RFC 826: ARP: Mapping IPv4 addresses to Ethernet
Summary
RFC 826 introduces ARP so that hosts can find the matching Ethernet address for an IPv4 address. Automatic neighbour discovery makes operations easier and at the same time creates a local trust gap. Many layer 2 attacks exploit the lack of cryptographic binding.
Ideas
- ARP requests are broadcast in the local segment.
- Replies temporarily link protocol and hardware addresses.
- Caches avoid a request before every packet.
Remarks
- RFC 826 has the status “Internet Standard”; current errata and successor documents should also be checked.
Recommendations
- Limit broadcast domains and monitor unusual ARP changes.
- Use protections such as Dynamic ARP Inspection where the risk justifies it.
References
Read the RFC at the RFC Editor
Links to the original source and the Web Archive open in a new tab.