Solved

Mac-Adddress to IP address Arp???

Posted on 2004-08-09
12
3,458 Views
Last Modified: 2010-05-18
Does any one know of a way to find the IP address of a computer when all I have is the Mac-Address.

I thought there was an inverse arp command but I cant seem to get that working

thanks
0
Comment
Question by:kdog3445
  • 5
  • 3
  • 2
  • +2
12 Comments
 
LVL 43

Expert Comment

by:JFrederick29
Comment Utility
No, there isn't unfortunately, not one I could find anyway.

Do you have a router where you can view the ARP cache?  If you can, you should see the MAC address in the routers ARP cache along with the corresponding IP address, as long as the PC is on the network.
0
 
LVL 27

Expert Comment

by:pseudocyber
Comment Utility
kdog3445 - what kind of network do you have?  Managed or not?  Pro gear or Small Office/Home Office (SOHO) gear?  Switched or hub?

If you're in a hub environment, you could do a sniff for a while of your network and then look for that MAC and look at the associated IP.

Ideally, you would view the ARP table in the default gateway router for the segment.
0
 
LVL 20

Expert Comment

by:DVation191
Comment Utility
Well, I know what you are talking about is RARP ( Reverse Address Resolution Protocol ), but unless you have access to the router (enterprise-grade), looking at the tables won't be possible. Maybe another expert can shine some more light on the situation
0
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
Is this system on your own local LAN? If not-- fuggedaboutit.
If it is on your own local LAN, in the same subnet, try a broadcast ping:
ping 192.168.1.255

All live hosts should respond, then use "arp -a" from Command line:
C:\WINDOWS>ping 192.168.12.255

Pinging 192.168.12.255 with 32 bytes of data:

Reply from 192.168.12.253: bytes=32 time<1ms TTL=255
Reply from 192.168.12.132: bytes=32 time<1ms TTL=64
Reply from 192.168.12.132: bytes=32 time<1ms TTL=64
Reply from 192.168.12.132: bytes=32 time<1ms TTL=64

Ping statistics for 192.168.122.255:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms

C:\WINDOWS>arp -a

Interface: 192.168.122.150 --- 0x2
  Internet Address      Physical Address      Type
  192.168.122.132       00-0c-41-d6-1e-5b     dynamic
  192.168.122.149       00-07-95-24-74-4f     dynamic
  192.168.122.157       00-0c-41-a9-3d-51     dynamic

C:\WINDOWS>

If it's not in the same subnet, but still on the local LAN, then you might have to resort to using a sniffer like Ethereal:
http://www.ethereal.com



0
 
LVL 43

Expert Comment

by:JFrederick29
Comment Utility
Excellent lrmoore!

I bow to you...
0
 

Author Comment

by:kdog3445
Comment Utility
It is a LAN and I do have acess to the Router. What is the command to view the Arp table?

I do sh Mac-address and it list all connected MAC's but does not list IP address. What command am I missing?

Thanks
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 27

Expert Comment

by:pseudocyber
Comment Utility
What kind of router?

You want to look at the ARP table, not the MAC forwarding table (assuming this is a layer 3 switch).

It's probably something along the lines of "show ip arp"  or "show arp"
0
 
LVL 27

Accepted Solution

by:
pseudocyber earned 125 total points
Comment Utility
On a Cisco layer 3 box ...

rtr#show ip arp ?
  GE-WAN               GigabitEthernetWAN IEEE 802.3z
  GigabitEthernet      GigabitEthernet IEEE 802.3z
  H.H.H                48-bit hardware address of ARP entry
  Hostname or A.B.C.D  IP address or hostname of ARP entry
  Null                 Null interface
  Vlan                 Catalyst Vlans
  summary              IP ARP table summary
  |                    Output modifiers
  <cr>
0
 

Author Comment

by:kdog3445
Comment Utility
It is a cisco and I am doing
rtr#show ip arp ?
  GE-WAN               GigabitEthernetWAN IEEE 802.3z
  GigabitEthernet      GigabitEthernet IEEE 802.3z
  H.H.H                48-bit hardware address of ARP entry
  Hostname or A.B.C.D  IP address or hostname of ARP entry
  Null                 Null interface
  Vlan                 Catalyst Vlans
  summary              IP ARP table summary
  |                    Output modifiers
  <cr>

I put in the Mac address after sh IP arp

but nothing gets displayed
0
 
LVL 27

Expert Comment

by:pseudocyber
Comment Utility
What do you get if you do a show ip arp?

The machine has to be on segments connected to the router.  It could also be the machine is off and has aged out of the arp table.
0
 

Author Comment

by:kdog3445
Comment Utility
Ahhhhh Haaaaaa

User Error

I was running all this from a switch and not the core router

so from the switch I run
sh mac-address int fast 5/3   and get the MAC

Then from the router I run

sh ip arp 00-00-00-00-00-00
that get me the IP

SWEET -- thanks all
0
 
LVL 27

Expert Comment

by:pseudocyber
Comment Utility
You're welcome! :)
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Cisco iWAN 8 45
WiFi Blackspot within home network 7 36
Extending  a subnet 9 34
Resource cost of NAT vs routing 3 13
There have been a lot of times when we have seen the need to enter a large number of DNS entries in a forward lookup zone. The standard procedure would be to launch the DNS Manager console, create the Zone and start adding new hosts using the New…
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now