skip to content

In IPv6, what replaces ARP for finding a neighbour's MAC address, and why does no broadcast take part?

level: juniorimportance: must knowfreq 50%

answer

  1. ICMPv6, not a separate protocol
  2. a solicitation and an advertisement
  3. one multicast group per address
  4. low 24 bits of the target

basics

~20 s

IPv6 Neighbor Discovery (RFC 4861) replaces ARP: a host sends an ICMPv6 Neighbor Solicitation to the target's solicited-node multicast address, and the target answers with a unicast Neighbor Advertisement carrying its MAC. IPv6 has no broadcast.

solid answer

~40 s

IPv6 resolves addresses with **Neighbor Discovery** (RFC 4861), which runs inside ICMPv6 rather than as a separate link-layer protocol the way ARP does. To reach `2001:db8:42:1::20`, a host sends a **Neighbor Solicitation** (ICMPv6 type 135) to that address's **solicited-node multicast group**, `ff02::1:ff00:20` — the prefix `ff02::1:ff00:0/104` plus the target's low 24 bits — with its own MAC in a Source Link-Layer Address option. The target replies with a unicast **Neighbor Advertisement** (type 136) carrying its MAC. IPv6 defines no broadcast at all, and only addresses sharing those low 24 bits join that group, so on a typical LAN only the target is interrupted. Neighbor Discovery also adds what ARP lacks: reachability tracking (Neighbor Unreachability Detection) and a Hop Limit of 255 that proves a message came from the link itself.

go deeper

for a junior

Recall that IPv6 has no ARP and no broadcast: Neighbor Discovery sends a Neighbor Solicitation to a multicast group derived from the target and gets a Neighbor Advertisement back.

for a middle

Explain how the solicited-node address is built from the low 24 bits, why the source MAC option is mandatory on a multicast solicitation, and what the neighbour cache states mean.

for a senior

Show you know what Neighbor Discovery does not protect: the Hop Limit 255 check stops off-link injection only, so a host on the same link can forge advertisements just as with ARP.

for a principal

Weigh what moving resolution into ICMPv6 bought — media independence, reachability tracking, a place for SEND — against what stayed the same: on-link trust that any attached device can abuse.

## Same job, different layer On an Ethernet link a packet can only be delivered once the sender knows the next hop's **link-layer (MAC) address**. IPv4 learns it with **ARP**, a separate protocol with its own EtherType that sits beside IP. IPv6 has no ARP. It uses **Neighbor Discovery (ND)**, defined in RFC 4861, whose messages are ICMPv6 packets (Next Header 58) carried inside ordinary IPv6 packets. RFC 4861 describes ND as the combination of three IPv4 mechanisms: ARP, ICMP Router Discovery and ICMP Redirect. This answer covers the ARP part, **address resolution**. Two ND messages do the work: - **Neighbor Solicitation (NS)**, ICMPv6 type 135 — "whoever holds this target address, tell me your link-layer address". - **Neighbor Advertisement (NA)**, ICMPv6 type 136 — "the target is mine, and here is my link-layer address". ## The exchange on the wire Take laptop A at `2001:db8:42:1::10` (MAC `00:00:5e:00:53:10`) sending its first packet to B at `2001:db8:42:1::20` on the same link. 1. A creates a neighbour cache entry for B in state `INCOMPLETE`, queues the packet, and builds an NS whose **Target Address** is `2001:db8:42:1::20`. 2. The NS goes to B's **solicited-node multicast address**: the fixed prefix `ff02::1:ff00:0/104` followed by the low 24 bits of the target, here `ff02::1:ff00:20`. On Ethernet, RFC 2464 maps an IPv6 multicast address to a MAC made of `33:33` plus the address's last four bytes, so the frame goes to `33:33:ff:00:00:20`. 3. Because the NS is multicast, A **must** include its own MAC in a **Source Link-Layer Address** option, so B can answer without asking back. 4. B, which joined that group when it configured its address, answers with a **unicast NA** to A, carrying its MAC in a **Target Link-Layer Address** option, with the **Solicited** flag set and normally the **Override** flag set. 5. A marks B `REACHABLE` and sends the queued packet. If no answer comes, A retries; RFC 4861's defaults are 3 multicast solicitations (`MAX_MULTICAST_SOLICIT`) one second apart (`RETRANS_TIMER`). Every ND message is sent with **Hop Limit 255**, and receivers discard ND messages that arrive with anything less. That proves the sender is on the link: a packet forwarded by a router would have been decremented. ## Why multicast instead of broadcast IPv6 has no broadcast address; all-nodes `ff02::1` is the nearest thing, and address resolution avoids it. The solicited-node group is the point: - An ARP request goes to `ff:ff:ff:ff:ff:ff`, so **every** host on the segment hands it up to its network stack, including hosts that do not run IPv4. - An NS goes to one of 2^24 (about 16 million) groups. Only hosts holding an address with the same low 24 bits joined it — on a normal LAN, the target alone — and other network cards typically filter the frame in hardware. - A switch without MLD snooping still floods the frame to every port, so the saving is in interrupts on hosts, not in bandwidth on the wire. - Addresses that differ only in their prefix share a group, so a host with several global addresses built on one interface identifier joins one group, not several. ## After the answer: the neighbour cache ND keeps more state than ARP because it also runs **Neighbor Unreachability Detection (NUD)**: | State | Meaning | |---|---| | `INCOMPLETE` | NS sent, no answer yet | | `REACHABLE` | reachability confirmed recently (base `REACHABLE_TIME` 30 s, randomised between 0.5 and 1.5 times) | | `STALE` | not confirmed lately; still used, but not probed until traffic is sent | | `DELAY` | traffic sent to a stale entry; waiting up to 5 s for an upper-layer hint such as TCP acknowledgements | | `PROBE` | unicast NS sent to confirm; after 3 unanswered the entry should be deleted | Confirmation comes either from a solicited NA or from upper-layer progress, so a busy TCP connection needs no extra probes. As RFC 4861 notes, IPv4 has no generally agreed mechanism that notices a neighbour has vanished; ND detects half-broken links and neighbours whose MAC changed. ## ARP vs Neighbor Discovery | | IPv4 ARP | IPv6 Neighbor Discovery | |---|---|---| | Carried in | its own link-layer protocol | ICMPv6 inside IPv6 | | Request sent to | link broadcast | solicited-node multicast | | Off-link senders kept out by | ARP frames are never routed | the Hop Limit 255 check, since ND rides routable IPv6 | | Reachability tracking | none in the base protocol | NUD state machine | | Cryptographic option | none | SEND (RFC 3971) | Living inside IP also lets ND use IP-layer security mechanisms, which is what SEND later did. ## Common confusions - The Hop Limit check does not stop a host **on the link** from forging an NA; that forgery is the IPv6 twin of ARP spoofing. - In normal resolution the NA is unicast to the solicitor. It is multicast to all-nodes when the solicitation came from the unspecified address (during duplicate address detection) or when a node announces a changed MAC unsolicited. - The solicited-node group carries ND traffic only; ordinary traffic still goes to the unicast address.

  • Why must an IPv6 Neighbor Solicitation carry the sender's MAC when it is multicast, but not necessarily when it is unicast?
    A multicast solicitation reaches a target that may have no cache entry for the sender, so RFC 4861 makes the Source Link-Layer Address option mandatory: it gives the target an address to unicast its advertisement to. A unicast solicitation, used to confirm reachability, comes from a node that already holds the target's MAC, so the target very likely has the sender cached too; the option may be omitted.
  • What does Neighbor Discovery's Hop Limit 255 requirement protect against, and what does it not?
    A router decrements the hop limit, so an ND message arriving at 255 cannot have been forwarded; receivers discard any lower value. That stops a sender elsewhere on the internet from injecting advertisements or redirects. It does nothing against a device on the same link, which sends at 255 legitimately; that needs SEND or filtering at the switch.

ARP is shouting a name across the whole office floor so everyone looks up. Neighbor Discovery is calling a pager channel shared only by people whose badge number ends in the same six digits: the person you want hears it, and almost nobody else is disturbed.

saying these in an interview costs you the question

  • IPv6 still uses ARP, just with longer addresses.
  • Neighbor Solicitations are broadcast to every host on the link.
  • Address resolution sends the solicitation to all-nodes ff02::1.
  • Neighbor Discovery is a separate protocol beside IPv6, as ARP is beside IPv4.
  • The Hop Limit 255 check stops spoofed advertisements from hosts on the same link.