ARP finds the MAC address that belongs to an IP address on the local network. A host broadcasts a request asking who holds the address, the owner replies with its MAC, and both sides cache it. A packet headed off the network makes the host resolve the gateway, not the destination.
- The request is a broadcast, the reply is a unicast to the asker
- Cache entries last seconds to minutes, not forever
- ARP never crosses a router, because broadcasts do not
- A remote destination produces an ARP request for the gateway
- There is no authentication, which is what makes spoofing trivial
On this page
Why it existsThe two address problem
ARP explained properly starts with why every network device carries two addresses that identify it. They exist for different reasons and neither one can do the other job.
The MAC address is burned into the hardware. It is 48 bits, it identifies one network interface, and it does not change when the device moves. Switches forward data using it, and a MAC address has no structure that says anything about where the device is. It is a hardware address, and nothing more.
The IP address describes where the device is. It is assigned, it changes when the device moves to a different network, and the structure of these addresses is what makes routing possible.
The two addresses also sit at two different layers. A frame of data on an Ethernet network is addressed at layer 2 to a MAC address, while the IP address it carries is a layer 3 address.
No device on the local network forwards a frame based on an IP address, because switches do not read past the layer 2 header.
So a host that wants to send data to 10.0.5.20 has the IP address and needs the MAC address, and address resolution is the mechanism that turns one of these addresses into the other.
ARP is what joins the two layers, which is why it is usually called a layer 2 protocol even though the question it answers is about a layer 3 address.
The two addresses are not related in any way. There is no arithmetic that produces one from the other, no registry of known mappings to look them up in, and no way to know the answer without asking. That is why the Address Resolution Protocol works by broadcasting a question to every device on the network.
The exchangeThe exchange, step by step
Four steps, and the first one is the one that runs most of the time.
Check the cache. The host keeps a table of known IP to MAC mappings it has already learned. If the address is there and has not expired, no ARP traffic happens at all. This is the normal case for almost all communication between devices on the network.
Broadcast the request. If the cache holds no known entry, the host sends an ARP request to the broadcast MAC address, so every device on the LAN receives it. The request says, in effect, who has 10.0.5.20, tell 10.0.5.11.
The owner replies, and only the owner. The machine configured with 10.0.5.20 answers with a unicast ARP reply carrying its MAC address, addressed directly back to the asker. Every other machine on the network received the question, saw an address that was not theirs, and ignored it.
Both sides cache the result. The asker stores the mapping it just learned. The replier also stores the asker's mapping, which it read out of the sender fields in the request, because communication that has started in one direction is about to go in the other.
who has 10.0.5.20? tell 10.0.5.11 broadcast, everyone receives it
10.0.5.20 is at 00:1b:21:3c:9f:0a unicast, only 10.0.5.11 receives it
The whole address resolution is two packets and takes under a millisecond on a local network. It happens once per destination per cache lifetime, which is why the protocol is invisible until something goes wrong with it.
Inside an ARP packet
RFC 826 gives both message types one format, and the field names describe the protocol better than any summary of it does. Nine fields, and no others.
| Field | What it holds |
|---|---|
| Hardware address space | 1 for Ethernet |
| Protocol address space | 0x0800 for IPv4 |
| Hardware address length | 6, the length of a MAC address |
| Protocol address length | 4, the length of an IPv4 address |
| Opcode | 1 for a request, 2 for a reply |
| Sender hardware address | The MAC address of the device sending this packet |
| Sender protocol address | The IP address of the device sending this packet |
| Target hardware address | Empty in a request, since that is what is being asked for |
| Target protocol address | The IP address whose MAC address is wanted |
Two things follow from that layout. The protocol is not tied to IP over Ethernet: the hardware and protocol address space fields exist so the same address resolution can run over other pairings, and IPv4 over Ethernet is the combination that survived.
And every ARP packet carries the sender hardware address and the sender protocol address, which is why the device that answers already holds the asker's mapping without having to ask for it. Those two fields are a free cache entry for anything on the network segment that reads the packet.
They are also the two fields an attacker fills in with whatever they like, because nothing in the format carries proof that the sender owns either address. That is ARP explained down to the last field, and there is nothing else in the protocol to appeal to.
The cacheThe cache, and why entries expire
An ARP cache entry is a known mapping that was true when it was made. Entries expire because the mapping can change: a device can be replaced, a virtual machine can move, a failover can hand an IP address to different hardware.
Lifetimes are short and vary by platform, from tens of seconds to a few minutes, and every implementation refreshes an entry that is actively in use rather than dropping a working conversation. The exact numbers matter less than the principle: the cache is a performance optimization with an expiry, not a source of truth.
Two commands read it, and they are worth knowing because a stale entry is a real failure mode.
| Platform | Read the cache | Clear one entry |
|---|---|---|
| Windows | arp -a | arp -d 10.0.5.20 |
| macOS | arp -a | sudo arp -d 10.0.5.20 |
| Linux | ip neighbor show | sudo ip neigh del 10.0.5.20 dev eth0 |
A cache holding the wrong MAC address for an IP produces a very specific symptom: data to that one device fails while communication with every other device works, and it starts working again a few minutes later without anyone doing anything.
Clearing the entry fixes it immediately, and the underlying cause is usually a device that took over an address without announcing it.
The gateway caseWhat happens when the destination is not local
This is the part that is most often misunderstood, and understanding it explains a large share of routing behavior.
A host that wants to send a packet first decides whether the destination is on its own network, by applying its subnet mask to both its own address and the destination. Two different answers lead to two different behaviors.
The destination is local. Resolve the destination address with ARP, and send the data straight to it.
The destination is not local. ARP for the default gateway, and send the frame to the gateway's MAC address, with the destination IP address still intact inside it.
That second case is the one worth sitting with. A packet from your laptop to a web server on the other side of the world leaves your LAN in a frame addressed to your router's MAC address, and the IP header still names the web server.
The router receives the frame because it is addressed to it, reads the IP header, and forwards the packet on with a new frame addressed to the next hop.
Two consequences follow.
ARP never crosses a router. An ARP request is a broadcast and routers do not forward broadcasts, so address resolution happens only within one broadcast domain. A host has no way to learn the MAC address of any device beyond its own network, and no reason to want one.
A missing gateway breaks everything at once. If the gateway does not answer ARP, the host cannot address a frame to it, so nothing leaves the local network. Local traffic keeps working perfectly, which is exactly the pattern that sends people looking at the wrong thing.
Two variationsGratuitous ARP and proxy ARP
Beyond the two ordinary message types, the request and the reply, two variations show up often enough to be worth naming. Both look like anomalies until you know what they are.
Gratuitous ARP is an announcement rather than a question. A device broadcasts an ARP message about its own addresses, which nobody asked for. It has two legitimate uses.
On startup, it checks whether anybody else replies, which detects a duplicate address. On a failover, it tells every device on the network to update its cache immediately, so data follows the address to the new hardware rather than waiting for caches to expire. Any high availability pair that moves a shared IP address does this.
Proxy ARP is a router answering on behalf of another device. The router replies to an ARP request for an address that is not its own, giving its own MAC address, so the asking host sends the data to the router and the router forwards it.
It exists to let a host reach something outside its network without a correct default gateway or subnet mask. It works, it hides configuration errors, and it is disabled by default on most modern equipment for exactly that reason.
SpoofingARP spoofing, and what actually stops it
The Address Resolution Protocol was designed in 1982 for a network where every device was trusted, and it shows. There is no authentication of any kind: a reply is believed because it arrived.
That produces a straightforward attack. An attacker on the LAN sends unsolicited ARP replies claiming that the gateway's IP address belongs to the attacker's MAC address. Neither of the two message types carries any proof of who sent it.
Every device that receives one updates its cache, and from then on it sends all of its outbound data to the attacker, who forwards it on to the real gateway.
Communication keeps flowing, nothing breaks, and the attacker sits in the middle of every connection. Doing it in both directions puts them between two specific hosts on the network.
ARP spoofing attacks are trivial to run with off the shelf tools and entirely local: they require a foothold on the same broadcast domain, which is the one real limit. ARP security is therefore a property of the network hardware rather than of the endpoint devices.
Four things reduce it, in rough order of usefulness.
| Control | Stops the attack | Effort |
|---|---|---|
| Dynamic ARP inspection | Yes, this is the real answer | Managed switches, and DHCP snooping first |
| Smaller broadcast domains | No, limits the reach | A VLAN plan you probably want anyway |
| Static ARP entries | For the few addresses you set | Manual, so a handful of systems only |
| Encryption everywhere | No, removes the value | Already done for most traffic |
Dynamic ARP inspection on the switches. The switch watches DHCP assignments, builds a table of which address belongs on which port, and discards ARP replies that contradict the known mapping. This is the actual answer to these attacks, and it is a feature of managed switches.
Smaller broadcast domains. These attacks reach only the local LAN segment, so a network split into VLANs by role limits how far any single compromise reaches.
Static ARP entries for the devices that matter. A permanent mapping for a gateway or a critical server cannot be overwritten by a reply. It also has to be maintained by hand, which is why it belongs on a handful of systems rather than everywhere.
Encryption everywhere. It does not prevent the interception and it removes most of the value. An attacker in the middle of a TLS connection sees the destination and the timing, and none of the data.
Notice what is not on that list: no endpoint security product on an individual device is very effective here, because the protocol has no way to tell a real reply from a fake one. The switch is the only thing on the network segment in a position to know which mapping is legitimate.
PitfallsWhere people go wrong
Expecting a host to ARP for a remote address. It never does. Anything off the local network produces an ARP request for the gateway instead, and a capture full of gateway requests is normal.
Blaming ARP for a routing problem. Address resolution happens within one network. If two devices are on different subnets and cannot communicate, the question is about the router, not about ARP.
Trusting the cache during a failover. A machine that has an old mapping keeps using it until the entry expires or a gratuitous ARP arrives. If the failover does not send one, the outage lasts as long as the cache does.
Assuming a duplicate IP address will announce itself. It often produces intermittent failures instead: whichever of the two devices replied to the last ARP request receives the traffic, and it alternates.
Filtering the protocol as a security measure. Blocking it stops every device on the local network communicating. The control that helps is dynamic ARP inspection, which validates rather than blocks.
Looking for ARP on IPv6 networks. It is not there. IPv6 uses Neighbor Discovery, which runs over ICMPv6 and uses multicast rather than broadcast, so the information reaches only interested devices.
Treating a full ARP table as a problem. A cache with hundreds of devices in it on a busy server is normal. A cache with entries that keep changing for the same address is the information worth looking at.
ComparisonThree lookups, and the one that never leaves the local network
| Criterion | ARP | DNS | Neighbor Discovery |
|---|---|---|---|
| Translates | IP to MAC | Name to IP | IPv6 to MAC |
| Scope | One broadcast domain | Global | One link |
| Uses broadcast | Yes | No | No, multicast |
| Runs on | Ethernet directly | UDP and TCP 53 | ICMPv6 |
| Has a cache with a timeout | Yes | Yes | Yes |
| Authenticates the answer | No | Only with DNSSEC | Only with SEND, rarely used |
| Works across a router | No | Yes | No |
The last row is the whole shape of the protocol. ARP answers a local question about one LAN, which is why it is invisible most of the time and why every problem it causes is a problem on one network segment.
FAQFrequently asked questions
What is ARP?
The Address Resolution Protocol, which finds the MAC address belonging to an IP address on a local network. It is what lets a host address a layer 2 frame to a destination device it only knows by its layer 3 IP address.
How does ARP work?
The host checks its cache, and if there is no entry it broadcasts a request to every device on the LAN asking who holds the address. The device that holds it replies with its MAC address, and both sides cache the result.
Does ARP work across a router?
No. An ARP request is a broadcast and routers do not forward broadcasts, so ARP only resolves addresses within one broadcast domain.
What does a host do when the destination is on another network?
It sends an ARP request for its default gateway and addresses the frame to the gateway's MAC address, with the destination IP address still in the packet.
How long do ARP cache entries last?
Seconds to a few minutes depending on the platform, with entries in active use refreshed rather than dropped. The cache holds an optimization with an expiry, not authoritative information.
How do I see the ARP cache?
arp -a on Windows and macOS, ip neighbor show on Linux. Clearing a stale entry is a legitimate fix when traffic to one host fails while everything else works.
What is gratuitous ARP?
An unsolicited announcement about a host's own address. It detects duplicate addresses at startup and, more usefully, tells every device to update its cache the moment an address moves to different hardware during a failover.
What is proxy ARP?
A router answering an ARP request for an address that is not its own, so traffic comes to it and it forwards on. It hides configuration mistakes and is disabled by default on most modern equipment.
What is ARP spoofing?
Sending fake ARP replies so that other devices send their traffic to the attacker instead of the real destination. It works because the sender hardware address and sender protocol address fields carry no proof of ownership, and it requires a foothold on the same LAN.
How do I prevent ARP spoofing?
Dynamic ARP inspection on managed switches is the real control. Smaller broadcast domains reduce the reach, static entries protect a few critical mappings, and encryption removes most of the value of succeeding.
Does IPv6 use ARP?
No. IPv6 replaces the protocol with Neighbor Discovery, which runs over ICMPv6 and uses multicast, so it reaches only the interested devices instead of every device on the LAN.
Why does traffic to one host fail while everything else works?
Frequently a stale or wrong ARP cache entry for that host. It resolves by itself when the entry expires, which is what makes it confusing to diagnose.
What causes a duplicate IP address to behave strangely?
Two machines answering ARP requests for the same address. Whichever replied most recently receives the traffic, so the failure moves between them rather than being consistent.
What does ARP mean?
The ARP meaning is Address Resolution Protocol. It is how a device that knows a neighbor's IP address finds that neighbor's MAC address, by broadcasting a question on the local network and caching the answer.
Keep readingRelated concepts
Read next · Addressing What Is a Subnet? The mask is what decides whether a host ARPs for the destination or for the gateway, so a wrong mask changes the question it asks. Open this next15 min- Addressing · 9 min What Is DHCP? Dynamic ARP inspection works from the DHCP lease table, so the two protocols end up defending each other.
- Addressing · 10 min Default Gateway Everything leaving the local network is addressed to the gateway MAC, which is what the second ARP request is for.
- Fundamentals · 9 min What a LAN Actually Is, Now That It Is Not About Distance The network that broadcast reaches, and where it stops.
- Fundamentals · 9 min Link Local Addresses, and Why One of Them Is Bad News The IPv4 equivalent of what IPv6 uses these addresses for.
- Switching · 9 min The MAC Address Table, and How to Find Which Port a Device Is On The other table, and the one you read first.
- Routing · 11 min HSRP vs VRRP, and What Happens When the Default Gateway Dies Why a router taking over a shared gateway announces itself with a gratuitous ARP.