What it is¶
arptables filters ARP requests and replies, which iptables cannot see because ARP is not IP. It is used to stop ARP spoofing on a segment or, in load-balancer setups such as IPVS Direct Routing, to stop real servers from answering ARP for the shared virtual IP (see the IPVS guide). Chains are INPUT, OUTPUT, and FORWARD.
In nftables, the equivalent is the arp family. arptables on modern systems is a shim over it.
Examples¶
sudo arptables -L
# Ignore ARP requests for the VIP (real server in a Direct Routing pool)
sudo arptables -A INPUT -d 192.0.2.100 -j DROP
sudo arptables -A OUTPUT -s 192.0.2.100 -j mangle --mangle-ip-s 192.168.1.11
# Accept ARP only from the gateway's MAC
sudo arptables -A INPUT --source-mac 52:54:00:aa:bb:cc -j ACCEPT
sudo arptables -P INPUT DROP
Equivalent nftables sketch:
table arp filter {
chain input {
type filter hook input priority 0; policy accept;
arp daddr ip 192.0.2.100 drop
}
}
For most real servers the sysctl approach (arp_ignore=1, arp_announce=2) is simpler than arptables; the IPVS guide covers it.