Use /etc/ethers to Load Static Ethernet Mappings Safely
You will create a small /etc/ethers database, check its syntax, and load its entries into the legacy net-tools ARP cache. The guide uses net-tools 2.10-0.1ubuntu4.4, installed on this machine. The file is useful when you need a repeatable Ethernet address to IPv4 mapping, but it is not itself the kernel's live ARP table.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about fifteen minutes. You need a shell and an Ethernet address and IPv4 address that you have already verified. Editing /etc/ethers requires elevated privileges. Reading it does not. Loading entries with arp -f changes live network state and normally requires root or the relevant network administration privilege.
1. Check the installed tools
Start with read-only checks so you know which implementation and binary you are using:
$ dpkg-query -W -f='${Package} ${Version}\n' net-tools
net-tools 2.10-0.1ubuntu4.4
$ command -v arp
/usr/sbin/arp
Your package version may differ. The ethers(5) page supplied by this package describes the database format; arp(8) documents the command that can read it. Checkpoint: if net-tools is not installed, stop here and use the networking tooling already supported by your distribution rather than assuming this legacy command is available.
2. Prepare one mapping
Each useful line in /etc/ethers has an Ethernet address followed by an IP number. Separate the two fields with spaces or tabs:
# MAC address IPv4 address or resolvable host name
02:00:5e:10:20:30 192.0.2.44
The six hexadecimal fields represent the six bytes of a 48-bit Ethernet address. Each field is from 00 to ff; the address is written in network byte order. The second field can be a dotted-decimal address or a hostname that DNS can resolve.
The example uses 192.0.2.44, from the documentation-only IPv4 range. Replace it with an address you control, and replace the example MAC address with the address printed on your own equipment. Do not copy a MAC address from a different interface or device: a syntactically valid mapping can still be operationally wrong.
A line beginning with # is a comment through the end of that line. Blank lines are harmless. Keep comments on their own lines while testing, so a typo is easier to spot.
3. Install the file with a backup
First inspect the current file. This is an ordinary read-only command, although the file may not exist:
$ sudo sed -n '1,120p' /etc/ethers
sed: can't read /etc/ethers: No such file or directory
If it exists, preserve its contents before editing. This changes no network state:
$ sudo cp -p /etc/ethers /etc/ethers.backup
Now edit the file as root with an editor you know how to use:
$ sudoedit /etc/ethers
Add your mapping in the format above. Do not use shell redirection with an unquoted, untrusted value. Do not replace an existing file blindly: it may contain mappings another service or administrator relies on.
Checkpoint: inspect the result and confirm the exact address and host value:
$ sudo sed -n '1,120p' /etc/ethers
02:00:5e:10:20:30 192.0.2.44
4. Load the mapping into the ARP cache
Warning
This step changes live kernel networking state. A wrong MAC address can send traffic to the wrong machine or make the address unreachable. Test one entry on a maintenance window or a host where a temporary connectivity change is acceptable.
The net-tools loader reads the file with -f. With no filename, /etc/ethers is its default:
$ sudo arp -f /etc/ethers
The ethers(5) format places the hardware address first. The arp(8) documentation describes its file format as hostname then hardware address and also documents the historical compatibility exception that permits the order to be exchanged. That is why the standard /etc/ethers example can be passed to this command.
To load a test file without editing /etc/ethers, use an explicit path. Create it from a reviewed file in a directory you control, then remove it after the test:
$ install -m 600 /etc/ethers /tmp/ethers-test
$ sudo arp -f /tmp/ethers-test
$ rm -- /tmp/ethers-test
The first command above is ordinary only when you have permission to read the source and write the destination. The load still needs elevated privileges. The final command removes the temporary copy; it does not undo the live ARP entry.
5. Verify live state separately
Inspect the kernel's ARP table after loading. Use numeric output so a name lookup does not obscure what was installed:
$ arp -n 192.0.2.44
Address HWtype HWaddress Flags Mask Iface
192.0.2.44 ether 02:00:5e:10:20:30 CM eth0
Interface names, columns and flags vary by host. The useful checks are that the requested IPv4 address appears, the hardware address matches, and the interface is the one that should carry the traffic. If there is no entry, check the command's error output, the mapping's field order, the address format, and the route to the IPv4 address.
Do not treat a successful edit as proof that the kernel accepted an entry. The database file is persistent text; the ARP cache is live state and can expire, be replaced, or differ after a reboot. If you need the entry after boot, arrange an explicit, reviewed service or network configuration for your platform rather than assuming /etc/ethers is automatically loaded.
6. Recover from a bad test
If the mapping is wrong, remove the live entry by IPv4 address. This is another state-changing operation and requires root or network administration privilege:
$ sudo arp -d 192.0.2.44
Then restore the text file if you changed an existing configuration:
$ sudo cp -p /etc/ethers.backup /etc/ethers
If you created /etc/ethers from scratch, remove it only after checking that no other configuration depends on it:
$ sudo rm -- /etc/ethers
Deleting the file does not delete an already loaded ARP entry, which is why the separate arp -d step matters. If you are unsure which entry is safe to remove, stop and inspect arp -n before making another change.
Done means
/etc/etherscontains reviewed MAC and IPv4 pairs, with comments and whitespace used only as intended.arp -fcompleted without an error for the file you tested.arp -n ADDRESSshows the expected hardware address and interface, where the kernel accepted the entry.- You know whether the mapping is only a current ARP-cache entry or is also loaded by a persistent service after reboot.
- You have a backup or a deliberate removal plan before changing another host.