Networking · Concept · 13 min read

ARP Explained, and the One Thing Everyone Gets Wrong About It

Two packets, one broadcast and one reply, and a cache that lasts a couple of minutes. Here is the exchange, the case people misread, and the attack a protocol from 1982 cannot defend against.

Written by Marko Ristic, Editor Updated Sep 23, 2026
2Packets in the whole exchange, a request and a reply
48Bits in the MAC address it goes looking for
0Routers an ARP request will ever cross
0Authentication in the protocol, which is the security story
Short answer

ARP finds the MAC address that belongs to an IP address on the local network. A host broadcasts a request asking who holds the address, the owner replies with its MAC, and both sides cache it. A packet headed off the network makes the host resolve the gateway, not the destination.

  • The request is a broadcast, the reply is a unicast to the asker
  • Cache entries last seconds to minutes, not forever
  • ARP never crosses a router, because broadcasts do not
  • A remote destination produces an ARP request for the gateway
  • There is no authentication, which is what makes spoofing trivial
On this page

Why it existsThe two address problem

ARP explained properly starts with why every network device carries two addresses that identify it. They exist for different reasons and neither one can do the other job.

The MAC address is burned into the hardware. It is 48 bits, it identifies one network interface, and it does not change when the device moves. Switches forward data using it, and a MAC address has no structure that says anything about where the device is. It is a hardware address, and nothing more.

The IP address describes where the device is. It is assigned, it changes when the device moves to a different network, and the structure of these addresses is what makes routing possible.

The two addresses also sit at two different layers. A frame of data on an Ethernet network is addressed at layer 2 to a MAC address, while the IP address it carries is a layer 3 address.

No device on the local network forwards a frame based on an IP address, because switches do not read past the layer 2 header.

So a host that wants to send data to 10.0.5.20 has the IP address and needs the MAC address, and address resolution is the mechanism that turns one of these addresses into the other.

ARP is what joins the two layers, which is why it is usually called a layer 2 protocol even though the question it answers is about a layer 3 address.

The two addresses are not related in any way. There is no arithmetic that produces one from the other, no registry of known mappings to look them up in, and no way to know the answer without asking. That is why the Address Resolution Protocol works by broadcasting a question to every device on the network.

The exchangeThe exchange, step by step

Four steps, and the first one is the one that runs most of the time.

Check the cache. The host keeps a table of known IP to MAC mappings it has already learned. If the address is there and has not expired, no ARP traffic happens at all. This is the normal case for almost all communication between devices on the network.

Broadcast the request. If the cache holds no known entry, the host sends an ARP request to the broadcast MAC address, so every device on the LAN receives it. The request says, in effect, who has 10.0.5.20, tell 10.0.5.11.

The owner replies, and only the owner. The machine configured with 10.0.5.20 answers with a unicast ARP reply carrying its MAC address, addressed directly back to the asker. Every other machine on the network received the question, saw an address that was not theirs, and ignored it.

Both sides cache the result. The asker stores the mapping it just learned. The replier also stores the asker's mapping, which it read out of the sender fields in the request, because communication that has started in one direction is about to go in the other.

who has 10.0.5.20?  tell 10.0.5.11     broadcast, everyone receives it
10.0.5.20 is at 00:1b:21:3c:9f:0a      unicast, only 10.0.5.11 receives it

The whole address resolution is two packets and takes under a millisecond on a local network. It happens once per destination per cache lifetime, which is why the protocol is invisible until something goes wrong with it.

Inside an ARP packet

RFC 826 gives both message types one format, and the field names describe the protocol better than any summary of it does. Nine fields, and no others.

FieldWhat it holds
Hardware address space1 for Ethernet
Protocol address space0x0800 for IPv4
Hardware address length6, the length of a MAC address
Protocol address length4, the length of an IPv4 address
Opcode1 for a request, 2 for a reply
Sender hardware addressThe MAC address of the device sending this packet
Sender protocol addressThe IP address of the device sending this packet
Target hardware addressEmpty in a request, since that is what is being asked for
Target protocol addressThe IP address whose MAC address is wanted

Two things follow from that layout. The protocol is not tied to IP over Ethernet: the hardware and protocol address space fields exist so the same address resolution can run over other pairings, and IPv4 over Ethernet is the combination that survived.

And every ARP packet carries the sender hardware address and the sender protocol address, which is why the device that answers already holds the asker's mapping without having to ask for it. Those two fields are a free cache entry for anything on the network segment that reads the packet.

They are also the two fields an attacker fills in with whatever they like, because nothing in the format carries proof that the sender owns either address. That is ARP explained down to the last field, and there is nothing else in the protocol to appeal to.

The cacheThe cache, and why entries expire

An ARP cache entry is a known mapping that was true when it was made. Entries expire because the mapping can change: a device can be replaced, a virtual machine can move, a failover can hand an IP address to different hardware.

Lifetimes are short and vary by platform, from tens of seconds to a few minutes, and every implementation refreshes an entry that is actively in use rather than dropping a working conversation. The exact numbers matter less than the principle: the cache is a performance optimization with an expiry, not a source of truth.

Two commands read it, and they are worth knowing because a stale entry is a real failure mode.

PlatformRead the cacheClear one entry
Windowsarp -aarp -d 10.0.5.20
macOSarp -asudo arp -d 10.0.5.20
Linuxip neighbor showsudo ip neigh del 10.0.5.20 dev eth0

A cache holding the wrong MAC address for an IP produces a very specific symptom: data to that one device fails while communication with every other device works, and it starts working again a few minutes later without anyone doing anything.

Clearing the entry fixes it immediately, and the underlying cause is usually a device that took over an address without announcing it.

The gateway caseWhat happens when the destination is not local

This is the part that is most often misunderstood, and understanding it explains a large share of routing behavior.

A host that wants to send a packet first decides whether the destination is on its own network, by applying its subnet mask to both its own address and the destination. Two different answers lead to two different behaviors.

The destination is local. Resolve the destination address with ARP, and send the data straight to it.

The destination is not local. ARP for the default gateway, and send the frame to the gateway's MAC address, with the destination IP address still intact inside it.

That second case is the one worth sitting with. A packet from your laptop to a web server on the other side of the world leaves your LAN in a frame addressed to your router's MAC address, and the IP header still names the web server.

The router receives the frame because it is addressed to it, reads the IP header, and forwards the packet on with a new frame addressed to the next hop.

Two consequences follow.

ARP never crosses a router. An ARP request is a broadcast and routers do not forward broadcasts, so address resolution happens only within one broadcast domain. A host has no way to learn the MAC address of any device beyond its own network, and no reason to want one.

A missing gateway breaks everything at once. If the gateway does not answer ARP, the host cannot address a frame to it, so nothing leaves the local network. Local traffic keeps working perfectly, which is exactly the pattern that sends people looking at the wrong thing.

Two variationsGratuitous ARP and proxy ARP

Beyond the two ordinary message types, the request and the reply, two variations show up often enough to be worth naming. Both look like anomalies until you know what they are.

Gratuitous ARP is an announcement rather than a question. A device broadcasts an ARP message about its own addresses, which nobody asked for. It has two legitimate uses.

On startup, it checks whether anybody else replies, which detects a duplicate address. On a failover, it tells every device on the network to update its cache immediately, so data follows the address to the new hardware rather than waiting for caches to expire. Any high availability pair that moves a shared IP address does this.

Proxy ARP is a router answering on behalf of another device. The router replies to an ARP request for an address that is not its own, giving its own MAC address, so the asking host sends the data to the router and the router forwards it.

It exists to let a host reach something outside its network without a correct default gateway or subnet mask. It works, it hides configuration errors, and it is disabled by default on most modern equipment for exactly that reason.

SpoofingARP spoofing, and what actually stops it

The Address Resolution Protocol was designed in 1982 for a network where every device was trusted, and it shows. There is no authentication of any kind: a reply is believed because it arrived.

That produces a straightforward attack. An attacker on the LAN sends unsolicited ARP replies claiming that the gateway's IP address belongs to the attacker's MAC address. Neither of the two message types carries any proof of who sent it.

Every device that receives one updates its cache, and from then on it sends all of its outbound data to the attacker, who forwards it on to the real gateway.

Communication keeps flowing, nothing breaks, and the attacker sits in the middle of every connection. Doing it in both directions puts them between two specific hosts on the network.

ARP spoofing attacks are trivial to run with off the shelf tools and entirely local: they require a foothold on the same broadcast domain, which is the one real limit. ARP security is therefore a property of the network hardware rather than of the endpoint devices.

Four things reduce it, in rough order of usefulness.

ControlStops the attackEffort
Dynamic ARP inspectionYes, this is the real answerManaged switches, and DHCP snooping first
Smaller broadcast domainsNo, limits the reachA VLAN plan you probably want anyway
Static ARP entriesFor the few addresses you setManual, so a handful of systems only
Encryption everywhereNo, removes the valueAlready done for most traffic

Dynamic ARP inspection on the switches. The switch watches DHCP assignments, builds a table of which address belongs on which port, and discards ARP replies that contradict the known mapping. This is the actual answer to these attacks, and it is a feature of managed switches.

Smaller broadcast domains. These attacks reach only the local LAN segment, so a network split into VLANs by role limits how far any single compromise reaches.

Static ARP entries for the devices that matter. A permanent mapping for a gateway or a critical server cannot be overwritten by a reply. It also has to be maintained by hand, which is why it belongs on a handful of systems rather than everywhere.

Encryption everywhere. It does not prevent the interception and it removes most of the value. An attacker in the middle of a TLS connection sees the destination and the timing, and none of the data.

Notice what is not on that list: no endpoint security product on an individual device is very effective here, because the protocol has no way to tell a real reply from a fake one. The switch is the only thing on the network segment in a position to know which mapping is legitimate.

PitfallsWhere people go wrong

Expecting a host to ARP for a remote address. It never does. Anything off the local network produces an ARP request for the gateway instead, and a capture full of gateway requests is normal.

Blaming ARP for a routing problem. Address resolution happens within one network. If two devices are on different subnets and cannot communicate, the question is about the router, not about ARP.

Trusting the cache during a failover. A machine that has an old mapping keeps using it until the entry expires or a gratuitous ARP arrives. If the failover does not send one, the outage lasts as long as the cache does.

Assuming a duplicate IP address will announce itself. It often produces intermittent failures instead: whichever of the two devices replied to the last ARP request receives the traffic, and it alternates.

Filtering the protocol as a security measure. Blocking it stops every device on the local network communicating. The control that helps is dynamic ARP inspection, which validates rather than blocks.

Looking for ARP on IPv6 networks. It is not there. IPv6 uses Neighbor Discovery, which runs over ICMPv6 and uses multicast rather than broadcast, so the information reaches only interested devices.

Treating a full ARP table as a problem. A cache with hundreds of devices in it on a busy server is normal. A cache with entries that keep changing for the same address is the information worth looking at.

THE SAME LAPTOP, TWO DESTINATIONS, TWO DIFFERENT ARP REQUESTSDESTINATION ON THE SAME LANLAPTOPwho has 10.0.5.20?THE MACHINE ITSELFit replies with a MACFRAME GOES DIRECTDESTINATION ON THE INTERNETLAPTOPwho has 10.0.5.1?THE GATEWAY, NOT THE SERVERrouter repliesFRAME TO THE ROUTERIP still names the serverThe laptop never learns the web server MAC address, and has no reason to want it.An ARP request is a broadcast, and routers do not forward broadcasts, so it never leaves the LAN.Which is why a gateway that stops answering ARP breaks everything outward while local traffic works.
The two cases side by side. The second row is the one that surprises people, and it explains most of what a capture of a quiet machine contains.

ComparisonThree lookups, and the one that never leaves the local network

CriterionARPDNSNeighbor Discovery
TranslatesIP to MACName to IPIPv6 to MAC
ScopeOne broadcast domainGlobalOne link
Uses broadcastYesNoNo, multicast
Runs onEthernet directlyUDP and TCP 53ICMPv6
Has a cache with a timeoutYesYesYes
Authenticates the answerNoOnly with DNSSECOnly with SEND, rarely used
Works across a routerNoYesNo

The last row is the whole shape of the protocol. ARP answers a local question about one LAN, which is why it is invisible most of the time and why every problem it causes is a problem on one network segment.

FAQFrequently asked questions

What is ARP?

The Address Resolution Protocol, which finds the MAC address belonging to an IP address on a local network. It is what lets a host address a layer 2 frame to a destination device it only knows by its layer 3 IP address.

How does ARP work?

The host checks its cache, and if there is no entry it broadcasts a request to every device on the LAN asking who holds the address. The device that holds it replies with its MAC address, and both sides cache the result.

Does ARP work across a router?

No. An ARP request is a broadcast and routers do not forward broadcasts, so ARP only resolves addresses within one broadcast domain.

What does a host do when the destination is on another network?

It sends an ARP request for its default gateway and addresses the frame to the gateway's MAC address, with the destination IP address still in the packet.

How long do ARP cache entries last?

Seconds to a few minutes depending on the platform, with entries in active use refreshed rather than dropped. The cache holds an optimization with an expiry, not authoritative information.

How do I see the ARP cache?

arp -a on Windows and macOS, ip neighbor show on Linux. Clearing a stale entry is a legitimate fix when traffic to one host fails while everything else works.

What is gratuitous ARP?

An unsolicited announcement about a host's own address. It detects duplicate addresses at startup and, more usefully, tells every device to update its cache the moment an address moves to different hardware during a failover.

What is proxy ARP?

A router answering an ARP request for an address that is not its own, so traffic comes to it and it forwards on. It hides configuration mistakes and is disabled by default on most modern equipment.

What is ARP spoofing?

Sending fake ARP replies so that other devices send their traffic to the attacker instead of the real destination. It works because the sender hardware address and sender protocol address fields carry no proof of ownership, and it requires a foothold on the same LAN.

How do I prevent ARP spoofing?

Dynamic ARP inspection on managed switches is the real control. Smaller broadcast domains reduce the reach, static entries protect a few critical mappings, and encryption removes most of the value of succeeding.

Does IPv6 use ARP?

No. IPv6 replaces the protocol with Neighbor Discovery, which runs over ICMPv6 and uses multicast, so it reaches only the interested devices instead of every device on the LAN.

Why does traffic to one host fail while everything else works?

Frequently a stale or wrong ARP cache entry for that host. It resolves by itself when the entry expires, which is what makes it confusing to diagnose.

What causes a duplicate IP address to behave strangely?

Two machines answering ARP requests for the same address. Whichever replied most recently receives the traffic, so the failure moves between them rather than being consistent.

What does ARP mean?

The ARP meaning is Address Resolution Protocol. It is how a device that knows a neighbor's IP address finds that neighbor's MAC address, by broadcasting a question on the local network and caching the answer.

Read next · Addressing What Is a Subnet? The mask is what decides whether a host ARPs for the destination or for the gateway, so a wrong mask changes the question it asks. Open this next15 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.