Address Resolution Protocol (ARP)

1
0

Introduction

Address Resolution Protocol (ARP) is used in IPv4 networks to map a known IP address to its corresponding MAC address on a local network. Since Ethernet communication requires a destination MAC address, a device must know the MAC address of the next device before it can send a frame on the LAN.

ARP bridges the gap between Layer 3 (IP addressing) and Layer 2 (MAC addressing), enabling devices to communicate over Ethernet networks.

ARP in the Same LAN

Consider two devices on the same subnet:

  • Laptop A => 192.168.1.10

  • Laptop B => 192.168.1.20

When Laptop A wants to send data to Laptop B, it first checks its ARP cache to see whether it already knows the MAC address associated with 192.168.1.20.

  • If an entry exists, the stored MAC address is used directly.

  • If no entry exists, Laptop A sends an ARP Request as a broadcast.

The request essentially asks: "Who has 192.168.1.20? Tell me your MAC address."

ARP Request and Reply

The ARP Request is sent using the broadcast MAC address:

FF:FF:FF:FF:FF:FF

Every device on the LAN receives the request and checks the target IP address. Only the device whose IP address matches the requested address responds with an ARP Reply containing its MAC address.

After receiving the reply, the sender stores the IP-to-MAC mapping in its ARP cache and can then build the Ethernet frame for transmission.

This highlights an important distinction:

  • IP Address: Identifies the logical destination.

  • MAC Address: Identifies the destination on the local link.

ARP communication is illustrated through a broadcast request to discover a device's MAC address and a unicast reply that returns the matching MAC address, along with an example ARP cache used for faster local network communication.

ARP communication is illustrated through a broadcast request to discover a device's MAC address and a unicast reply that returns the matching MAC address, along with an example ARP cache used for faster local network communication.

ARP for Different Networks

When a device needs to communicate with a host outside its local subnet, ARP works differently.

For example, if a host wants to reach 8.8.8.8:

  • It determines that the destination is outside the local subnet.

  • It forwards the packet to the default gateway.

  • It performs ARP for the gateway's MAC address.

  • The Ethernet frame is addressed to the gateway.

The destination IP address remains unchanged throughout the journey.

A key concept to remember is:

  • MAC Destination = Next Hop

  • IP Destination = Final Destination

As packets move through routers, the Layer 2 frame is rebuilt at each hop, causing MAC addresses to change. However, the destination IP address typically remains the same until the packet reaches its final destination.

ARP Cache

To avoid broadcasting ARP requests repeatedly, devices maintain an ARP cache containing recently learned IP-to-MAC mappings. When a matching entry is available, communication can begin immediately without generating additional ARP traffic.

ARP cache entries typically contain:

  • IP Address

  • MAC Address

  • Entry Type (Dynamic or Static)

A common command for viewing the ARP cache is: arp -a

Gratuitous ARP

Gratuitous ARP is an ARP announcement sent by a device for its own IP address without first receiving an ARP request. Instead of asking for a mapping, the device is advertising one.

Common uses include:

  • Announcing ownership of an IP address.

  • Updating ARP cache entries on other devices.

  • Detecting duplicate IP addresses.

  • Supporting failover and redundancy mechanisms.

ARP Security Issues

ARP does not verify whether ARP replies are genuine. Because of this, attackers can send forged ARP messages and manipulate traffic within a local network.

  • ARP Spoofing: An attacker sends fake ARP replies that associate their MAC address with another device's IP address, often the default gateway, causing traffic to be redirected.

  • ARP Cache Poisoning: False IP-to-MAC mappings are inserted into a device's ARP cache, causing it to trust and use incorrect address information.

  • Man-in-the-Middle (MITM): By spoofing ARP entries, an attacker can position themselves between two communicating devices and intercept or modify traffic.

  • ARP Flooding: Large numbers of fake ARP messages are sent to overwhelm networking devices, potentially causing excessive broadcasts and abnormal network behavior.

Preventing ARP Attacks

  • Dynamic ARP Inspection (DAI): Verifies ARP packets against trusted information and blocks forged ARP messages.

  • Static ARP Entries: Manually configured IP-to-MAC mappings prevent attackers from modifying ARP records dynamically.

  • Network Segmentation: Using VLANs and smaller broadcast domains limits the spread and impact of ARP-based attacks.

  • Port Security: Restricts which devices can connect to switch ports, helping prevent unauthorized devices from participating in the network.

Summary

ARP (Address Resolution Protocol) maps an IPv4 address to a MAC address, allowing devices to communicate on a local Ethernet network. If a device does not know the destination MAC address, it sends a broadcast ARP Request, and the correct device replies with its MAC address. For devices on different networks, ARP resolves only the default gateway's MAC address while the destination IP address stays the same.

ARP stores learned IP-to-MAC mappings in an ARP cache to reduce repeated broadcasts and also supports Gratuitous ARP for updating caches and detecting duplicate IP addresses. Because ARP does not authenticate replies, it is vulnerable to attacks such as ARP spoofing, ARP cache poisoning, and MITM attacks, which can be mitigated using Dynamic ARP Inspection (DAI), static ARP entries, VLANs, and port security.

CS Core

Read Similar Blogs

Comments0