Reading ARP tables
Every platform prints the same core facts in a different shape, uses different column names, and sometimes uses the same name for fields with different meanings. Here is how to read each format, and what an ARP entry does and does not prove.
What an ARP table actually is
An ARP cache stores IPv4-to-link-layer mappings for next hops on an attached link. When no usable mapping exists, a device usually broadcasts an ARP request on that link and may cache the reply with its outgoing interface and some notion of how stale the entry is.
Three consequences follow, and all three catch people out. Ordinary ARP broadcasts do not cross a router, though proxy ARP can create mappings for off-link addresses. Dynamic entries only reflect recent traffic and expire on their own schedule, while static, local, and proxy entries can persist. A device that is powered on and silent may be missing, and a table read two minutes apart may not be the same table.
IPv6 does not use ARP. Neighbor Discovery performs address resolution and reachability detection; use
ip -6 neighbor on Linux or, for example,
show ipv6 neighbors on Cisco IOS and IOS-XE. The cache is similar, but Neighbor Discovery also
tracks router and reachability information.
Not the same thing as a MAC address table
The two get confused constantly, and they answer different questions on different boxes.
| Detail | ARP table | MAC address table |
|---|---|---|
| Maps | IP address to MAC address | MAC address to switch port and VLAN |
| Lives on | IPv4 nodes on ARP-capable links | Layer 2 switches and software bridges |
| Answers | The cached link-layer destination for this IPv4 next hop | The port and VLAN where this source MAC was last learned |
| Typical command | show ip arp | show mac address-table |
Tracing usually needs both: the gateway's ARP cache supplies a MAC, then each switch's MAC table shows where that MAC was last learned. An uplink usually means keep walking; an access port identifies the next attachment point, not necessarily the endpoint itself.
The same entry in different formats
One host, 10.0.0.51 at 00:1b:21:3c:4d:5e, as each
platform might print it. These are illustrative examples with shared sample addresses; exact columns and flags vary by release.
Cisco IOS and IOS-XE
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.0.0.51 12 001b.213c.4d5e ARPA Vlan191
Age is in minutes. A dash means the entry is local or otherwise not aged. NX-OS uses a different column layout and commonly renders age as a
duration such as 00:04:12, so retain its header.
Linux, iproute2
10.0.0.51 dev eth0 lladdr 00:1b:21:3c:4d:5e REACHABLE
The default output has no age column. The trailing word is the entry's neighbour state, covered below.
Linux net-tools, arp -a
server.lan (10.0.0.51) at 00:1b:21:3c:4d:5e [ether] on eth0
? (10.0.0.52) at 00:50:56:9a:1b:2c [ether] on eth0
The leading name comes from local name resolution, such as DNS or a hosts file, not from the peer. A question mark means no name was resolved, which says nothing about the host.
macOS (BSD-style output)
? (10.0.0.51) at 0:1b:21:3c:4d:5e on en0 ifscope [ethernet]
Note the first octet: 0:, not 00:. macOS can omit the
leading zero from any one-digit octet, so tooling must normalize each colon-separated octet before matching the address.
Windows
Interface: 10.0.0.50 --- 0xf
Internet Address Physical Address Type
10.0.0.51 00-1b-21-3c-4d-5e dynamic
10.0.0.255 ff-ff-ff-ff-ff-ff static
Windows uses hyphens, hexadecimal case may vary, and no age is shown. The 0xf in the interface
header is a hexadecimal interface index, not a VLAN. Automatically generated broadcast and multicast mappings may appear as static entries,
but the exact rows and ordering vary.
Juniper
MAC Address Address Name Interface Flags
00:1b:21:3c:4d:5e 10.0.0.51 server.lan ge-0/0/1.100 none
MAC first, then IP. The suffix after the dot is the Junos logical unit number. Operators sometimes choose a unit number matching the VLAN ID, but that relationship depends on the configuration.
HPE, Aruba, Huawei, MikroTik
HPE/Aruba 10.0.0.51 001b21-3c4d5e dynamic 1/1/1
Huawei/H3C 10.0.0.51 001b-213c-4d5e 20 D GE0/0/1
MikroTik 0 DC 10.0.0.51 00:1B:21:3C:4D:5E ether1
These labeled excerpts compare notation; the platform labels are not part of the command output. HPE and Aruba product families do not all use
the same layout. MikroTik places a row index and flags before the address;
D means dynamic and C means complete in this example.
Read the legend printed by your RouterOS release for its full flag set.
The age column is not comparable across platforms
On many Cisco IOS interfaces, the default ARP timeout is four hours, while many Cisco switch MAC tables default to 300 seconds. If the MAC entry expires first, the router still emits a unicast frame, but the switch treats its destination MAC as unknown and floods it within the VLAN until the address is learned again.
Windows arp -a shows only dynamic or
static. Some BSD variants show time remaining until expiry. Default Linux
ip neighbor output emphasizes state, though extended output can expose timing. Neither an old nor
a fresh entry proves that the endpoint is currently healthy.
Reading Linux neighbour states
The state word at the end of an ip neighbor line tells you what the kernel currently believes
about the neighbour. It distinguishes an entry awaiting resolution from one that is simply due for revalidation.
| State | What it means |
|---|---|
| REACHABLE | Positive reachability confirmation arrived recently; valid until the reachability timeout expires. |
| STALE | Known but unconfirmed. Perfectly normal; it will be revalidated when next used. |
| DELAY | Waiting a moment for upper-layer confirmation before probing. |
| PROBE | Unicast probes are in progress; no positive confirmation has arrived yet. |
| FAILED | The probe limit was exceeded. Endpoint, link, filtering, or transient failures can cause this. |
| INCOMPLETE | Address resolution has not yet completed. |
| PERMANENT | Valid indefinitely and removable administratively. |
| NOARP | Valid without neighbour validation attempts, but removable when its lifetime expires. |
The default listing omits NOARP and NONE entries. Use ip neighbor show nud all when you need every
state.
Incomplete entries and all-zero addresses
When resolution is pending or has failed, a platform may retain a row while omitting the hardware address or marking it incomplete:
Internet 10.0.0.77 0 Incomplete ARPA Vlan1
10.0.0.77 dev eth0 INCOMPLETE
? (10.0.0.77) at (incomplete) on en0
All three say that no usable mapping has yet been resolved. An all-zero hardware address is a placeholder, not a device; a naive OUI lookup
may label it Xerox because 00:00:00 is genuinely registered.
Rows like these are worth reading rather than skipping. Many incompletes can indicate offline destinations, scanning, filtering, or a subnet mask or VLAN mismatch. Investigate rather than assuming one cause.
Where an ARP table will mislead you
Several entirely normal configurations produce entries that mean something other than "this device has this IP".
| What you see | Possible explanation |
|---|---|
| Many IPs sharing one MAC | One interface owning several IPs, a virtual MAC, or proxy ARP. NAT alone does not establish the cause. |
A gateway MAC starting 00:00:0c:07:ac |
The standard HSRPv1 virtual MAC range. The active router using it can change without notice; HSRPv2 uses a different range. |
A gateway MAC starting 00:00:5e:00:01 |
The standard IPv4 VRRP virtual MAC range. IPv6 VRRP uses 00:00:5e:00:02. |
| One MAC associated with different IPs over time | DHCP reassignment or an endpoint changing its IP configuration. |
| Two MACs claiming the same IP in one capture | Duplicate addressing, planned failover, or ARP spoofing. A single mapping does not rule out spoofing. |
Capturing output that stays readable
Most of the mess in pasted output is paging. Turn it off before you run the command:
terminal length 0 on Cisco, | no-more on Juniper,
screen-length 0 temporary on Huawei. Otherwise, the pager can insert prompts and terminal-control
characters into copied output.
Keep the header row: it identifies otherwise ambiguous columns, such as age and VLAN, and makes parsing more reliable. Keeping the command line and prompt above the output provides useful context too.
What macs4days does with ARP output
The parser accepts the MAC notations illustrated above in one mixed paste. It finds recognized MAC
addresses first and then extracts surrounding fields; an unfamiliar row layout may still yield a MAC and nearby context, but is not guaranteed
to parse completely. The abbreviated HPE/Aruba example yields its MAC and IP, but its numeric port
1/1/1 is not extracted. Keep the original output when a missing field matters.
When a table header is present, it is used: labels such as
Hardware Addr, Physical Address,
Age, Type,
Interface, and Name are matched to their column
positions, and values are read from the columns rather than guessed from the line. Without a header, it falls back to positional rules that
know what Cisco, HPE, and MikroTik rows look like.
The extras worth knowing about:
-
Hostnames are taken from the
arp -aform, and a bare?is correctly read as no hostname. -
REACHABLE,STALE,NOARP, andPERMANENTbecome the entry type. -
Interface names are shortened the way the CLI does it, so
TenGigabitEthernet1/1/1becomesTe1/1/1andPort-channel10becomesPo10. - A VLAN interface fills in both the interface and the VLAN.
-
A Juniper logical unit such as
ge-0/0/1.100contributes VLAN 100 as a heuristic that must be checked against the configuration.
Things that look like data, but are not, get left alone. The interface index in a Windows
arp -a header is not read as a VLAN, octets of an IP address are not read as VLAN numbers, the
reserved VLAN IDs 0 and 4095 are dropped, and an all-zero address on an incomplete row is skipped rather than resolved to its registered
owner. Rows are keyed by normalized MAC address, so repeated sightings are merged; verify merged IP, interface, and VLAN values rather than
assuming they describe one physical host or preserve an association between each IP and interface. Lines with no recognized MAC are kept and
shown separately, even if they contain IP addresses or other useful text.
Sources and further reading
For command details, see the iproute2 neighbour manual, Windows ARP reference, Junos show arp reference, and RouterOS networking fundamentals. Cisco documents ARP ageing and ARP and MAC-table timeout interactions. The virtual address ranges are specified in RFC 2281 (HSRP) and RFC 9568 (VRRP).
For the addresses themselves, read MAC address formats and OUI and IEEE registries.