Juniper · Junos OS

Junos LLDP, ARP and MAC Address Lookup Commands

Quick answer #

Use ARP on the endpoint's gateway to find its IPv4-to-MAC mapping, the correct switching table to find the learned interface, and LLDP to identify the next device. These three views describe different relationships; none alone is a complete inventory of the network.

Scope: Junos OS: LLDP and IPv4 ARP where supported; MAC examples are explicitly split between EX/QFX ELS switching and MX bridge domains. Non-ELS switches, SRX switching and EVPN mac-vrf designs require their own syntax validation.

Commands #

Shared discovery examples in operational mode:

Commands
Junos OS · Operational CLI

Read-only
show arp no-resolve
Read-only
show lldp neighbors
Read-only

Replace these example values: ge-0/0/1.

show lldp neighbors interface ge-0/0/1

EX/QFX with Enhanced Layer 2 Software (ELS):

Commands
Junos OS · Operational CLI

Read-only
show ethernet-switching table
Read-only

Replace these example values: ge-0/0/1.0.

show ethernet-switching table interface ge-0/0/1.0
Read-only

Replace these example values: USERS.

show ethernet-switching table vlan-name USERS

MX with bridge domains:

Commands
Junos OS · Operational CLI

Read-only
show bridge mac-table
Read-only

Replace these example values: xe-0/0/0.100.

show bridge mac-table interface xe-0/0/0.100
Read-only

Replace these example values: CUSTOMER-LAN.

show bridge mac-table bridge-domain CUSTOMER-LAN

Replace interface, VLAN and bridge-domain names. On an ELS switch, the VLAN selector is vlan-name; older non-ELS syntax differs. MX bridge-domain examples must not be pasted as EX switching commands.

Interpret the evidence #

ARP is a Layer 3 neighbor cache. A Layer 2-only access switch may have no ARP entry for the user, even while it switches their traffic correctly. Query the actual gateway in the correct routing context. For IPv6, use neighbor-discovery information rather than expecting an ARP entry.

A learned MAC identifies a direction within a VLAN or bridge domain. If that direction is an uplink, continue on the next switch. If it is an aggregate, inspect the aggregate and its peer rather than assuming one particular physical member is the endpoint connection.

LLDP advertises adjacent-device information where enabled. Read the remote port identifier and system name together. Missing LLDP does not prove that a cable is disconnected; endpoints and intermediate equipment may not advertise it.

Workflow #

Record the user's IP, expected VLAN and gateway. Obtain the MAC at the gateway, locate that MAC in the correct Layer 2 domain, then walk toward the access port using LLDP. At each hop, save the device, interface and VLAN so that the resulting path can be checked later.

If the entry is missing, first establish whether the endpoint has recently transmitted traffic. Avoid clearing all MAC or ARP entries just to stimulate learning; that changes the investigation and can affect unrelated users.

Pitfalls #

A remote EVPN-learned MAC points toward a remote forwarding path, not necessarily a locally attached host. An OUI lookup suggests an address registrant; it does not prove device model, ownership or identity. Hypervisors, phones with downstream PCs and small unmanaged switches can legitimately put multiple MAC addresses behind one port.

Continue with #

Junos Interface Errors and Optical Power Commands investigates the final port and Junos LACP Troubleshooting and AE Member Commands explains aggregate membership. The IPv4 Subnet Calculator helps check the endpoint and gateway addressing against the intended subnet. Reverse DNS / PTR Converter formats reverse lookup names; it does not identify switch ports or query a device's neighbor table.

Sources

Documentation reviewed: 8 October 2026