ARP
How a host turns an IP address into the MAC address it needs.
The request
28 bytes asking: who has 192.168.1.1?
Whole frame
Twenty-eight bytes that mean: 'I am 192.168.1.20 at 3C:22:FB:AA:01:20. Whoever owns 192.168.1.1, tell me your MAC.'
| Field | Offset | Example value | Meaning |
|---|---|---|---|
| Hardware type | Byte 0–1 | 0x0001 = Ethernet | The link layer in use. 1 = Ethernet. ARP was designed to be generic, so it says which kind of hardware address follows. |
| Protocol type | Byte 2–3 | 0x0800 = IPv4 | The network-layer address being resolved, using EtherType numbers. 0x0800 = IPv4. |
| Hardware length | Byte 4 | 6 | Length of a hardware address in bytes: 6 for a MAC. |
| Protocol length | Byte 5 | 4 | Length of a protocol address in bytes: 4 for IPv4. |
| Operation | Byte 6–7 | 1 = request | 1 = request ('who has this IP?'), 2 = reply ('I do, here is my MAC'). |
| Sender MAC | Byte 8–13 | 3C:22:FB:AA:01:20 | The asker's MAC. The target will cache it so it can answer without asking back. |
| Sender IP | Byte 14–17 | 192.168.1.20 | The asker's IP. |
| Target MAC | Byte 18–23 | 00:00:00:00:00:00 (?) | Unknown, which is the whole point: all zeros in a request. |
| Target IP | Byte 24–27 | 192.168.1.1 | The IP being asked about: the router. |
Overview
Ethernet frames are addressed by MAC, but applications use IP addresses. Before the first packet to a neighbour can leave, the host asks the whole LAN 'who has this IP?' using ARP (Address Resolution Protocol) and remembers the answer.
ARP is small and trusting: any host can answer, and nothing is authenticated. That makes ARP spoofing a classic LAN attack and is one reason IPv6 replaced it with Neighbor Discovery.
Key facts
- Layer
- Between link and network
- Size
- 28 bytes (IPv4 over Ethernet)
- EtherType
- 0x0806
- Request goes to
- FF:FF:FF:FF:FF:FF
- Standard
- RFC 826
The reply
The same layout with the roles swapped.
Whole frame
The same 28 bytes with the sender and target swapped and the blanks filled in. The asker stores 192.168.1.1 → 00:1A:2B:3C:4D:5E in its ARP cache.
| Field | Offset | Example value | Meaning |
|---|---|---|---|
| Hardware type | Byte 0–1 | Ethernet | Same as the request. |
| Protocol type | Byte 2–3 | IPv4 | Same as the request. |
| Hardware length | Byte 4 | 6 | Same as the request. |
| Protocol length | Byte 5 | 4 | Same as the request. |
| Operation | Byte 6–7 | 2 = reply | 2 = reply. Unlike the request, the reply is unicast straight back to the asker. |
| Sender MAC | Byte 8–13 | 00:1A:2B:3C:4D:5E | The answer: the router's MAC. This is what the asker wanted. |
| Sender IP | Byte 14–17 | 192.168.1.1 | The IP that was asked about. |
| Target MAC | Byte 18–23 | 3C:22:FB:AA:01:20 | Now filled in with the original asker's MAC. |
| Target IP | Byte 24–27 | 192.168.1.20 | The original asker's IP. |
The exchange
Question, answer, then the packet that needed the answer.
Whole exchange
ARP is the glue between IP addresses and MAC addresses on one LAN: broadcast a question, unicast an answer, cache the result.
1Who has 192.168.1.1?
The laptop wants to send a packet to its router but only knows the IP. It broadcasts an ARP request to every host on the LAN.
2192.168.1.1 is at 00:1A:...
Only the owner of 192.168.1.1 answers, and directly to the asker. The laptop caches the mapping (usually for minutes) so it does not have to ask again.
3Now the real packet
With the MAC known, the Ethernet frame carrying the actual IP packet can be addressed to the router.
Where you meet it
- Every IPv4 LAN: it runs before nearly every first packet to a neighbour
- Gratuitous ARP announces a new or moved address and detects IP conflicts
- `arp -a` shows the cache on your own machine
Watch out for
- ARP only works within one broadcast domain. For hosts beyond the router you ARP for the router's MAC, not the far host's.
- Stale cache entries after swapping hardware cause 'works for a while, then fails' puzzles; flushing the cache fixes it.
- Replies are accepted unauthenticated, so ARP spoofing can redirect traffic on an untrusted LAN.
Standards
- RFC 826: An Ethernet Address Resolution Protocol