What Is an ARP Table?
An ARP table is the list of IP-to-MAC address pairs a device has learned about its neighbors, so it can hand each packet to the right one on the local network.
Here is one such pair from arp -a on a Windows laptop:
192.168.1.1 3c-52-82-1a-9f-00 dynamic
Translated: the gateway at 192.168.1.1 can be reached at that MAC, and the laptop learned it on its own, which is what dynamic means.
Every host, router, firewall and Layer 3 switch keeps one, and most engineers say ARP cache instead, since nothing in it survives for long.
Why two addresses? The IP address gets a packet to the right network, and the MAC address gets it to the right card once it lands there.
The table maps a Layer 3 address onto a Layer 2 one, so the OSI model purists we know call ARP a Layer 2.5 protocol, with a straight face most of the time.
What Is ARP (Address Resolution Protocol)?
ARP fills the table, with zero subtlety. Rewind the laptop above to the first time it needed the gateway, table empty. It put one frame on the wire addressed to everybody, asking who has 192.168.1.1.
The gateway answered with its MAC, unicast, straight back, and the laptop wrote the pair down and sent the packet it had been holding. Total elapsed time, a millisecond or so.
That broadcast is the reason ARP never leaves the subnet, because routers don't forward it.
For 10.0.5.20 on another network, the laptop resolves the gateway's MAC instead, and the router repeats the dance on the far side.
IPv6 threw ARP out entirely, and Neighbor Discovery Protocol does the job there, so an IPv6 host shows you a neighbor table instead.
What Does an ARP Table Contain?
One row per neighbor. Column names differ by operating system, yet the same five things turn up nearly everywhere.
Field | What It Holds | Example |
IP address | The neighbor this row describes | 192.168.1.1 |
MAC address | The hardware address that came back in the reply, 48 bits of it | 3c:52:82:1a:9f:00 |
Interface | Where it was learned: a NIC on a host, a port or VLAN on a switch | eth0, Vlan10, Ethernet 2 |
Type or state | Dynamic (learned) or static (configured), plus a reachability state on some systems | dynamic, REACHABLE, STALE, INCOMPLETE |
Age | How long since the entry was learned or last confirmed | 12 minutes on Cisco IOS |
Watch for INCOMPLETE. The device asked and heard nothing back, so the row has an IP and a blank where the MAC belongs. Usually somebody powered the thing off or pulled its cable.
How Do You Look at Your ARP Table?
Nothing needs installing. Here are the four commands we type most.
Windows
Run arp -a in Command Prompt for Internet Address, Physical Address and Type, grouped per adapter.
PowerShell's Get-NetNeighbor adds a State column (Reachable, Stale, Permanent), and on servers we prefer it because the output pipes straight into a script.
Linux
ip neigh show replaced the old arp -n, and a line looks like this:
192.168.1.1 dev eth0 lladdr 3c:52:82:1a:9f:00 REACHABLE
macOS
arp -a in Terminal prints ? (192.168.1.1) at 3c:52:82:1a:9f:0 on en0, the question mark meaning it has no hostname for that address.
Cisco IOS
From privileged EXEC mode, show ip arp returns six columns:
Protocol Address Age (min) Hardware Addr Type Interface
Internet 192.168.1.1 - 3c52.821a.9f00 ARPA Vlan10
Internet 192.168.1.20 12 0050.56a1.7b3e ARPA Vlan10
Internet 192.168.1.44 0 Incomplete ARPA
The dash in the first row is the switch's own address on the VLAN, not a stale neighbor. On a core switch this runs to thousands of rows, so filter by host (show ip arp 192.168.1.20) or by VLAN (show ip arp vlan 10).
Read the Age Column First
An entry whose age keeps resetting to 0 belongs to something chatty (fine for a gateway, odd for a printer). One that climbs toward the timeout has gone quiet, and usually somebody unplugged it.
Dynamic vs Static ARP Entries: What's the Difference?
Dynamic entries appear and expire on their own. Static ones stay until you delete them, and that changes how each one fails.
Almost everything in the table is dynamic, learned from an ARP reply and dropped if no traffic confirms it within the timeout. That timeout is four hours on Cisco IOS and under a minute on a Windows or Linux host.
A static entry pins one IP to one MAC and no ARP reply can overwrite it. We keep them for the two or three devices that must never move, and we'd rather have three than thirty.
The commands differ on every platform, so here they are in one place.
Platform | Add a Static Entry | Remove One Entry | Flush Everything |
Windows | netsh interface ipv4 add neighbors "Ethernet" 192.168.1.10 00-14-22-01-23-45 | arp -d 192.168.1.10 | arp -d * |
Linux | ip neigh add 192.168.1.10 lladdr 00:14:22:01:23:45 dev eth0 nud permanent | ip neigh del 192.168.1.10 dev eth0 | ip neigh flush all |
macOS | sudo arp -s 192.168.1.10 00:14:22:01:23:45 | sudo arp -d 192.168.1.10 | sudo arp -a -d |
Cisco IOS | arp 192.168.1.10 0014.2201.2345 arpa (global config) | clear ip arp 192.168.1.10 | clear arp-cache |
Windows wants an administrator prompt for all of them. Static entries shrug off every flush command in that table, which is the point of them, and also the bill.
Swap the network card in that server and the entry points at a MAC that no longer exists, and nothing tells you.
When Should You Flush an ARP Table, and How?
Flushing does no harm to the system. The device relearns everything from live traffic within seconds. Here are three common scenarios where flushing is usually recommended.
A server got a new NIC and its old MAC is still in every neighbor's table.
A device moved to a new IP and the old pairing hasn't aged out yet.
The uneasy feeling that somebody has been poisoning entries.
The commands sit in the table above.
ARP Table vs MAC Address Table vs Routing Table
Three tables cooperate to move a packet, and people muddle them because all three can live on the same switch.
Table | Maps | Built From | Lives On |
ARP table | IP address to MAC address | ARP replies | Anything with an IP address |
MAC address table | MAC address to switch port | The source MAC of frames coming in | Switches |
Routing table | Destination network to next hop and exit interface | Static routes and routing protocols such as OSPF | Routers and Layer 3 switches |
The Layer 2 switch trips people up. It forwards on MAC addresses alone, so its ARP table holds little beyond its own management address. Enable routing and an ARP table appears for every VLAN it routes between.
What Can the ARP Table Tell You When Something Breaks?
The moment a local device goes quiet on us, the ARP table is the first screen we open. One line says whether the problem is at Layer 2 or above it.
1. Ping It, Then Read the Entry
Ping fails and the entry says Incomplete? The target never answered ARP, so it's off, unplugged or on the wrong VLAN, and firewall tinkering won't help. Ping fails but the entry is complete? Layer 2 is fine, so look at a host firewall or a routing rule.
2. Watch for a MAC That Keeps Changing Under One IP
Two MACs trading places under one IP inside a few minutes means a duplicate address, nearly every time. The culprit we keep finding is a static IP somebody parked inside a DHCP scope.
If the flip is on the gateway's IP, stop assuming an accident. Somebody is answering ARP requests with their own MAC so your traffic detours through their machine, which is ARP spoofing.
Dynamic ARP Inspection on the access switches is the cure: the switch checks every reply against its DHCP snooping table.
3. Watch the Size of the Table
An access switch that suddenly holds a few thousand Incomplete entries has a scanner on it, since every unanswered address in a sweep leaves one behind. Decent network segmentation keeps that sweep inside one VLAN.
Beyond One Switch at a Time
All of this works one device at a time. Across a few hundred switches you want switch monitoring that pulls the ARP and MAC tables over SNMP and joins them.
That way, when you type an IP, you get back the switch, the port and the MAC.
Explore More IT Terms
Browse our comprehensive IT glossary to learn more about technology terminology.