arp - manipulate the system ARP cache
| Use Case | Command | Description |
|---|---|---|
| 📋 Display ARP cache | arp -n | Show current ARP table with numeric addresses |
| 🗑️ Delete ARP entry | arp -d 10.0.0.1 | Remove a specific ARP table entry |
| ➕ Add static entry | arp -s 10.0.0.5 00:11:22:33:44:55 | Manually set a permanent ARP mapping |
| 📢 Add proxy ARP entry | arp -i eth0 -Ds 10.0.0.2 eth1 pub | Answer ARP requests for an IP on another interface |
| 📄 Bulk add from file | arp -f /etc/ethers | Load multiple ARP entries from a file |
arp [-vn] [-H type] [-i if] [-ae] [hostname]
arp [-v] [-i if] -d hostname [pub]
arp [-v] [-H type] [-i if] -s hostname hw_addr [temp]
arp [-v] [-H type] [-i if] -s hostname hw_addr [netmask nm] pub
arp [-v] [-H type] [-i if] -Ds hostname ifname [netmask nm] pub
arp [-vnD] [-H type] [-i if] -f [filename]
Arp manipulates or displays the kernel's IPv4 network neighbour cache. It can add entries to the table, delete one or display the current content.
ARP stands for Address Resolution Protocol, which is used to find the media access control address of a network neighbour for a given IPv4 Address.
arp -d address: Delete an ARP table entry. Root or netadmin privilege required. The entry is found by IP address. If a hostname is given, it is resolved first.arp -s address hw_addr: Set up a new table entry. Hardware address format depends on class (for Ethernet: 6 hex bytes separated by colons). For proxy ARP entries (with pub flag), a netmask may be specified. Without temp flag, entries are permanent. Use arp -Ds address ifname to take hardware address from an interface.Tell the user what is going on by being verbose.
Shows numerical addresses instead of trying to determine symbolic host, port or user names.
When setting or reading the ARP cache, this optional parameter tells arp which class of entries it should check for. Default value is ether (IEEE 802.3 10Mbps Ethernet). Other values include arcnet, pronet, ax25, netrom.
Use alternate BSD style output format (with no fixed columns).
Use default Linux style output format (with fixed columns).
Instead of a hw_addr, the given argument is the name of an interface. arp will use the MAC address of that interface for the table entry. Usually the best option to set up a proxy ARP entry to yourself.
Select an interface. When dumping the ARP cache only entries matching the specified interface will be printed. When setting a permanent or temp ARP entry this interface will be associated with the entry; if this option is not used, the kernel will guess based on the routing table. For pub entries the specified interface is the interface on which ARP requests will be answered.
Note: This has to be different from the interface to which the IP datagrams will be routed. As of kernel 2.2.0 it is no longer possible to set an ARP entry for an entire subnet. Linux instead does automagic proxy arp when a route exists and it is forwarding. See arp(7) for details. Also the dontpub option cannot be used with 2.4 and newer kernels.
Similar to the -s option, but the address info is taken from file filename. This can be used if ARP entries for a lot of hosts have to be set up. The name of the data file is very often /etc/ethers, but this is not official. If no filename is specified, /etc/ethers is used as default.
The format of the file is simple: it contains ASCII text lines with a hostname and a hardware address separated by whitespace. Additionally the pub, temp and netmask flags can be used.
In all places where a hostname is expected, one can also enter an IP address in dotted-decimal notation. As a special case for compatibility the order of the hostname and the hardware address can be exchanged.
Each complete entry in the ARP cache will be marked with the C flag. Permanent entries are marked with M and published entries have the P flag.
/usr/sbin/arp -i eth0 -Ds 10.0.0.2 eth1 pub
This will answer ARP requests for 10.0.0.2 on eth0 with the MAC address for eth1.
/usr/sbin/arp -i eth1 -d 10.0.0.1
Delete the ARP table entry for 10.0.0.1 on interface eth1. This will match published proxy ARP entries and permanent entries.
/proc/net/arp/etc/networks/etc/hosts/etc/ethersFred N. van Kempen <waltje AT uwalt.org>, Bernd Eckenfels <net-tools AT lina.de>.
arp - Linux ARP kernel module.
This kernel protocol module implements the Address Resolution Protocol defined in RFC 826. It is used to convert between Layer2 hardware addresses and IPv4 protocol addresses on directly connected networks. The user normally doesn't interact directly with this module except to configure it; instead it provides a service for other protocols in the kernel.
A user process can receive ARP packets by using packet(7) sockets. There is also a mechanism for managing the ARP cache in user-space by using netlink(7) sockets. The ARP table can also be controlled via ioctl(2) on any AF_INET socket.
The ARP module maintains a cache of mappings between hardware addresses and protocol addresses. The cache has a limited size so old and less frequently used entries are garbage-collected. Entries which are marked as permanent are never deleted by the garbage-collector. The cache can be directly manipulated by the use of ioctls and its behavior can be tuned by the /proc interfaces described below.
When there is no positive feedback for an existing mapping after some time (see the /proc interfaces below), a neighbor cache entry is considered stale. Positive feedback can be gotten from a higher layer; for example from a successful TCP ACK. Other protocols can signal forward progress using the MSG_CONFIRM flag to sendmsg(2). When there is no forward progress, ARP tries to reprobe. It first tries to ask a local arp daemon app_solicit times for an updated MAC address. If that fails and an old MAC address is known, a unicast probe is sent ucast_solicit times. If that fails too, it will broadcast a new ARP request to the network. Requests are sent only when there is data queued for sending.
Linux will automatically add a nonpermanent proxy arp entry when it receives a request for an address it forwards to and proxy arp is enabled on the receiving interface. When there is a reject route for the target, no proxy arp entry is added.
Three ioctls are available on all AF_INET sockets. They take a pointer to a struct arpreq as their argument.
struct arpreq {
struct sockaddr arp_pa; /* protocol address */
struct sockaddr arp_ha; /* hardware address */
int arp_flags; /* flags */
struct sockaddr arp_netmask; /* netmask of protocol address */
char arp_dev[16];
};
SIOCSARP, SIOCDARP and SIOCGARP respectively set, delete and get an ARP mapping. Setting and deleting ARP maps are privileged operations and may be performed only by a process with the CAP_NET_ADMIN capability or an effective UID of 0.
arp_pa must be an AF_INET address and arp_ha must have the same type as the device which is specified in arp_dev. arp_dev is a zero-terminated string which names a device.
| Flag | Meaning |
|---|---|
| ATF_COM | Lookup complete |
| ATF_PERM | Permanent entry |
| ATF_PUBL | Publish entry |
| ATF_USETRAILERS | Trailers requested |
| ATF_NETMASK | Use a netmask |
| ATF_DONTPUB | Don't answer |
If the ATF_NETMASK flag is set, then arp_netmask should be valid. Linux 2.2 does not support proxy network ARP entries, so this should be set to 0xffffffff, or 0 to remove an existing proxy arp entry. ATF_USETRAILERS is obsolete and should not be used.
ARP supports a range of /proc interfaces to configure parameters on a global or per-interface basis. The interfaces can be accessed by reading or writing the /proc/sys/net/ipv4/neigh/*/* files. Each interface in the system has its own directory in /proc/sys/net/ipv4/neigh/. The setting in the "default" directory is used for all newly created devices. Unless otherwise specified, time-related interfaces are specified in seconds.
mcast_solicit). Defaults to 0.base_reachable_time/2 and 3*base_reachable_time/2. An entry's validity will be extended if it receives positive feedback from higher level protocols. Defaults to 30 seconds. This file is now obsolete in favor of base_reachable_time_ms.base_reachable_time, but measures time in milliseconds. Defaults to 30000 milliseconds.proxy_delay jiffies before replying. This is used to prevent network flooding in some cases. Defaults to 0.8 seconds.retrans_time_ms.app_solicit). Defaults to 3.The struct arpreq changed in Linux 2.0 to include the arp_dev member and the ioctl numbers changed at the same time. Support for the old ioctls was dropped in Linux 2.2.
Support for proxy arp entries for networks (netmask not equal 0xffffffff) was dropped in Linux 2.2. It is replaced by automatic proxy arp setup by the kernel for all reachable hosts on other interfaces (when forwarding and proxy arp is enabled for the interface).
The neigh/* interfaces did not exist before Linux 2.2.
Some timer settings are specified in jiffies, which is architecture- and kernel version-dependent; see time(7).
There is no way to signal positive feedback from user space. This means connection-oriented protocols implemented in user space will generate excessive ARP traffic, because ndisc will regularly reprobe the MAC address. The same problem applies for some kernel protocols (e.g., NFS over UDP).
This man page mashes together functionality that is IPv4-specific with functionality that is shared between IPv4 and IPv6.
This page is part of release 5.10 of the Linux man-pages project. A description of the project, information about reporting bugs, and the latest version of this page, can be found at https://www.kernel.org/doc/man-pages/.
Generated by phpman v4.9.26-1-g511901d · Markdown · JSON · MCP Author: Che Dong Under GNU General Public License
2026-08-04 12:37 @216.73.216.183
CrawledBy Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)
Enhanced by LLM: deepseek-v4-flash / taotoken.net / www.chedong.com - original format