Check and Clean Up Legacy RARP Entries with rarp
You will learn how to inspect the system RARP table, understand the legacy rarp commands for adding and removing mappings, and recognise a kernel that cannot perform the operation. This is an administration command from the net-tools package, version 2.10-0.1ubuntu4.4 on the system used for this guide. Allow about 10 minutes for inspection. Changing a live table needs a maintenance window and a tested recovery command.
The route
Jump straight to the step you need, or tick off Done means at the end.
Before you start
RARP, the Reverse Address Resolution Protocol, was used by some machines to discover an address from a hardware address during boot. It is obsolete on modern Linux: the local rarp(8) manual says that Linux kernels no longer contain RARP support from kernel version 2.3. The command can still be installed because it is part of the compatibility-oriented net-tools package, but installation does not restore kernel support.
Use an account that can run ordinary inspection commands. Listing may work without elevated privileges, while adding or deleting a kernel table entry normally requires root. If the command reports that the kernel does not support RARP, stop there. Do not try to work around that message by repeatedly adding entries.
Checkpoint 1: confirm the command and version
- Check the installed implementation before relying on its behaviour.
command -v rarp
rarp -V
On this machine the executable is /usr/sbin/rarp, and the program reports net-tools 2.10. The installed Debian package is net-tools 2.10-0.1ubuntu4.4. The package version and the program version are related but are not the same string, so record both when troubleshooting a mixed or customised installation.
The help output on this build also mentions options not described by the supplied manual page. This guide sticks to the documented interface: -a, -d, -s, -t, -v, and the version and help switches. Do not copy an option from another release without checking that installed binary.
Checkpoint 2: list the RARP table
- Ask the kernel for the current table.
rarp -a
The documented short form is -a; the manual also lists the long form --list. A supported system returns the entries known to the kernel. The output is the evidence to save before making a change, so redirect it to a temporary file if you are investigating an old host:
rarp -a 2>/tmp/rarp-list.err | tee /tmp/rarp-list.txt
status=${PIPESTATUS[0]}
test "$status" -eq 0
On a current Linux kernel, the expected failure is This kernel does not support RARP. with a non-zero status. That is a compatibility result, not proof that the rarp executable is missing. The presence of /proc/net/rarp would be another useful check, but a missing file alone is not a reason to create one.
Checkpoint 3: understand an entry before changing it
The set form is rarp -s hostname hw_addr. For Ethernet, the hardware address is six hexadecimal bytes separated by colons. The optional -t type selects the hardware class; its default is ether, hardware code 0x01. The manual mentions ax25 and netrom as other possible classes, but the available classes depend on the program and kernel.
Do not treat a hostname as a harmless label. It identifies the host for which the mapping is created, and some older systems used a RARP reply as part of network boot. Adding an entry can therefore affect boot behaviour and can surprise the network team.
If the kernel supports RARP and you have a verified change request, the following is the shape of a root command. Replace both placeholders with values from your change record:
sudo rarp -v -s HOSTNAME 02:00:00:12:34:56
The -v switch asks for progress information. It does not make an unsupported kernel support RARP, and it does not validate that the hardware address belongs to the intended machine.
Checkpoint 4: remove a mapping and recover
The delete form removes all RARP entries for the named host. This is a state-changing operation and needs elevated privileges on systems that still implement the table:
sudo rarp -v -d HOSTNAME
There is no documented undo stack. Before deleting, capture rarp -a and confirm the exact hostname. Recovery is to add the mapping again with the recorded hardware address and hardware type:
sudo rarp -v -t ether -s HOSTNAME 02:00:00:12:34:56
That recovery only applies when the kernel supports RARP. On this machine both listing and modification fail with the same unsupported-kernel message, so there is no live RARP table to clean up. If a service or boot process still expects RARP, identify its replacement or migration plan rather than forcing this utility into service.
Common traps
- Confusing package presence with support:
dpkg -s net-toolsproves that the user-space package is installed, not that the kernel implements RARP. - Using the wrong address format: Ethernet uses six hexadecimal octets separated by colons. The format is hardware-class dependent.
- Deleting a name too broadly:
-dremoves all entries for the specified host, so check spelling and table output first. - Assuming a successful-looking command is enough: use the exit status and then run
rarp -aagain. A non-zero status or an unsupported-kernel message means the requested state was not established.
Done means
rarp -Videntified the installed implementation.rarp -aeither displayed the table or clearly reported that the kernel lacks RARP support.- Any proposed change has a recorded hostname, hardware address and hardware class.
- Any deletion was approved, captured beforehand, and has a tested re-add command.