Which of these is the iproute2 replacement for `arp -n`, showing the mapping of neighbouring IP addresses to their MAC addresses?

LPIC-1 Exam 102-500, objective 109. Networking fundamentals medium

Draft — not checked yet. This question was written from the published exam objectives and cites the clause it comes from, but nobody has yet read it against that clause and signed for it.

It is kept out of search results and out of mock exams until they have. Read the source below before you take the answer as settled.

The options

Correct ip neigh show

Correct. `ip neigh show` (also `ip n s`, or `ip neighbour show`) prints the kernel's neighbour table: the IPv4 ARP and IPv6 neighbour-discovery entries with their link-layer addresses and states such as REACHABLE or STALE.

Not correct ip link show

Wrong. `ip link show` lists the local interfaces and their own MAC addresses and flags, not the addresses of other hosts on the segment.

Not correct ip route get

Wrong. `ip route get DESTINATION` asks the kernel which route and source address it would use for one destination. It answers a routing question, not a link-layer one.

Not correct ip maddr show

Wrong. `ip maddr` lists multicast group memberships of the interfaces, which is a different table entirely.

Why

The neighbour table caches which MAC address answers for a given IP on the local link, learned via ARP for IPv4 and neighbour discovery for IPv6. Two hosts showing the same MAC for different addresses, or an entry stuck in FAILED, points at a duplicated address or an unreachable neighbour. Delete a stale entry with `ip neigh del ADDRESS dev IFACE`; the old net-tools equivalents are `arp -n` and `arp -d`.

Where this comes from

Cited
manual page ip-neighbour(8)

Practise this

Reading one question is not practice. The trainer will draw a set from objective 109 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500