Inspect and Safely Change the Linux ARP Cache with arp

A host that will not answer on the network often comes down to a stale or wrong entry in the Linux ARP cache, which arp lets you inspect and fix. By the end you can read this host's IPv4 ARP cache, narrow it to one interface, add a temporary mapping when you have a genuine reason, and remove it again. The examples use arp from net-tools 2.10, package version 2.10-0.1ubuntu4.4.

Allow about fifteen minutes. You need a shell and an IPv4 interface. Reading the cache is harmless; adding or deleting an entry changes kernel networking state and normally needs root or netadmin privilege, so test somewhere a brief neighbour-resolution hiccup is acceptable. This guide never flushes the whole cache or touches persistent network configuration.

1. Check the installed command

Confirm the executable and package before you trust any example, including this one. These checks are read-only and need no sudo:

$ command -v arp
/usr/sbin/arp
$ arp -V
net-tools 2.10
+I18N +SELINUX
AF: (inet) +UNIX +INET +INET6 +IPX +AX25 +NETROM +X25 +ATALK +ECONET +ROSE -BLUETOOTH
HW: (ether) +ETHER +ARC +SLIP +PPP +TUNNEL -TR +AX25 +NETROM +X25 +FR +ROSE +ASH +SIT +FDDI +HIPPI +HDLC/LAPB +EUI64
$ dpkg-query -W -f='${Package} ${Version}\n' net-tools
net-tools 2.10-0.1ubuntu4.4

arp is an older net-tools interface for the IPv4 neighbour cache, so do not assume syntax from a different network tool applies. On newer systems ip neighbour may be preferred, but this guide sticks to the installed arp(8) contract.

Checkpoint: you have confirmed the binary and package version before relying on anything below.

2. Read the cache without changing it

Run arp with no mode option, adding -n so addresses stay numeric instead of triggering name resolution:

$ arp -n
Address                  HWtype  HWaddress           Flags Mask            Iface
192.0.2.15               ether   02:00:00:12:34:56   C                     eth0

Your addresses and interfaces will differ. C marks a complete entry, M a permanent one, P a published one. An incomplete entry can appear while the kernel is still resolving a neighbour, so never copy one of those rows as a usable MAC mapping.

-e gives the fixed-column Linux format above; -a gives an alternate BSD-style format without fixed columns. Pick one and stick to it if a script or runbook consumes the output, and remember it is a live snapshot, not a durable inventory.

To narrow the view to one interface, add -i:

$ arp -n -i eth0
Address                  HWtype  HWaddress           Flags Mask            Iface
192.0.2.15               ether   02:00:00:12:34:56   C                     eth0

No matching row does not prove the address is offline. The entry may simply have expired, belong to another interface, or sit in a different neighbour state.

3. Add a temporary mapping only when you need one

Use -s with an IPv4 address and an Ethernet MAC address. This changes the cache, so it needs elevated privilege:

$ sudo arp -i eth0 -s 192.0.2.15 02:00:00:12:34:56 temp
$ arp -n -i eth0 192.0.2.15
Address                  HWtype  HWaddress           Flags Mask            Iface
192.0.2.15               ether   02:00:00:12:34:56   C                     eth0

The temp flag asks for a temporary entry. Leave it off and the manual says the entry is stored permanently in the cache instead, which does not mean it survives a reboot or belongs in a network manager config; it just describes the kernel cache entry. Do not drop temp without a documented reason.

Use real values from your own network. Never invent an address on a production interface just to see some output: a wrong mapping can misdirect traffic or make a host unreachable.

Checkpoint: verify the exact row and interface after adding it. Wrong MAC or interface means stop using it and remove it in the next step.

4. Remove an entry and recover from a bad mapping

Deletion is also a privileged state change. Delete by IP address, choosing the interface if the host has more than one:

$ sudo arp -i eth0 -d 192.0.2.15
$ arp -n -i eth0 192.0.2.15
arp: in 0 entries no match found.

The exact wording and count vary by build. What matters is that the specific address no longer appears in the filtered listing. If it reappears, the kernel likely re-resolved it through normal ARP traffic, not a failed deletion.

If an entry was wrong, delete it and let normal resolution rebuild the correct one. Do not reach for a broad cache-clearing command as a first response: arp(8) documents deleting one address, not a harmless undo for everything. Keep the original address and interface in your shell history or change record so the recovery command is unambiguous.

5. Understand interface selection and hardware type

For a read, -i IFACE filters what is shown. For an add, it associates the new entry with that interface; leave it off and the kernel guesses from the routing table. For a published entry, the chosen interface is where ARP requests get answered, and the manual warns it must differ from the interface the IP datagrams are actually routed through.

The default hardware class is ether, which covers most current wired, wireless and virtual Ethernet interfaces. Select a class explicitly with -H:

$ arp -n -H ether -i eth0

Other classes this version lists include arcnet, pronet, ax25 and netrom. Do not pick one just because it appears in the list; it has to match the actual hardware type of the interface and entry you are managing.

6. Treat proxy ARP as a separate, riskier operation

Proxy ARP makes this host answer ARP requests for another IPv4 address. It can affect traffic for other machines, so it is not a casual connectivity test. The manual's device form takes the MAC address from an interface:

$ sudo arp -i eth0 -Ds 192.0.2.50 eth1 pub
$ arp -n -i eth0 192.0.2.50
Address                  HWtype  HWaddress           Flags Mask            Iface
192.0.2.50               ether   02:00:00:aa:bb:cc   P                     eth0

The MAC shown is host-specific, so treat that output as illustrative. -D takes the address from eth1; pub marks the entry published. Before doing this for real, document the route, forwarding policy, affected peers and rollback command. Undo the example with:

$ sudo arp -i eth0 -d 192.0.2.50

For a modern routed subnet design, check the route and forwarding configuration rather than assuming a proxy entry is the right fix. The local manual also notes that Linux has automatic proxy ARP behaviour under suitable forwarding and route setups, and that subnet-wide ARP entries are no longer set the old way.

7. Load several entries from a file when the change is deliberate

For a documented batch, -f reads whitespace-separated hostname and hardware-address lines, defaulting to /etc/ethers if you give no filename:

$ sudo arp -f /path/to/arp-entries.txt
$ arp -n -i eth0

The file may also carry pub, temp and netmask flags. Review it before running the command, restrict its permissions, and keep a backup if it represents live operational configuration. One typo can install several bad mappings at once; to recover, check the full file and delete each affected address explicitly.

Done means