macs4days

Bulk MAC Address Parser & Vendor Lookup

Reading ARP tables

Every platform prints the same core facts in a different shape, uses different column names, and sometimes uses the same name for fields with different meanings. Here is how to read each format, and what an ARP entry does and does not prove.

What an ARP table actually is

An ARP cache stores IPv4-to-link-layer mappings for next hops on an attached link. When no usable mapping exists, a device usually broadcasts an ARP request on that link and may cache the reply with its outgoing interface and some notion of how stale the entry is.

Three consequences follow, and all three catch people out. Ordinary ARP broadcasts do not cross a router, though proxy ARP can create mappings for off-link addresses. Dynamic entries only reflect recent traffic and expire on their own schedule, while static, local, and proxy entries can persist. A device that is powered on and silent may be missing, and a table read two minutes apart may not be the same table.

IPv6 does not use ARP. Neighbor Discovery performs address resolution and reachability detection; use ip -6 neighbor on Linux or, for example, show ipv6 neighbors on Cisco IOS and IOS-XE. The cache is similar, but Neighbor Discovery also tracks router and reachability information.

Not the same thing as a MAC address table

The two get confused constantly, and they answer different questions on different boxes.

Detail ARP table MAC address table
Maps IP address to MAC address MAC address to switch port and VLAN
Lives on IPv4 nodes on ARP-capable links Layer 2 switches and software bridges
Answers The cached link-layer destination for this IPv4 next hop The port and VLAN where this source MAC was last learned
Typical command show ip arp show mac address-table

Tracing usually needs both: the gateway's ARP cache supplies a MAC, then each switch's MAC table shows where that MAC was last learned. An uplink usually means keep walking; an access port identifies the next attachment point, not necessarily the endpoint itself.

The same entry in different formats

One host, 10.0.0.51 at 00:1b:21:3c:4d:5e, as each platform might print it. These are illustrative examples with shared sample addresses; exact columns and flags vary by release.

Cisco IOS and IOS-XE

Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  10.0.0.51              12   001b.213c.4d5e  ARPA   Vlan191

Age is in minutes. A dash means the entry is local or otherwise not aged. NX-OS uses a different column layout and commonly renders age as a duration such as 00:04:12, so retain its header.

Linux, iproute2

10.0.0.51 dev eth0 lladdr 00:1b:21:3c:4d:5e REACHABLE

The default output has no age column. The trailing word is the entry's neighbour state, covered below.

Linux net-tools, arp -a

server.lan (10.0.0.51) at 00:1b:21:3c:4d:5e [ether] on eth0
? (10.0.0.52) at 00:50:56:9a:1b:2c [ether] on eth0

The leading name comes from local name resolution, such as DNS or a hosts file, not from the peer. A question mark means no name was resolved, which says nothing about the host.

macOS (BSD-style output)

? (10.0.0.51) at 0:1b:21:3c:4d:5e on en0 ifscope [ethernet]

Note the first octet: 0:, not 00:. macOS can omit the leading zero from any one-digit octet, so tooling must normalize each colon-separated octet before matching the address.

Windows

Interface: 10.0.0.50 --- 0xf
  Internet Address      Physical Address      Type
  10.0.0.51             00-1b-21-3c-4d-5e     dynamic
  10.0.0.255            ff-ff-ff-ff-ff-ff     static

Windows uses hyphens, hexadecimal case may vary, and no age is shown. The 0xf in the interface header is a hexadecimal interface index, not a VLAN. Automatically generated broadcast and multicast mappings may appear as static entries, but the exact rows and ordering vary.

Juniper

MAC Address        Address     Name        Interface      Flags
00:1b:21:3c:4d:5e  10.0.0.51   server.lan  ge-0/0/1.100   none

MAC first, then IP. The suffix after the dot is the Junos logical unit number. Operators sometimes choose a unit number matching the VLAN ID, but that relationship depends on the configuration.

HPE, Aruba, Huawei, MikroTik

HPE/Aruba    10.0.0.51    001b21-3c4d5e   dynamic   1/1/1
Huawei/H3C   10.0.0.51    001b-213c-4d5e  20  D  GE0/0/1
MikroTik      0 DC 10.0.0.51 00:1B:21:3C:4D:5E ether1

These labeled excerpts compare notation; the platform labels are not part of the command output. HPE and Aruba product families do not all use the same layout. MikroTik places a row index and flags before the address; D means dynamic and C means complete in this example. Read the legend printed by your RouterOS release for its full flag set.

The age column is not comparable across platforms

On many Cisco IOS interfaces, the default ARP timeout is four hours, while many Cisco switch MAC tables default to 300 seconds. If the MAC entry expires first, the router still emits a unicast frame, but the switch treats its destination MAC as unknown and floods it within the VLAN until the address is learned again.

Windows arp -a shows only dynamic or static. Some BSD variants show time remaining until expiry. Default Linux ip neighbor output emphasizes state, though extended output can expose timing. Neither an old nor a fresh entry proves that the endpoint is currently healthy.

Reading Linux neighbour states

The state word at the end of an ip neighbor line tells you what the kernel currently believes about the neighbour. It distinguishes an entry awaiting resolution from one that is simply due for revalidation.

State What it means
REACHABLE Positive reachability confirmation arrived recently; valid until the reachability timeout expires.
STALE Known but unconfirmed. Perfectly normal; it will be revalidated when next used.
DELAY Waiting a moment for upper-layer confirmation before probing.
PROBE Unicast probes are in progress; no positive confirmation has arrived yet.
FAILED The probe limit was exceeded. Endpoint, link, filtering, or transient failures can cause this.
INCOMPLETE Address resolution has not yet completed.
PERMANENT Valid indefinitely and removable administratively.
NOARP Valid without neighbour validation attempts, but removable when its lifetime expires.

The default listing omits NOARP and NONE entries. Use ip neighbor show nud all when you need every state.

Incomplete entries and all-zero addresses

When resolution is pending or has failed, a platform may retain a row while omitting the hardware address or marking it incomplete:

Internet  10.0.0.77   0   Incomplete        ARPA  Vlan1
10.0.0.77 dev eth0  INCOMPLETE
? (10.0.0.77) at (incomplete) on en0

All three say that no usable mapping has yet been resolved. An all-zero hardware address is a placeholder, not a device; a naive OUI lookup may label it Xerox because 00:00:00 is genuinely registered.

Rows like these are worth reading rather than skipping. Many incompletes can indicate offline destinations, scanning, filtering, or a subnet mask or VLAN mismatch. Investigate rather than assuming one cause.

Where an ARP table will mislead you

Several entirely normal configurations produce entries that mean something other than "this device has this IP".

What you see Possible explanation
Many IPs sharing one MAC One interface owning several IPs, a virtual MAC, or proxy ARP. NAT alone does not establish the cause.
A gateway MAC starting 00:00:0c:07:ac The standard HSRPv1 virtual MAC range. The active router using it can change without notice; HSRPv2 uses a different range.
A gateway MAC starting 00:00:5e:00:01 The standard IPv4 VRRP virtual MAC range. IPv6 VRRP uses 00:00:5e:00:02.
One MAC associated with different IPs over time DHCP reassignment or an endpoint changing its IP configuration.
Two MACs claiming the same IP in one capture Duplicate addressing, planned failover, or ARP spoofing. A single mapping does not rule out spoofing.

Capturing output that stays readable

Most of the mess in pasted output is paging. Turn it off before you run the command: terminal length 0 on Cisco, | no-more on Juniper, screen-length 0 temporary on Huawei. Otherwise, the pager can insert prompts and terminal-control characters into copied output.

Keep the header row: it identifies otherwise ambiguous columns, such as age and VLAN, and makes parsing more reliable. Keeping the command line and prompt above the output provides useful context too.

What macs4days does with ARP output

The parser accepts the MAC notations illustrated above in one mixed paste. It finds recognized MAC addresses first and then extracts surrounding fields; an unfamiliar row layout may still yield a MAC and nearby context, but is not guaranteed to parse completely. The abbreviated HPE/Aruba example yields its MAC and IP, but its numeric port 1/1/1 is not extracted. Keep the original output when a missing field matters.

When a table header is present, it is used: labels such as Hardware Addr, Physical Address, Age, Type, Interface, and Name are matched to their column positions, and values are read from the columns rather than guessed from the line. Without a header, it falls back to positional rules that know what Cisco, HPE, and MikroTik rows look like.

The extras worth knowing about:

  • Hostnames are taken from the arp -a form, and a bare ? is correctly read as no hostname.
  • REACHABLE, STALE, NOARP, and PERMANENT become the entry type.
  • Interface names are shortened the way the CLI does it, so TenGigabitEthernet1/1/1 becomes Te1/1/1 and Port-channel10 becomes Po10.
  • A VLAN interface fills in both the interface and the VLAN.
  • A Juniper logical unit such as ge-0/0/1.100 contributes VLAN 100 as a heuristic that must be checked against the configuration.

Things that look like data, but are not, get left alone. The interface index in a Windows arp -a header is not read as a VLAN, octets of an IP address are not read as VLAN numbers, the reserved VLAN IDs 0 and 4095 are dropped, and an all-zero address on an incomplete row is skipped rather than resolved to its registered owner. Rows are keyed by normalized MAC address, so repeated sightings are merged; verify merged IP, interface, and VLAN values rather than assuming they describe one physical host or preserve an association between each IP and interface. Lines with no recognized MAC are kept and shown separately, even if they contain IP addresses or other useful text.

Sources and further reading

For command details, see the iproute2 neighbour manual, Windows ARP reference, Junos show arp reference, and RouterOS networking fundamentals. Cisco documents ARP ageing and ARP and MAC-table timeout interactions. The virtual address ranges are specified in RFC 2281 (HSRP) and RFC 9568 (VRRP).

For the addresses themselves, read MAC address formats and OUI and IEEE registries.