skip to content

ARP

ARP maps an IPv4 next hop to the MAC address that receives the frame, by broadcast and cache. It is small, unauthenticated and trusted, which is why interviewers pair it with spoofing.

on this pageshow

explore

questions

23

In IPv4 over Ethernet, what is the ARP cache, what does each entry hold, and why does a host keep one?

level: juniorimportance: must knowfreq 55%

answer

  1. a frame needs a destination MAC
  2. one broadcast, then remembered
  3. next hop, not final destination
  4. the target learns the asker too

basics

~10 s

The ARP cache is a host's table of IPv4-address-to-MAC-address mappings for neighbours on the same link. Keeping resolved mappings lets the host build Ethernet frames without broadcasting an ARP request before every packet.

solid answer

~40 s

To put an IPv4 packet on Ethernet, a host needs the MAC address of the **next hop**: the destination itself when it is on the local subnet, the default gateway otherwise. ARP (RFC 826) finds it with a broadcast request and a unicast reply, and the cache keeps the answer so later packets leave immediately. An entry maps one IPv4 address to one MAC address on one interface; implementations add an age or state and a dynamic-or-static flag. RFC 826 also has the *target* of a request store the requester's mapping before it replies, because the two hosts are likely to talk in both directions. Entries are not permanent: RFC 1122 requires a mechanism to flush out-of-date ones.

go deeper

for a junior

Recall why the cache exists: Ethernet needs a destination MAC, ARP finds it with one broadcast, and the cache stops that broadcast repeating for every packet. Know that remote destinations resolve to the gateway.

for a middle

Walk through RFC 826's receive algorithm: the merge of a known sender before the target check, and the target adding the requester. Explain what an entry holds and which parts are implementation additions.

for a senior

Connect the merge rule to operations: it is why a changed MAC spreads to peers that overhear a broadcast, and why ARP trusts whatever arrives. Expect to reason about which hosts hold an entry for whom.

for a principal

Frame the cache as a trade between broadcast load and staleness on a shared link, and note that the protocol left lifetime and trust entirely to implementers, which shapes every later hardening choice.

## Why a cache exists at all An IPv4 packet travelling on Ethernet is carried inside a frame, and the frame needs a **destination MAC address** in its header. IP knows only the IPv4 address of the next hop, so something has to translate one into the other. That translator is the **Address Resolution Protocol** (ARP, RFC 826): the sender broadcasts a request to `ff:ff:ff:ff:ff:ff` asking "who has this IPv4 address?", and the owner answers with a unicast reply carrying its MAC. Doing that before every packet would be wasteful in three ways: - every host on the link would have to receive and process a broadcast for every packet anyone sends; - every packet would wait a full request-reply round trip before leaving; - a busy host would flood the link with requests, which RFC 1122 explicitly requires implementations to prevent. So a host remembers each answer in the **ARP cache** (RFC 826 calls it the translation table) and consults it first. Only a miss triggers a request. ## What an entry holds RFC 826 describes the stored item as a triplet: protocol type, sender protocol address, sender hardware address. In practice an entry looks like this: | Part | Meaning | Defined by | |---|---|---| | IPv4 address | the neighbour's protocol address | RFC 826 | | MAC address | the neighbour's 48-bit hardware address | RFC 826 | | Protocol type | `0x0800` for IPv4, the IPv4 EtherType | RFC 826, value from RFC 894 | | Interface | which link the neighbour sits on | implementation | | Age or state | how recently it was learned or confirmed | implementation | | Dynamic or static | learned from ARP, or configured by hand | implementation | The last three columns are not in the protocol at all. RFC 826 left ageing "outside the scope of this protocol", and the state names some systems display are borrowed from IPv6 Neighbor Discovery. That is why two operating systems can show the same cache very differently. ## How entries get in RFC 826's receive algorithm is the heart of the cache, and it is more generous than most people expect. When any ARP packet, request or reply, arrives: 1. If the sender's IPv4 address is **already** in the table, its MAC is overwritten with the one in the packet (the "merge"). 2. If this host is the **target** of the packet and there was no entry, the sender's mapping is **added**. 3. Only then is the opcode examined; a request addressed to this host gets a reply. Two consequences follow. The host that *answers* a request learns the asker's mapping for free, on the assumption that "if A has some reason to talk to B, then B will probably have some reason to talk to A", so B never has to ARP back. And any host that already knows the sender refreshes that knowledge from any broadcast it overhears, which is how a changed MAC can spread without anyone asking for it. ## Only next hops appear A common surprise: a laptop that has been talking to a dozen internet servers has none of them in its ARP cache. ARP works only on one link. For an off-subnet destination the host looks up its routing table, finds the gateway, and resolves the **gateway's** MAC; every frame to every remote server carries that same destination MAC, while the IP header carries the server's address. So the cache of a typical client holds the gateway plus whichever local peers it has talked to. ## Entries do not live forever RFC 826 only suggested ageing. RFC 1122 §2.3.2.1 made it a MUST: an implementation has to provide a mechanism to flush out-of-date entries, because a mapping can go wrong when a host changes its hardware or when a router answers on another host's behalf. How long an entry lives is an implementation choice; the protocol fixes no number. ## Misunderstandings worth correcting - The cache belongs to each host and router, not to the switch. A switch keeps a separate MAC address table mapping MACs to ports, and it does not use IPv4 addresses to build it. - ARP maps IPv4 addresses to MAC addresses; mapping names to IPv4 addresses is DNS's job. - An entry is learned from requests as well as replies, as the receive algorithm above shows. - IPv6 has no ARP; it resolves neighbours with Neighbor Discovery, which keeps a Neighbor Cache of its own.

  • Why does a host's ARP cache not contain entries for the internet servers it talks to?
    ARP resolves addresses only on the local link. For an off-subnet destination the routing table names the gateway as next hop, so the host resolves the gateway's MAC and sends every remote-bound frame there. The server's IPv4 address stays in the IP header; its MAC is never needed and never learned.
  • Why does RFC 826 have the target of a request add the requester's mapping before it replies?
    Communication is usually two-way: if A asks for B, A is about to send B something and B will soon answer. Storing A's mapping from the request saves B a broadcast request of its own. The merge happens before the opcode is even checked, so the same step serves requests and replies.

saying these in an interview costs you the question

  • The ARP cache holds MAC addresses for remote internet servers too.
  • The switch stores the ARP cache for every host on the LAN.
  • ARP maps hostnames to IPv4 addresses.
  • Only ARP replies add entries; a received request teaches nothing.
  • Once learned, an ARP entry stays valid until the host reboots.
open as a page

In IPv4 ARP, what is a gratuitous ARP, what do its address fields contain, and why would a host send one?

level: juniorimportance: must knowfreq 38%

basics

~20 s

A gratuitous ARP is an unsolicited, broadcast ARP packet whose sender and target IP fields both hold the sender's own IPv4 address. It tells the link which MAC now owns that address, so peers overwrite stale cache entries.

open as a page

In IPv4, what is proxy ARP, and how does a router answering ARP for a remote host make that host appear on-link?

level: juniorimportance: must knowfreq 30%

basics

~20 s

Proxy ARP is a router answering an ARP request for a host on another network with its own MAC address. The asker caches that mapping and sends the frames to the router, which routes them onward.

open as a page

When an IPv4 host sends a packet to an address outside its own subnet, whose MAC address does its ARP request ask for, and why?

level: juniorimportance: must knowfreq 64%

basics

~10 s

The default gateway's. The mask marks the destination off-link, so the host ARPs for the gateway's IPv4 address; the frame goes to the gateway's MAC while the IPv4 header still names the remote destination.

open as a page

In IPv4 over Ethernet, how does ARP find a neighbour's MAC address, and why is the request broadcast but the reply unicast?

level: juniorimportance: must knowfreq 76%

basics

~20 s

ARP broadcasts a request naming the wanted IPv4 address; the owner answers with a unicast reply carrying its MAC, sent to the requester's MAC copied from the request. The requester caches the mapping, then sends the waiting frame.

open as a page

In IPv4 ARP, why can any host on the same Ethernet segment overwrite another host's IP-to-MAC entry, and what does that let it do?

level: juniorimportance: must knowfreq 62%

basics

~20 s

ARP carries no authentication, and RFC 826's receive algorithm overwrites an existing entry from any packet's sender fields before reading the opcode. Any host on the segment can therefore claim another's IP and draw its traffic.

open as a page

When an active/standby pair moves a virtual IPv4 address to the standby, how does the standby's gratuitous ARP redirect LAN hosts and Ethernet switches?

level: middleimportance: must knowfreq 33%

basics

~20 s

The new holder broadcasts an ARP Announcement for the virtual IP. Hosts that cached the address overwrite its MAC, and every switch relearns the frame's source MAC on the new port, so traffic shifts without waiting for timeouts.

open as a page

How do ARP cache entries age out in IPv4, what do RFC 826 and RFC 1122 each require, and how do static entries differ?

level: middleimportance: should knowfreq 40%

basics

~20 s

RFC 826 sets no lifetime; RFC 1122 requires a mechanism to flush out-of-date entries, with a configurable timeout if one is used. Dynamic entries age out and are re-resolved; static entries are configured by hand and never age.

open as a page

Some systems label IPv4 ARP entries INCOMPLETE, REACHABLE, STALE, DELAY or PROBE: where do these states come from, and what does each mean?

level: middleimportance: should knowfreq 25%

basics

~20 s

They are the Neighbor Cache states of IPv6 Neighbor Discovery (RFC 4861), reused for ARP by some implementations: INCOMPLETE while resolving, REACHABLE after recent confirmation, STALE once that lapses, then DELAY and PROBE to re-verify an entry in use.

open as a page

An IPv4 host misconfigured with a /16 mask on a /24 subnet still reaches neighbouring /24s; how does proxy ARP hide the error?

level: middleimportance: should knowfreq 24%

basics

~20 s

A /16 mask makes the host treat other /24s as on-link, so it ARPs for those hosts directly. A proxy-ARP router answers with its own MAC and routes the traffic, so everything works until proxy ARP goes away.

open as a page

In ARP over Ethernet as RFC 826 defines it, what fields does the packet carry, and how do a request and its reply fill them?

level: middleimportance: should knowfreq 36%

basics

~20 s

Hardware type 1, protocol type 0x0800, lengths 6 and 4, an opcode (1 request, 2 reply), then sender MAC and IPv4 address and target MAC and IPv4 address. The reply swaps the pairs and answers in its sender fields.

open as a page

In ARP cache poisoning for a man-in-the-middle position, why must the attacker poison both the victim's entry for the gateway and the gateway's entry for the victim?

level: middleimportance: should knowfreq 42%

basics

~20 s

Each host resolves MACs from its own cache. Forging only the victim's entry diverts outbound frames while the gateway's replies still go straight back, so the attacker sees half the conversation; both entries must name the attacker's MAC.

open as a page

When an IPv4 server's NIC is replaced and its MAC changes, why can some peers' ARP caches keep it unreachable for minutes, and how do you clear it?

level: seniorimportance: should knowfreq 35%

basics

~20 s

Peers that cached the old MAC keep sending frames to it, and Ethernet reports no loss. Each recovers only when an ARP packet from the server reaches it, its own ageing or probing drops the entry, or someone flushes it.

open as a page

After an IPv4 failover the new holder sent gratuitous ARPs, yet some hosts on the same LAN keep sending to the old MAC for minutes; what in ARP explains it?

level: seniorimportance: should knowfreq 22%

basics

~20 s

Gratuitous ARP only works if each receiver accepts it. Hosts hardened to ignore unsolicited ARP, announcements lost or sent too early, or an old holder still answering leave caches stale until each host's own entry ages out.

open as a page

An IPv4 router has proxy ARP enabled on every interface by default; what risks does that carry, and how do you judge turning it off?

level: seniorimportance: should knowfreq 14%

basics

~20 s

Default proxy ARP is an implementation choice, not an RFC rule. It hides wrong host configuration, silently routes traffic through the router and blurs spoofing signals; disable it where nothing designed depends on it, expecting failures as caches expire.

open as a page

An IPv4 host reaches peers on its own subnet but nothing beyond it; what can the ARP traffic on its segment tell you about where the fault lies?

level: seniorimportance: should knowfreq 31%

basics

~20 s

Read what the host asks for. Unanswered gateway requests implicate the gateway or the path to it; requests for remote addresses mean a too-wide mask; an unexpected or duplicate reply means another station claims the gateway.

open as a page

On an IPv4 Ethernet segment, which ARP-level observations point to cache poisoning, and why is each one only a hint rather than proof?

level: seniorimportance: should knowfreq 28%

basics

~20 s

Hints: a gateway IP whose MAC changes or flips, one MAC claiming many IPs, replies with no request, and hosts reporting their address claimed elsewhere. Each has lookalikes such as failover, proxy ARP and NIC replacement.

open as a page

How does Dynamic ARP Inspection on an Ethernet switch decide to drop a forged ARP packet, and what does it depend on?

level: seniorimportance: should knowfreq 36%

basics

~20 s

Dynamic ARP Inspection is a switch feature that checks ARP packets on untrusted ports against a binding table of valid IP-MAC pairs, usually learned from DHCP, and drops mismatches. It needs a complete table and correct trusted ports.

open as a page

While an IPv4 ARP resolution is pending, what must a host or router do with waiting packets, and when may it report failure?

level: middleimportance: nice to knowfreq 15%

basics

~20 s

RFC 1122: keep at least the latest packet per unresolved address, send it once resolved, rate-limit requests, and never report Destination Unreachable just for a missing entry. RFC 1812: a router reports Host Unreachable only after resolution fails.

open as a page

Beyond covering for a wrong subnet mask, where is IPv4 proxy ARP still a deliberate part of a network design?

level: middleimportance: nice to knowfreq 10%

basics

~20 s

Proxy ARP is designed in wherever hosts will ARP for an address that is deliberately not on their segment: Mobile IPv4 home agents, Basic NAT pools from the LAN's subnet, private VLANs, VPN pools numbered from the LAN, and historic transparent subnetting.

open as a page

In RFC 826's ARP, what do receivers do with a broadcast request, and why is the sender's mapping merged before the opcode is read?

level: middleimportance: nice to knowfreq 20%

basics

~10 s

Receivers already holding an entry for the sender's IPv4 address overwrite its MAC; only the target adds a new entry and replies. RFC 826 merges before reading the opcode because traffic is assumed bidirectional.

open as a page

For ARP spoofing on a shared segment, what do static ARP entries and private-VLAN port isolation each stop, and what does each cost to operate?

level: middleimportance: nice to knowfreq 22%

basics

~20 s

A static entry pins one host's mapping against forged packets but protects only that host and needs editing when a MAC changes. Port isolation stops peers reaching each other at Layer 2, containing poisoning but not the path to the gateway.

open as a page

Under RFC 5227 IPv4 address conflict detection, how does an ARP Probe differ from an ARP Announcement, and why does the probe carry sender IP 0.0.0.0?

level: seniorimportance: nice to knowfreq 14%

basics

~10 s

An ARP Probe asks whether an IPv4 address is free, with sender IP 0.0.0.0 so it cannot overwrite anyone's cache; an ARP Announcement then claims it, with sender IP equal to target IP.

open as a page