Ethernet, ARP, and Neighbor Discovery Explained

Learn how Ethernet frames, switches, VLANs, ARP, and IPv6 Neighbor Discovery deliver packets on a local link, with Linux diagnostics and failure examples.

published: reading time: 11 min read author: GeekWorkBench
Quick Summary

Ethernet frames carry IP packets across a local link, while switches use MAC learning to forward them within a VLAN. This guide explains how IPv4 ARP and IPv6 Neighbor Discovery resolve the local next hop, how routers replace link-layer headers, and where VLAN boundaries require routing. It also walks through Linux and packet-capture checks for stale neighbors, misconfigured VLANs, and blocked ICMPv6, with security guidance for spoofing and rogue advertisements.

Ethernet, ARP, and Neighbor Discovery Explained

Introduction

An IP packet can name a host on another continent, but the first transmission still has to cross a local link: a cable, Wi-Fi network, virtual switch, or another Layer 2 segment. Ethernet carries that packet in a frame. Before sending it, an IPv4 host usually needs a MAC address for its next hop; IPv6 uses Neighbor Discovery for the same local-link job.

These pieces are often blurred together as “the network.” Keeping them separate helps when a host can reach its gateway but not a peer, or when a neighbor entry keeps going stale. Ethernet moves frames within a link, switches forward those frames, and routers choose the next network. ARP and Neighbor Discovery resolve a next-hop address on the current link. They do not discover the MAC address of a remote server across routers.

When to Use

Use this model when diagnosing a host that has an IP address and link but cannot reach a peer or gateway. First establish whether the destination is on-link or routed. Then check whether the host has a neighbor entry for the correct next hop and whether frames can cross the expected switch ports and VLAN.

It is also useful when designing or reviewing:

  • VLAN layouts and router-on-a-stick or Layer 3 switch interfaces.
  • Virtual machines, containers, bridges, and overlay networks that introduce extra Layer 2 boundaries.
  • Firewall rules for ARP-adjacent behavior or ICMPv6 Neighbor Discovery.
  • Packet captures where the IP destination and Ethernet destination differ.

When NOT to Use

Do not use ARP to look up a remote server’s MAC address. The remote server is not on the sender’s Ethernet link, so the sender resolves its gateway instead. Do not treat a successful ping to the gateway as proof that DNS, routing beyond the gateway, or the remote application works.

Do not assume that all IPv6 neighbor-resolution trouble is an “ARP issue.” IPv6 does not use ARP. Inspect ICMPv6 Neighbor Solicitation/Advertisement, router advertisements, address configuration, and firewall behavior. Likewise, a switch MAC table cannot explain a missing IP route; those are different tables maintained at different layers.

Production Failure Scenarios

Wrong VLAN or trunk configuration

The interface reports carrier and has a static IPv4 address, yet it cannot resolve the gateway. The host sends ARP requests, but the switch places its access port in the wrong VLAN or does not allow that VLAN on the trunk. The request never reaches the gateway’s Layer 2 domain. Check the switch port and VLAN configuration alongside host captures; a link light alone does not prove Layer 2 adjacency.

Stale or conflicting IPv4 neighbor entry

A service moves to a new interface or failover node, but peers keep sending frames to an old MAC address until caches refresh. Duplicate IP use can produce an even stranger symptom: replies alternate between machines. On Linux, inspect ip neigh and capture ARP traffic. Confirm ownership and DHCP/static address records before deleting entries, since flushing the cache may only hide the conflict for a moment.

ICMPv6 blocked by a host or network firewall

IPv6 traffic stalls even though the interface has a global address. A firewall rule drops Neighbor Solicitation or Advertisement messages, or router advertisements are blocked on the segment. Neighbor entries remain INCOMPLETE or FAILED. Permit the ICMPv6 types required by the network policy and inspect the path; blindly allowing or blocking all ICMPv6 can break basic IPv6 operation.

Duplicate address detection finds a collision

When IPv6 Duplicate Address Detection sees another node claim the tentative address, address assignment may fail or remain unusable. In a capture, look for Neighbor Solicitations for the tentative address and unexpected advertisements. Check static configuration, cloned VM images, and automation that may have copied addresses.

Trade-Off Table

Mechanism What it resolves or forwards Scope Operational trade-off
Ethernet switching Destination MAC to switch port One VLAN / Layer 2 domain Fast local forwarding; unknown unicast and broadcast traffic are flooded within the VLAN
IPv4 ARP IPv4 next-hop address to MAC One local link Simple and widely supported; broadcast requests and unauthenticated replies can be abused
IPv6 Neighbor Discovery IPv6 next-hop address to link-layer address One local link Uses multicast and ICMPv6; supports additional IPv6 functions, so filtering needs care
IP routing Destination IP prefix to next hop/interface Across Layer 3 networks Scales across links; every router makes a new forwarding decision and rewrites the Layer 2 header

Observability Checklist

Start on the host and follow the packet toward the switch and gateway. These commands are read-only diagnostics unless otherwise noted.

# Inspect interfaces, link state, and MAC addresses
ip link show

# See cached IPv4 and IPv6 neighbors
ip neigh show

# Watch ARP and ICMPv6 Neighbor Discovery on one interface
sudo tcpdump -ni eth0 'arp or icmp6'

# Capture Ethernet and IP headers for a particular peer
sudo tcpdump -ni eth0 -e 'host 192.0.2.20'

Replace eth0 and example addresses with the interface and peer under investigation. -e prints the link-layer header, which helps confirm whether the frame targets the peer or a gateway. On a routed path, a remote IP destination paired with the gateway’s MAC is expected.

Check each layer in order:

  1. ip link shows the expected interface, MAC address, and UP/LOWER_UP state.
  2. The route lookup selects the expected interface and next hop; a neighbor entry for that next hop appears in ip neigh.
  3. A capture shows ARP request/reply for IPv4 or Neighbor Solicitation/Advertisement for IPv6.
  4. The switch learns the host MAC on the expected port and VLAN; the gateway interface is in the same intended Layer 2 domain.
  5. Once local resolution works, test routing, firewall policy, and the application separately.

Security and Compliance Notes

ARP has no built-in authentication. On a shared or poorly controlled Layer 2 network, a malicious host can send forged replies and redirect IPv4 traffic. Controls can include port security, DHCP snooping with Dynamic ARP Inspection where supported, segmentation, and monitoring for unexpected MAC/IP changes. Apply them with care in environments that use static addresses or unusual virtualization.

IPv6 ND also needs protection. Router Advertisement Guard, Neighbor Discovery inspection, and port controls can reduce rogue-router or spoofing risks when available, but rules must allow legitimate ICMPv6. Keep packet captures and neighbor data within your organization’s retention and privacy policies; MAC addresses can identify devices or users in operational logs.

The official RFC 826 overview specifies ARP for mapping protocol addresses to local network addresses. For IPv6 neighbor resolution and related functions, consult RFC 4861.

Common Pitfalls / Anti-Patterns

  • Looking for a remote host’s MAC in the local ARP table. The local table should contain the gateway’s MAC when the destination is routed.
  • Treating INCOMPLETE or FAILED in ip neigh as a routing diagnosis. It points to local resolution trouble; routes and firewalls still need separate checks.
  • Blocking all ICMPv6 because it is assumed to be optional. ND and router discovery depend on ICMPv6 messages.
  • Assuming a switch forwards based on IP addresses. Ordinary Layer 2 switching learns source MAC addresses and forwards by destination MAC within a VLAN.
  • Flushing neighbor caches as the first fix. That forces fresh resolution, but it does not repair a wrong VLAN, duplicate address, or broken peer.
  • Confusing VLAN tagging with routing. A trunk can carry multiple VLANs; a Layer 3 interface must still route between them.

Quick Recap Checklist

  • An Ethernet frame has local source and destination MAC addresses; its payload can contain an IP packet.
  • A switch learns source MAC-to-port mappings and forwards known destinations within a VLAN.
  • VLANs split Layer 2 broadcast domains; crossing between them requires Layer 3 routing.
  • IPv4 uses ARP; IPv6 uses Neighbor Discovery over ICMPv6.
  • Both resolve a next hop on the local link. A remote destination’s MAC is never carried across routers.
  • Use ip link, ip neigh, and tcpdump -e to inspect interface state, neighbor state, and actual frame headers.

Interview Questions

1. A host sends to an IP address outside its subnet. Which MAC address goes in the Ethernet frame?

The MAC address of the selected next-hop router on the local link. The IP packet still carries the remote destination IP. At each routed hop, the router removes the incoming Layer 2 header and creates another one for the next link.

2. How does a learning switch build its forwarding table?

It records the source MAC address of each received frame against its ingress port, usually in the frame's VLAN. It then forwards known unicast traffic to the learned port. Unknown unicast and broadcast traffic are flooded within the VLAN, subject to switch policy.

3. Why does ARP not resolve a remote internet host?

ARP requests are local-link broadcasts and routers do not forward them. The sender uses its routing table to choose a gateway, then resolves that gateway's MAC address. The remote host's MAC belongs to a different link and is not needed by the sender.

4. What replaces ARP in IPv6, and what should a capture show?

IPv6 uses Neighbor Discovery over ICMPv6. A capture commonly shows Neighbor Solicitation and Neighbor Advertisement messages, often using solicited-node multicast for resolution. ND also supports Duplicate Address Detection and router discovery, so checking only for a unicast reply can miss the relevant traffic.

5. What does an `INCOMPLETE` or `FAILED` neighbor entry suggest, and what would you check?

Expected answer points:

  • The host did not complete local next-hop address resolution.
  • Check whether the destination is on-link or routed, then verify the selected interface, VLAN path, and ARP or Neighbor Discovery traffic.
  • Do not treat the neighbor state alone as proof of a missing remote route; it points to a local-link resolution problem.
6. Why can an interface show `UP` while a host still cannot reach its gateway?

Expected answer points:

  • Link state shows carrier or administrative state, not that the host is in the intended Layer 2 domain.
  • A wrong access VLAN or a trunk that omits the VLAN can prevent gateway ARP or Neighbor Discovery from reaching the router.
  • Check host captures and switch port/VLAN configuration together.
7. How does Dynamic ARP Inspection reduce spoofing risk, and what can make it block valid traffic?

Expected answer points:

  • Where supported, it checks ARP sender IP/MAC claims against trusted bindings, commonly learned through DHCP snooping.
  • Static-address devices may not have those learned bindings and can be blocked unless their valid mappings are configured through an appropriate trusted mechanism.
  • Test the policy against the address-assignment model before enabling it broadly.
8. Why does carrying two VLANs on a trunk not let hosts in those VLANs communicate by itself?

Expected answer points:

  • VLANs are separate Layer 2 broadcast domains.
  • A trunk transports tagged frames for multiple VLANs but does not route between their IP subnets.
  • Communication across them needs a Layer 3 interface and appropriate routing and policy.

Further Reading

Conclusion

Ethernet delivers frames across a local Layer 2 domain, while switches learn MAC locations and keep forwarding decisions inside VLAN boundaries. ARP and IPv6 Neighbor Discovery resolve a local next hop; routers replace the Ethernet header at every hop. When connectivity fails, inspect the interface, route, neighbor entry, captured frames, and VLAN path as separate clues instead of expecting ARP to cross a router.

Category

Related Posts

IP Routing and NAT: How Packets Cross Networks

Learn how routers choose paths with routing tables, longest-prefix match, and gateways, then see how NAT and port translation change packets at network edges.

#computer-networks #ip-routing #nat

IPv4 and IPv6 Addressing: CIDR and Subnetting

Read IPv4 and IPv6 prefixes, calculate subnet membership, plan routes, and avoid CIDR overlap with practical examples in Python and production network design.

#networking #ipv4 #ipv6

TCP Congestion Control: Flow, Loss, and Fairness

Learn how TCP congestion control limits traffic, responds to ACKs and loss, and affects throughput, latency, and fairness, with Linux inspection commands.

#tcp #networking #congestion-control