Skip to main content

ARP

Address Resolution Protocol

Pronunciation
ARP
Updated 3 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/arp

In short

ARP is a network protocol that finds the MAC address belonging to an IPv4 address on the local network, so a device knows where to deliver each Ethernet frame.

What is ARP?

ARP, the Address Resolution Protocol, connects two kinds of addresses. Programs send data to IP addresses, but on a local Ethernet or Wi-Fi network, frames are actually delivered to MAC addresses, the hardware identifiers of network interfaces. ARP is how a device learns which MAC address belongs to a given IPv4 address on its own network.

When a device wants to reach 192.168.1.30 and doesn't know its MAC address, it broadcasts an ARP request to every device on the LAN, asking who has that address. The device that owns the address replies directly with its MAC address, and the sender stores the answer in its ARP cache for a short time so it doesn't have to ask again for every packet. For destinations outside the subnet, a device doesn't look up the final destination at all; it uses ARP to find the MAC address of its default gateway and sends the frame there. IPv6 does the same job with the Neighbor Discovery Protocol instead of ARP.

ARP is like calling out a name in a crowded office, waiting for the right person to wave, and then remembering where they sit. It runs constantly and invisibly on every IPv4 network, and developers usually meet it only while troubleshooting, for example when two devices were accidentally given the same IP address and both answer, or when reading the ARP table to see which devices are on a network.

ARP is sometimes confused with DNS, since both translate one kind of name into another. DNS turns domain names into IP addresses and works across the internet, while ARP turns IP addresses into MAC addresses and only works inside one local network. ARP also has no authentication, so any device can answer falsely: in ARP spoofing, an attacker on the same network redirects traffic through their own machine for a man-in-the-middle attack, which is one reason to encrypt traffic with TLS even on networks you trust.

Key takeaways

  • ARP maps an IPv4 address to a MAC address on the local network.
  • A device broadcasts an ARP request, and the owner of the address replies with its MAC address.
  • Answers are kept in an ARP cache for a short time.
  • For remote destinations, a device uses ARP to find its default gateway's MAC address.
  • ARP has no authentication, which makes ARP spoofing possible; IPv6 uses Neighbor Discovery instead.

Example

Inspecting the ARP cachebash
# Show the ARP cache: IP addresses and the MAC addresses they map to (Linux)
ip neigh show
# 192.168.1.1 dev wlan0 lladdr 3c:22:fb:9a:41:0e REACHABLE

# The classic command, also available on macOS and Windows
arp -a

# Send ARP requests directly and see which MAC address answers
sudo arping -c 3 192.168.1.30

Readers ask

What is the difference between ARP and DNS?

DNS translates domain names such as example.com into IP addresses and works across the internet. ARP translates IPv4 addresses into MAC addresses and works only within a single local network.

What is ARP spoofing?

ARP spoofing is an attack in which a device on the local network sends fake ARP replies, so other devices link the attacker's MAC address to someone else's IP address, often the router's. Traffic then flows through the attacker, who can read or change anything that isn't encrypted.

Does IPv6 use ARP?

No. IPv6 replaces ARP with the Neighbor Discovery Protocol, which uses ICMPv6 messages sent to multicast addresses instead of broadcasts to find neighbors' MAC addresses.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings