In IPv6, what replaces ARP for finding a neighbour's MAC address, and why does no broadcast take part?
answer
- ICMPv6, not a separate protocol
- a solicitation and an advertisement
- one multicast group per address
- low 24 bits of the target
basics
~20 sIPv6 Neighbor Discovery (RFC 4861) replaces ARP: a host sends an ICMPv6 Neighbor Solicitation to the target's solicited-node multicast address, and the target answers with a unicast Neighbor Advertisement carrying its MAC. IPv6 has no broadcast.
solid answer
~40 sIPv6 resolves addresses with **Neighbor Discovery** (RFC 4861), which runs inside ICMPv6 rather than as a separate link-layer protocol the way ARP does. To reach `2001:db8:42:1::20`, a host sends a **Neighbor Solicitation** (ICMPv6 type 135) to that address's **solicited-node multicast group**, `ff02::1:ff00:20` — the prefix `ff02::1:ff00:0/104` plus the target's low 24 bits — with its own MAC in a Source Link-Layer Address option. The target replies with a unicast **Neighbor Advertisement** (type 136) carrying its MAC. IPv6 defines no broadcast at all, and only addresses sharing those low 24 bits join that group, so on a typical LAN only the target is interrupted. Neighbor Discovery also adds what ARP lacks: reachability tracking (Neighbor Unreachability Detection) and a Hop Limit of 255 that proves a message came from the link itself.
go deeper
Recall that IPv6 has no ARP and no broadcast: Neighbor Discovery sends a Neighbor Solicitation to a multicast group derived from the target and gets a Neighbor Advertisement back.
Explain how the solicited-node address is built from the low 24 bits, why the source MAC option is mandatory on a multicast solicitation, and what the neighbour cache states mean.
Show you know what Neighbor Discovery does not protect: the Hop Limit 255 check stops off-link injection only, so a host on the same link can forge advertisements just as with ARP.
Weigh what moving resolution into ICMPv6 bought — media independence, reachability tracking, a place for SEND — against what stayed the same: on-link trust that any attached device can abuse.
## Same job, different layer On an Ethernet link a packet can only be delivered once the sender knows the next hop's **link-layer (MAC) address**. IPv4 learns it with **ARP**, a separate protocol with its own EtherType that sits beside IP. IPv6 has no ARP. It uses **Neighbor Discovery (ND)**, defined in RFC 4861, whose messages are ICMPv6 packets (Next Header 58) carried inside ordinary IPv6 packets. RFC 4861 describes ND as the combination of three IPv4 mechanisms: ARP, ICMP Router Discovery and ICMP Redirect. This answer covers the ARP part, **address resolution**. Two ND messages do the work: - **Neighbor Solicitation (NS)**, ICMPv6 type 135 — "whoever holds this target address, tell me your link-layer address". - **Neighbor Advertisement (NA)**, ICMPv6 type 136 — "the target is mine, and here is my link-layer address". ## The exchange on the wire Take laptop A at `2001:db8:42:1::10` (MAC `00:00:5e:00:53:10`) sending its first packet to B at `2001:db8:42:1::20` on the same link. 1. A creates a neighbour cache entry for B in state `INCOMPLETE`, queues the packet, and builds an NS whose **Target Address** is `2001:db8:42:1::20`. 2. The NS goes to B's **solicited-node multicast address**: the fixed prefix `ff02::1:ff00:0/104` followed by the low 24 bits of the target, here `ff02::1:ff00:20`. On Ethernet, RFC 2464 maps an IPv6 multicast address to a MAC made of `33:33` plus the address's last four bytes, so the frame goes to `33:33:ff:00:00:20`. 3. Because the NS is multicast, A **must** include its own MAC in a **Source Link-Layer Address** option, so B can answer without asking back. 4. B, which joined that group when it configured its address, answers with a **unicast NA** to A, carrying its MAC in a **Target Link-Layer Address** option, with the **Solicited** flag set and normally the **Override** flag set. 5. A marks B `REACHABLE` and sends the queued packet. If no answer comes, A retries; RFC 4861's defaults are 3 multicast solicitations (`MAX_MULTICAST_SOLICIT`) one second apart (`RETRANS_TIMER`). Every ND message is sent with **Hop Limit 255**, and receivers discard ND messages that arrive with anything less. That proves the sender is on the link: a packet forwarded by a router would have been decremented. ## Why multicast instead of broadcast IPv6 has no broadcast address; all-nodes `ff02::1` is the nearest thing, and address resolution avoids it. The solicited-node group is the point: - An ARP request goes to `ff:ff:ff:ff:ff:ff`, so **every** host on the segment hands it up to its network stack, including hosts that do not run IPv4. - An NS goes to one of 2^24 (about 16 million) groups. Only hosts holding an address with the same low 24 bits joined it — on a normal LAN, the target alone — and other network cards typically filter the frame in hardware. - A switch without MLD snooping still floods the frame to every port, so the saving is in interrupts on hosts, not in bandwidth on the wire. - Addresses that differ only in their prefix share a group, so a host with several global addresses built on one interface identifier joins one group, not several. ## After the answer: the neighbour cache ND keeps more state than ARP because it also runs **Neighbor Unreachability Detection (NUD)**: | State | Meaning | |---|---| | `INCOMPLETE` | NS sent, no answer yet | | `REACHABLE` | reachability confirmed recently (base `REACHABLE_TIME` 30 s, randomised between 0.5 and 1.5 times) | | `STALE` | not confirmed lately; still used, but not probed until traffic is sent | | `DELAY` | traffic sent to a stale entry; waiting up to 5 s for an upper-layer hint such as TCP acknowledgements | | `PROBE` | unicast NS sent to confirm; after 3 unanswered the entry should be deleted | Confirmation comes either from a solicited NA or from upper-layer progress, so a busy TCP connection needs no extra probes. As RFC 4861 notes, IPv4 has no generally agreed mechanism that notices a neighbour has vanished; ND detects half-broken links and neighbours whose MAC changed. ## ARP vs Neighbor Discovery | | IPv4 ARP | IPv6 Neighbor Discovery | |---|---|---| | Carried in | its own link-layer protocol | ICMPv6 inside IPv6 | | Request sent to | link broadcast | solicited-node multicast | | Off-link senders kept out by | ARP frames are never routed | the Hop Limit 255 check, since ND rides routable IPv6 | | Reachability tracking | none in the base protocol | NUD state machine | | Cryptographic option | none | SEND (RFC 3971) | Living inside IP also lets ND use IP-layer security mechanisms, which is what SEND later did. ## Common confusions - The Hop Limit check does not stop a host **on the link** from forging an NA; that forgery is the IPv6 twin of ARP spoofing. - In normal resolution the NA is unicast to the solicitor. It is multicast to all-nodes when the solicitation came from the unspecified address (during duplicate address detection) or when a node announces a changed MAC unsolicited. - The solicited-node group carries ND traffic only; ordinary traffic still goes to the unicast address.
- Why must an IPv6 Neighbor Solicitation carry the sender's MAC when it is multicast, but not necessarily when it is unicast?A multicast solicitation reaches a target that may have no cache entry for the sender, so RFC 4861 makes the Source Link-Layer Address option mandatory: it gives the target an address to unicast its advertisement to. A unicast solicitation, used to confirm reachability, comes from a node that already holds the target's MAC, so the target very likely has the sender cached too; the option may be omitted.
- What does Neighbor Discovery's Hop Limit 255 requirement protect against, and what does it not?A router decrements the hop limit, so an ND message arriving at 255 cannot have been forwarded; receivers discard any lower value. That stops a sender elsewhere on the internet from injecting advertisements or redirects. It does nothing against a device on the same link, which sends at 255 legitimately; that needs SEND or filtering at the switch.
ARP is shouting a name across the whole office floor so everyone looks up. Neighbor Discovery is calling a pager channel shared only by people whose badge number ends in the same six digits: the person you want hears it, and almost nobody else is disturbed.
saying these in an interview costs you the question
- IPv6 still uses ARP, just with longer addresses.
- Neighbor Solicitations are broadcast to every host on the link.
- Address resolution sends the solicitation to all-nodes ff02::1.
- Neighbor Discovery is a separate protocol beside IPv6, as ARP is beside IPv4.
- The Hop Limit 255 check stops spoofed advertisements from hosts on the same link.