Difficulty: Intermediate
What is ARP and how does it work? What happens when the destination is on a different network? What is ARP spoofing?
You have an IP address for the machine you want to talk to, but Ethernet frames need a MAC address. ARP, Address Resolution Protocol, is the glue between those two worlds on a local network. It is often described as the phone book lookup of the LAN: I know the name, I need the number.
Here is the flow. Host A (192.168.1.10) wants to send to host B (192.168.1.20) on the same subnet. A first checks its ARP cache, a small table of IP to MAC mappings. On a miss, A broadcasts an ARP request frame with destination MAC ff:ff:ff:ff:ff:ff saying who has 192.168.1.20, tell 192.168.1.10. Every device on the LAN receives it, but only B recognises its own IP and replies with a unicast ARP reply containing its MAC. A stores the mapping in its cache, usually for a few minutes, then sends the actual data frame. Note that B also learns A's MAC from the request, so the reverse lookup is free.
What if B is on a different subnet? A compares B's IP with its own subnet mask, sees B is remote, and decides to send the packet to its default gateway. So A ARPs for the gateway's MAC (say 192.168.1.1) and sends a frame with the destination MAC of the router but the destination IP of B. The router then does its own ARP on the next network. This is the exact reason MAC addresses change per hop while IPs do not.
ARP sits between layers 2 and 3, and it is not routed: ARP requests never cross a router. In IPv6 the same job is done by Neighbor Discovery using ICMPv6 and multicast instead of broadcast.
Now for the security twist. ARP has no authentication. Any host can send an unsolicited reply, called a gratuitous ARP, and other hosts will happily update their caches. In ARP spoofing or ARP poisoning, an attacker tells the victim that the gateway's IP is at the attacker's MAC, and tells the gateway that the victim's IP is at the attacker's MAC. Now all traffic flows through the attacker, a classic man-in-the-middle. Defences include Dynamic ARP Inspection on managed switches (which validates ARP packets against the DHCP snooping table), static ARP entries for critical hosts, port security, and using encryption such as HTTPS and SSH so that intercepted traffic is useless.
Gratuitous ARP also has legitimate uses: a host announces its own IP to update caches after a failover, for example when a virtual IP moves to a standby server in a high-availability pair, and to detect duplicate IP addresses. Related is Proxy ARP, where a router answers ARP requests on behalf of hosts in another network. Also RARP, the reverse, is obsolete and was replaced by BOOTP and DHCP.
$ arp -a
? (192.168.1.1) at 3c:22:fb:9a:12:7e [ether] on eth0
? (192.168.1.20) at a4:5e:60:c1:09:d2 [ether] on eth0
$ sudo tcpdump -n -i eth0 arp
ARP, Request who-has 192.168.1.20 tell 192.168.1.10, length 28
ARP, Reply 192.168.1.20 is-at a4:5e:60:c1:09:d2, length 28
The request is broadcast; the reply is unicast back to the asker.
ARP, ARP Cache, Broadcast, ARP Spoofing, Default Gateway