EMZETT.
Login

ARP

In short: Address Resolution Protocol — resolves a known IP address in the local network to the associated MAC address.

In more detail: IP addresses are logical (layer 3), MAC addresses physical (layer 2) — to actually deliver a packet in the local network, a device has to know the target’s MAC address. To do this, ARP asks “Who has IP X.X.X.X?” via broadcast and remembers the answer in the ARP cache. Vulnerable to ARP spoofing (see Spoofing).

In Depth

The procedure step by step

A device that wants to send a packet to a specific IP address in the same local network but doesn’t yet know its MAC address sends an ARP request message as a broadcast to all devices in the segment:

ARP Request:  Who has 192.168.1.10? Tell 192.168.1.5 (aa:bb:cc:dd:ee:ff)
ARP Reply:    192.168.1.10 is at 11:22:33:44:55:66

Only the device with the matching IP replies directly (unicast) with its MAC address; all other devices in the segment silently ignore the request. The requesting device then stores the result for a limited time (typically a few minutes) in the local ARP cache, viewable on Windows and Linux via arp -a or ip neigh, so that it doesn’t have to ask again for every single packet. When the entry expires, the process repeats automatically when needed.

Gratuitous ARP

A special case is “gratuitous ARP”: here a device sends an ARP message unsolicited (i.e. without a prior request) announcing its own IP-to-MAC mapping. This typically happens at system start-up, after an IP address change, or in high-availability setups in which a server takes over an already assigned IP address in the event of a failover and asks all other devices on the network to update their ARP cache immediately, instead of waiting for the old entry to expire naturally.

ARP spoofing as an attack vector

It’s precisely the missing authentication mechanism that makes ARP vulnerable: since every device on the network can claim unsolicited “this IP belongs to my MAC address” (without any real request having preceded it), an attacker can use ARP spoofing (also called ARP poisoning) to send forged replies and thereby divert traffic actually intended for another client or the gateway to their own device. This is the technical basis of many man-in-the-middle attacks in local networks: the attacker poses as the gateway to the victim AND as the victim to the gateway, routes the entire data traffic through themselves and can read or manipulate it before passing it on (usually unchanged) so that the attack goes unnoticed.

Protective measures

ARP itself has no authentication built in at all — in practice, protection doesn’t come from the protocol itself but from switch features such as Dynamic ARP Inspection (DAI), which checks ARP replies against a known, trusted list of IP-MAC mappings and discards suspicious packets, as well as from static ARP entries for particularly critical systems (e.g. the gateway itself), which can’t be overwritten via ARP at all. Network monitoring tools can also detect duplicate or contradictory ARP replies as an alarm signal.

Replacement by NDP in IPv6

For IPv6, ARP was completely replaced by the more secure Neighbor Discovery Protocol (NDP), which builds on ICMPv6 and optionally supports cryptographic protection (SEND, Secure Neighbor Discovery) — a direct lesson from ARP’s well-known weaknesses in the IPv4 era.

See also: MAC addresses, IP addresses, Spoofing, ICMP