Articles

ARP and Neighbor Discovery: resolving the next hop, not the destination

Why IPv4 ARP and IPv6 Neighbor Discovery map a layer-3 address to a layer-2 address on the local link, what each protocol actually does, and where their trust model breaks.

Reading: 4 minNetworking

Article cover: ARP and Neighbor Discovery: resolving the next hop, not the destination

IPv4 and IPv6 both need a MAC address before a host can put a packet on the wire. ARP does this for IPv4; Neighbor Discovery (ND) does it for IPv6, together with router and prefix discovery. Both resolve the address of the next hop on the local link — the destination if it is on-link, otherwise the router — and neither locates a host several hops away.

Read both protocols through this sequence:

destination IP
      ↓
routing decision (prefix match against the on-link prefixes)
      ↓
next hop  — the destination itself if on-link, otherwise a router
      ↓
ARP / Neighbor Discovery
      ↓
MAC address of that next hop
      ↓
Ethernet frame addressed to it

A node chooses the next hop first: a longest-prefix match against its on-link prefix list yields the destination if it is on-link, otherwise a router from the default-router list (RFC 4861 §5.2). Only then does it need a MAC address for that hop. IPv4 behaves the same way implicitly — a route for a remote destination points at a router, and ARP resolves that router. The rest of this sheet applies that model twice: ARP, then ND.

Terms. On-link: reachable without a router. Next hop: the node the packet is handed to at this step. MAC (Media Access Control) address: the identifier a frame is addressed to; link-layer address is the broader term for non-Ethernet media.

Why a layer-3 address must be resolved at layer 2

An IP address is a logical identifier, while a frame is delivered by a MAC address. Protocol addresses are not 48-bit link addresses and need not relate to them, so a mapping step is required before a frame can be sent (RFC 826). On an IPv4 link that step is ARP; on an IPv6 link it is the address-resolution part of ND.

ARP for IPv4

ARP is a request-and-reply exchange. To learn the MAC address of a target IP, the sender broadcasts a request carrying its own MAC and protocol addresses and the target’s protocol address, leaving the target MAC field empty; the station that owns the target IP answers with a unicast reply carrying its MAC address (RFC 826). Both sides keep an ARP cache. The receive algorithm merges the sender’s addresses into the table before it examines the opcode, assuming that communication is bidirectional, and RFC 826 leaves table ageing and timeouts to the implementation. One consequence follows: any reply is accepted, because the protocol defines no way to verify that the sender owns the address it claims.

Host A                                     Next hop (on-link device or router)
  |  ARP request   broadcast: who has <target IP>?   |
  |--------------------------------------------------|
  |  ARP reply     unicast: <target IP> is at <MAC>  |
  |<-------------------------------------------------|
  |  frame now addressed to that MAC                 |

Neighbor Discovery for IPv6

ND moves the job to ICMPv6 and folds together functions IPv4 spreads over ARP, ICMP Router Discovery and ICMP Redirect: router and prefix discovery, address resolution, next-hop determination, Neighbor Unreachability Detection (NUD) and Redirect (RFC 4861 §3.1). Router Solicitation and Router Advertisement let hosts find routers and learn on-link prefixes; Neighbor Solicitation (NS) and Neighbor Advertisement (NA) perform address resolution. Unlike ARP’s broadcast, an NS goes to a solicited-node multicast address derived from the target address, so only the likely owner is interrupted (RFC 4861 §7.2.2; RFC 4291 §2.7.1). The reply is unicast to the soliciting source, and multicast to the all-nodes address only when that source was unspecified (RFC 4861 §7.2.4). Results live in a Neighbor Cache, with reachability state that ARP lacks. Address autoconfiguration (SLAAC) and Duplicate Address Detection reuse the same NS/NA machinery; both are separate subjects, not developed here.

Aspect ARP (IPv4) Neighbor Discovery (IPv6)
Encapsulation its own Ethernet type (RFC 826) ICMPv6 messages over IPv6
Request transport broadcast to all stations solicited-node multicast
Reply transport unicast unicast; multicast only for DAD
Also provides address resolution only router/prefix discovery, redirect, NUD, DAD
Local state ARP cache Neighbor Cache

Resolution is local: one lookup per hop

A packet crossing several routers is resolved once per hop: the source resolves the first router, each router resolves the next, and the last router resolves the destination host. The remote host’s MAC address is never known to the source, and never needs to be.

A common misconception

A frequent error is to read an ARP entry, or a packet capture, as proof that ARP “found” the destination computer. When the destination is off-link, the address ARP returns belongs to the next-hop router, not to the far host. The table maps addresses inside the local segment only. Reading a local table (ip neigh on Linux) with that in mind avoids a common misdiagnosis.

Security: unauthenticated by default

Neither ARP nor ND authenticates messages by default. RFC 826 defines no cryptographic protection, so a receiver updates its table from a reply it cannot verify. RFC 4861 names denial of service, address spoofing and router spoofing as ND’s main threats, states that a node cannot check whether a Neighbor Advertisement’s sender owns the address, and limits off-link interference by accepting ND packets only with Hop Limit 255 (§§11.1–11.2).

The exposure is inherent — a node on the link can answer for another node’s address — while whether it is exploitable depends on position, because it requires access to the same layer-2 link and stays confined to that domain. The mitigation therefore sits in the switch or in an optional extension of ND, not in the protocol: Dynamic ARP Inspection, ND inspection, Router Advertisement guard, and the cryptographic option SEND (RFC 3971). Their mechanisms, dependencies and limits are material for a separate sheet.

Level and prerequisites. L1 — fundamentals. Prerequisites: what an IP address is, the idea of a MAC address and a frame, and a rough sense of what a router and a default gateway are. No configuration experience is required.

Where to go next

References

  • RFC 826 — An Ethernet Address Resolution Protocol (ARP).
  • RFC 4861 — Neighbor Discovery for IP version 6 (IPv6).
  • RFC 4862 — IPv6 Stateless Address Autoconfiguration.
  • RFC 4291 — IP Version 6 Addressing Architecture.
  • RFC 3971 — SEcure Neighbor Discovery (SEND).