosts on other subnets of the same network | RFC 925 (proposal), RFC 1027 | | Mobile IPv4 | the home agent | a mobile node's home address while it is away | RFC 5944 §4.6 (Standards Track) | | Basic NAT on a LAN | the NAT router | public pool addresses taken from the LAN's subnet | RFC 3022 §6.2 (Informational) | | Private VLANs | the router on the primary VLAN | isolated hosts in the same subnet | RFC 5517 §5 (Informational) | | Remote-access VPN | the VPN gateway | client addresses taken from the LAN's subnet | common design practice, no RFC | ## Transparent subnetting — the original use In the mid-1980s many host operating systems had no subnet support. RFC 925 proposed letting gateways answer ARP across LANs so a site could split one network into segments without changing the hosts; RFC 1027 documented a restricted, widely deployed version. Hosts kept the mask of the whole network, and the subnet gateways answered for every address behind them. This use is now history — every IPv4 stack understands masks — but it is where proxy ARP's rules come from. ## Mobile IPv4 home agents RFC 5944 §4.6 makes proxy ARP part of a Standards Track protocol: 1. When a mobile node registers from a foreign network and its home agent accepts the registration, the home agent sends a **gratuitous ARP** on the home network mapping the home address to its own MAC, so cached entries move to it. 2. While the binding lasts, the home agent **must** answer ARP requests for the mobile node's home address with the MAC of its own interface, and tunnels the packets it receives to the mobile node. 3. When the mobile node comes home, it re-enables its own ARP replies and sends a gratuitous ARP for itself; once the home agent accepts the home registration, it stops proxying and sends a gratuitous ARP restoring the node's own MAC. Proxy ARP keeps the home network's hosts unaware that the node moved. ## Basic NAT with a pool from the LAN's subnet RFC 3022 §6.2 covers a NAT router whose outside interface is a LAN and whose pool of global addresses belongs to that LAN's subnet. Nobody owns those addresses on the wire, so unless the NAT router answers ARP for them with its own MAC, requests from the upstream router go unanswered. For Basic NAT the RFC calls answering "a must" in that situation; it is unlikely with port translation, which normally uses the router's own interface address. ## Private VLANs and VPN pools - **Private VLANs** (RFC 5517, an Informational RFC describing one switch vendor's feature) keep isolated hosts in one subnet from talking at layer 2. The router assumes same-subnet hosts can talk directly, so the RFC says a "proxy-ARP-like functionality" is needed on the router interface for those hosts to reach each other through it. - **Remote-access VPN gateways** that hand clients addresses from the office LAN's own subnet must answer ARP on the LAN for those addresses, or office hosts that ARP for a client get no reply. No RFC specifies this; it is a common way to make VPN clients look local. ## The IPv6 counterpart IPv6 has no ARP, but RFC 4861 §7.2.8 lets a router send **proxy Neighbor Advertisements**, for example for a mobile node that has moved off-link. A proxy joins the target's solicited-node multicast group, and its solicited advertisements must carry the **Override flag set to zero**, so the real node's own advertisement, with Override set, wins if the node is present on the link. That is a safety valve IPv4 proxy ARP never had.

  • What is the IPv6 equivalent, and how does it avoid hijacking a node that is present?
    IPv6 uses proxy Neighbor Advertisements (RFC 4861 §7.2.8). The proxy joins the target's solicited-node multicast group and sends solicited advertisements with the Override flag cleared, so if the real node is on the link, its own advertisement, with Override set, replaces the proxy's entry in neighbours' caches.
  • In Mobile IPv4, why does the home agent pair proxy ARP with gratuitous ARP?
    Proxy ARP only answers new requests; home hosts that already cached the mobile node's MAC would keep sending to it. The home agent's gratuitous ARP on accepting the registration overwrites those entries with its own MAC, and the reverse announcement when the node returns restores the node's MAC.

saying these in an interview costs you the question

  • Proxy ARP has no legitimate use once every host supports subnet masks.
  • A NAT router never needs to answer ARP for its translation pool.
  • Mobile IPv4 home agents forward ARP requests to the mobile node through the tunnel.
  • IPv6 proxies by sending ARP replies inside ICMPv6.
  • Any proxy ARP on a network is a sign of an attack.