In IPv4, what is proxy ARP, and how does a router answering ARP for a remote host make that host appear on-link?
answer
- an agent answering for someone else
- one field differs in the reply
- asker caches a useful lie
- router then routes as usual
basics
~20 sProxy ARP is a router answering an ARP request for a host on another network with its own MAC address. The asker caches that mapping and sends the frames to the router, which routes them onward.
solid answer
~40 sA host uses its address mask to decide whether a destination is on-link; if it thinks so, it broadcasts an ARP request for that IP. With proxy ARP, a router that hears the request and has a route to the target through a *different* interface sends an ARP reply (opcode 2) whose sender protocol address is the target's IP and whose sender hardware address is the router's own MAC. The host caches `target IP -> router MAC` and frames every packet for the target to the router, which forwards it by ordinary IP routing. Nothing changes on the host — no gateway entry, no new protocol. RFC 1027 documented this in 1987 as transparent subnet gateways: the router acts as the remote host's agent.
code
pseudocode · 14 lineson ARP request R arriving on interface IN:
if R.target_ip is one of my own addresses:
reply normally; return
if R.target_ip is a broadcast address:
return # never proxy for broadcast
route = lookup(R.target_ip, ignore_default = true)
if route is none: return # cannot reach it
if route.interface == IN: return # target is on the asker's side
reply.op = 2 # ARP reply
reply.sender_mac = my_mac(IN) # the proxy's own MAC
reply.sender_ip = R.target_ip
reply.target_mac = R.sender_mac
reply.target_ip = R.sender_ip
unicast reply to R.sender_macgo deeper
Recall the one-line picture: a router answers ARP for a host that is not on the segment, using its own MAC, so traffic reaches the router and is routed on.
Walk through the reply field by field and explain why the host's on-link decision, made from its mask, is what sends it to ARP in the first place.
Explain when a proxying router must not answer, and what it means operationally that hosts depend on a router they have no configuration for.
Frame proxy ARP as moving routing knowledge out of hosts into routers: convenient for unmodifiable hosts, but it makes the path invisible to the hosts that depend on it.
## The problem proxy ARP answers An IPv4 host decides, before it sends anything, whether a destination is **on-link** or reachable only through a router. RFC 1122 §3.3.1.1 makes that a mechanical rule: apply the host's **address mask** to the destination and to its own address; if the two results match, the destination is on the connected network and the packet goes straight to it; if not, it goes to a gateway. For an on-link destination the host needs the destination's MAC address, so it broadcasts an **ARP request** (RFC 826) and waits for the owner to reply. That works only when the target really shares the segment. If the host's idea of "on-link" is wider than the physical segment — because of how the network was built or because the mask is wrong — the request is broadcast on a segment where the target is not listening, and nobody answers. **Proxy ARP** closes that gap from the router's side: a router attached to the segment answers on the target's behalf. ## What the router does, step by step 1. Host A broadcasts an ARP request (opcode 1) asking for the MAC address of host B's IPv4 address. 2. A router attached to A's segment hears the broadcast, like every other station on it. 3. The router looks up B's address in its routing table. If the route leaves through a **different interface** from the one the request arrived on, B is not on A's segment and the router can reach it. 4. The router sends an ARP reply (opcode 2) to A. The reply's sender protocol address is **B's IP address**; its sender hardware address is **the router's own MAC** on A's segment. 5. A caches the mapping *B's IP -> router's MAC* and frames every packet for B to that MAC. The IP header still says destination B. 6. The router receives the frames, strips the link-layer header and forwards the packets to B by ordinary IP routing, decrementing TTL as for any routed packet. The host never learns that a router was involved. It has no gateway entry for B, runs no new protocol and sees a perfectly ordinary ARP reply. RFC 1027 (1987) documented this as **transparent subnet gateways**, "commonly known as Proxy ARP or the ARP hack": the router acts "as an agent for host B". RFC 925 (1984) had proposed a more general multi-LAN form; RFC 1027 is the restricted version that relies only on the routers' existing routing tables. ## What goes on the wire | ARP reply field | Normal reply from B | Proxy reply from the router | |---|---|---| | Opcode | 2 (reply) | 2 (reply) | | Sender hardware address | B's MAC | the router's MAC on A's segment | | Sender protocol address | B's IP | B's IP | | Target hardware address | A's MAC | A's MAC | | Target protocol address | A's IP | A's IP | The only difference is one field. RFC 5944 §4.6 states it the same way: a proxy reply reverses the sender and target protocol addresses as usual "but supplies some configured link-layer address (generally, its own) in the Sender Hardware Address field". Because ARP carries no authentication, a receiver cannot tell a proxy reply from the real owner's. ## When a proxying router must stay silent RFC 1027's sanity checks keep the router from answering requests it should not: - **Same interface:** if the route to the target leaves through the interface the request arrived on, the router must not reply — the target is on the asker's segment and can answer itself, or another router is closer. - **No default route:** the reachability check must ignore the default route, or every request would match. - **Broadcast targets:** a request for a broadcast address gets no reply, or the asker would send real traffic to a broadcast address — the memo's "Chernobyl effect". - **Foreign networks:** if the asker and target are on different IP networks, the router should not reply, so it cannot be used to reach foreign networks around the security checks at the IP gateways. Modern implementations generally follow the same idea — answer when a route exists through another interface — but exactly which requests they answer is an implementation choice. ## The return direction and the IPv6 counterpart Proxy ARP is per direction. When B answers A, B makes its own on-link decision: if B's mask correctly says A is remote, B simply sends to its gateway; only if B also believes A is on-link does a router on B's side need to proxy for A. RFC 1027 notes the two hosts need not even share the same proxying router. IPv6 has no ARP. Its equivalent is a **proxy Neighbor Advertisement** (RFC 4861 §7.2.8), sent with the Override flag cleared so that the real node's own advertisement wins if it is present on the link.
- Under RFC 1027, when must a proxy-ARP router stay silent?When the route to the target leaves through the same interface the request arrived on, because the target is on the asker's side; when the target is a broadcast address; and when the only route is the default route, which must be ignored for this check. It also should not answer when asker and target are on different IP networks, so it cannot become a path around the IP gateways' security checks.
- If two routers on the segment both proxy for the same target, which one does the host use?RFC 1027 notes a host acts on the first reply that arrives, which it calls rudimentary load balancing. Under RFC 826's receive rule a later reply for an address already cached also updates the entry, so the path depends on reply timing either way. Neither choice is deterministic, which is one reason designs with redundant routers use explicit gateways instead.
- Can the host tell that a proxy answered rather than the real target?Not from the reply itself: ARP has no authentication and a proxy reply differs from a genuine one only in the sender hardware address. The visible clue is indirect: the host's ARP cache shows many different IP addresses mapped to the same MAC, the router's.
A receptionist who answers the phone for colleagues in the annex: callers think they reached the person, but every call actually goes to the front desk, which passes it on.
saying these in an interview costs you the question
- Proxy ARP works because the host routes the packet via its default gateway.
- The proxying router rewrites the destination IP address of forwarded packets.
- Proxy ARP is a separate protocol with its own message types.
- A proxy-ARP router answers every request it hears, even for hosts on the same segment.
- The router replies with the remote host's real MAC address.