Schedule DemoStart Free Trial

Unified Observability Platform for Modern IT Operations

Summarize with AI what Motadata does:

ObserveOps

  • Network Observability
  • Network Configuration & Compliance Management
  • Hybrid Infrastructure Monitoring
  • Log Monitoring
  • Application Performance Monitoring
  • Real User Monitoring

ServiceOps

  • Service Management
  • IT Asset & Configuration Management
  • Patch & Deployment Management
  • Agentic AI & Orchestration
  • MSP Edition

By Use Cases

  • Data Centre Monitoring
  • Docker Monitoring
  • Enterprise Service Management
  • IT Service Desk
  • ITSM MSP
  • Enterprise Network Monitoring

By Technologies

  • AWS Monitoring
  • Azure Monitoring
  • Kubernetes Monitoring
  • DevOps Observability
  • REST API Monitoring
  • Storage Monitoring

Resources

  • Getting Started
  • Documentation
  • Integrations
  • IT Glossary
  • Whitepapers
  • Ebooks & Guides
  • Product Brochures
  • Success Stories
  • Comparison
  • Features

Community

  • Blog
  • Press Releases
  • Events
  • Webinar
  • Become a Partner

Company

  • Company
  • Careers
  • Contact Us
  • Customer Support

Get in Touch

  • Request Demo
  • sales@motadata.com
  • support@motadata.com
© 2026 Mindarray Systems Limited. All rights reserved.
Privacy PolicyTerms of Service
Back to IT Glossary
IT Resources

ARP Table

What Is an ARP Table?

An ARP table is the list of IP-to-MAC address pairs a device has learned about its neighbors, so it can hand each packet to the right one on the local network.

Here is one such pair from arp -a on a Windows laptop:

192.168.1.1        3c-52-82-1a-9f-00     dynamic

Translated: the gateway at 192.168.1.1 can be reached at that MAC, and the laptop learned it on its own, which is what dynamic means.

Every host, router, firewall and Layer 3 switch keeps one, and most engineers say ARP cache instead, since nothing in it survives for long.

Why two addresses? The IP address gets a packet to the right network, and the MAC address gets it to the right card once it lands there.

The table maps a Layer 3 address onto a Layer 2 one, so the OSI model purists we know call ARP a Layer 2.5 protocol, with a straight face most of the time.

What Is ARP (Address Resolution Protocol)?

ARP fills the table, with zero subtlety. Rewind the laptop above to the first time it needed the gateway, table empty. It put one frame on the wire addressed to everybody, asking who has 192.168.1.1.

The gateway answered with its MAC, unicast, straight back, and the laptop wrote the pair down and sent the packet it had been holding. Total elapsed time, a millisecond or so.

That broadcast is the reason ARP never leaves the subnet, because routers don't forward it.

For 10.0.5.20 on another network, the laptop resolves the gateway's MAC instead, and the router repeats the dance on the far side.

IPv6 threw ARP out entirely, and Neighbor Discovery Protocol does the job there, so an IPv6 host shows you a neighbor table instead.

What Does an ARP Table Contain?

One row per neighbor. Column names differ by operating system, yet the same five things turn up nearly everywhere.

Field

What It Holds

Example

IP address

The neighbor this row describes

192.168.1.1

MAC address

The hardware address that came back in the reply, 48 bits of it

3c:52:82:1a:9f:00

Interface

Where it was learned: a NIC on a host, a port or VLAN on a switch

eth0, Vlan10, Ethernet 2

Type or state

Dynamic (learned) or static (configured), plus a reachability state on some systems

dynamic, REACHABLE, STALE, INCOMPLETE

Age

How long since the entry was learned or last confirmed

12 minutes on Cisco IOS

Watch for INCOMPLETE. The device asked and heard nothing back, so the row has an IP and a blank where the MAC belongs. Usually somebody powered the thing off or pulled its cable.

How Do You Look at Your ARP Table?

Nothing needs installing. Here are the four commands we type most.

Windows

Run arp -a in Command Prompt for Internet Address, Physical Address and Type, grouped per adapter.

PowerShell's Get-NetNeighbor adds a State column (Reachable, Stale, Permanent), and on servers we prefer it because the output pipes straight into a script.

Linux

ip neigh show replaced the old arp -n, and a line looks like this:

192.168.1.1 dev eth0 lladdr 3c:52:82:1a:9f:00 REACHABLE

macOS

arp -a in Terminal prints ? (192.168.1.1) at 3c:52:82:1a:9f:0 on en0, the question mark meaning it has no hostname for that address.

Cisco IOS

From privileged EXEC mode, show ip arp returns six columns:

Protocol  Address        Age (min)  Hardware Addr   Type   Interface

Internet  192.168.1.1            -   3c52.821a.9f00  ARPA   Vlan10

Internet  192.168.1.20          12   0050.56a1.7b3e  ARPA   Vlan10

Internet  192.168.1.44           0   Incomplete      ARPA

The dash in the first row is the switch's own address on the VLAN, not a stale neighbor. On a core switch this runs to thousands of rows, so filter by host (show ip arp 192.168.1.20) or by VLAN (show ip arp vlan 10).

Read the Age Column First

An entry whose age keeps resetting to 0 belongs to something chatty (fine for a gateway, odd for a printer). One that climbs toward the timeout has gone quiet, and usually somebody unplugged it.

Dynamic vs Static ARP Entries: What's the Difference?

Dynamic entries appear and expire on their own. Static ones stay until you delete them, and that changes how each one fails.

Almost everything in the table is dynamic, learned from an ARP reply and dropped if no traffic confirms it within the timeout. That timeout is four hours on Cisco IOS and under a minute on a Windows or Linux host.

A static entry pins one IP to one MAC and no ARP reply can overwrite it. We keep them for the two or three devices that must never move, and we'd rather have three than thirty.

The commands differ on every platform, so here they are in one place.

Platform

Add a Static Entry

Remove One Entry

Flush Everything

Windows

netsh interface ipv4 add neighbors "Ethernet" 192.168.1.10 00-14-22-01-23-45

arp -d 192.168.1.10

arp -d *

Linux

ip neigh add 192.168.1.10 lladdr 00:14:22:01:23:45 dev eth0 nud permanent

ip neigh del 192.168.1.10 dev eth0

ip neigh flush all

macOS

sudo arp -s 192.168.1.10 00:14:22:01:23:45

sudo arp -d 192.168.1.10

sudo arp -a -d

Cisco IOS

arp 192.168.1.10 0014.2201.2345 arpa (global config)

clear ip arp 192.168.1.10

clear arp-cache

Windows wants an administrator prompt for all of them. Static entries shrug off every flush command in that table, which is the point of them, and also the bill.

Swap the network card in that server and the entry points at a MAC that no longer exists, and nothing tells you.

When Should You Flush an ARP Table, and How?

Flushing does no harm to the system. The device relearns everything from live traffic within seconds. Here are three common scenarios where flushing is usually recommended.

  1. A server got a new NIC and its old MAC is still in every neighbor's table.

  1. A device moved to a new IP and the old pairing hasn't aged out yet.

  1. The uneasy feeling that somebody has been poisoning entries.

The commands sit in the table above.

ARP Table vs MAC Address Table vs Routing Table

Three tables cooperate to move a packet, and people muddle them because all three can live on the same switch.

Table

Maps

Built From

Lives On

ARP table

IP address to MAC address

ARP replies

Anything with an IP address

MAC address table

MAC address to switch port

The source MAC of frames coming in

Switches

Routing table

Destination network to next hop and exit interface

Static routes and routing protocols such as OSPF

Routers and Layer 3 switches

The Layer 2 switch trips people up. It forwards on MAC addresses alone, so its ARP table holds little beyond its own management address. Enable routing and an ARP table appears for every VLAN it routes between.

What Can the ARP Table Tell You When Something Breaks?

The moment a local device goes quiet on us, the ARP table is the first screen we open. One line says whether the problem is at Layer 2 or above it.

1. Ping It, Then Read the Entry

Ping fails and the entry says Incomplete? The target never answered ARP, so it's off, unplugged or on the wrong VLAN, and firewall tinkering won't help. Ping fails but the entry is complete? Layer 2 is fine, so look at a host firewall or a routing rule.

2. Watch for a MAC That Keeps Changing Under One IP

Two MACs trading places under one IP inside a few minutes means a duplicate address, nearly every time. The culprit we keep finding is a static IP somebody parked inside a DHCP scope.

If the flip is on the gateway's IP, stop assuming an accident. Somebody is answering ARP requests with their own MAC so your traffic detours through their machine, which is ARP spoofing.

Dynamic ARP Inspection on the access switches is the cure: the switch checks every reply against its DHCP snooping table.

3. Watch the Size of the Table

An access switch that suddenly holds a few thousand Incomplete entries has a scanner on it, since every unanswered address in a sweep leaves one behind. Decent network segmentation keeps that sweep inside one VLAN.

Beyond One Switch at a Time

All of this works one device at a time. Across a few hundred switches you want switch monitoring that pulls the ARP and MAC tables over SNMP and joins them.

That way, when you type an IP, you get back the switch, the port and the MAC.

Explore More IT Terms

Browse our comprehensive IT glossary to learn more about technology terminology.

Back to IT GlossaryContact Us
Table of Contents