?
Solved

Changing your IP address, and the effect it has on ARP caches

Posted on 2004-11-08
4
Medium Priority
?
1,763 Views
Last Modified: 2013-02-25
Say I'm ip address 192.168.1.15.    And I change my IP address to 192.168.1.20.
Will my router still have my MAC address MAPPED to 192.168.1.15 for a few minutes thereafter?

I've noticed that if I change my IP address, then view traffic with a sniffer. I can sometimes see my OLD IP address still doing ARP requests like a ghost (and no, no one was reassigned my old address). The problem fades away after a few minutes (hours?)

Would the "clear arp cache" command remedy this situation?

Thanks
0
Comment
Question by:dissolved
4 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 600 total points
ID: 12527331
Yes, the entry in the ARP cache is used until it ages out and then the new MAC address is mapped to the IP address when the router does an ARP broadcast.

Yes, if you use the "clear arp cache" command, it will remove all cached entries immediately and will rebuild the cache.  This will make the change immediate.
0
 
LVL 28

Assisted Solution

by:mikebernhardt
mikebernhardt earned 800 total points
ID: 12527684
You can have multiple IPs mapped to a single MAC address. You CANNOT have 1 IP mapped to multiple MAC addresses. You may be seeing arps for the old address because hosts cache DNS info. If hosta thinks that servera.domain.com is 192.168.1.15 and then you change it to 192.168.1.20, then hosta still thinks that servera is at 192.168.1.15 until it's rebooted or you flush the DNS cache on hosta.

The router can have mutliple IPs on a single MAC, no problem. It wouldn't arp for the old address unless someone was asking for it, such as hosta in the previous example. If you clear the arp cache, it will clear the router table. But hosta may still ask for it and the router will try again. You would see "Incomplete" in the arp table.
0
 
LVL 79

Assisted Solution

by:lrmoore
lrmoore earned 600 total points
ID: 12527855
Absolutely, you have an arp cache that will "hold on" to the old mapping for a period of time, as well as other systems around you will also have arp cache and dns cache and Netbios name caches.

See this Question, too, where we had the issue of changing out firewalls. New MAC address, same IP address, and the router cache had to be cleared:
http://www.experts-exchange.com/Security/Firewalls/Q_21197865.html

Default arp cache on a Cisco router is something like 4 hours..
0
 

Author Comment

by:dissolved
ID: 12529267
Thanks fellas
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question