RadiusNest › Guides

MikroTik ARP reply-only: stop users from setting their own IP address

Last updated: 11 October 2026

On a network that gives addresses by DHCP, a user can still type an address by hand, take someone else's address, or escape a queue that is tied to a lease. With ARP reply-only, the router talks only to devices that got their address from its own DHCP server or that you listed yourself.

Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.

How it works

Before two devices on a LAN can talk, one asks "who has this IP address?" (ARP) and learns the other's MAC address. Normally the router learns every device that speaks. With arp=reply-only it stops learning and uses only the ARP list: entries the DHCP server added for its leases, and entries you added by hand. A device with a self-made address gets no answer from the router, so it has no internet.

1. Let the DHCP server fill the ARP list

/ip dhcp-server print
/ip dhcp-server set [find name=dhcp1] add-arp=yes

Use the name of your DHCP server. From now on, every lease it hands out also creates an ARP entry, and the entry goes away when the lease ends.

2. Wait until current devices have entries

/ip arp print

Entries made by the DHCP server carry the H (DHCP) flag. Devices that already had a lease get their entry when they renew. Wait for at least half the lease time, or until the count of DHCP entries matches the count of bound leases (/ip dhcp-server lease print count-only where status=bound).

3. Add devices with fixed addresses

Printers, cameras, access points and anything you set by hand do not use DHCP. Give each a static ARP entry, or better, a static DHCP lease:

/ip arp add address=192.168.88.20 mac-address=AA:BB:CC:DD:EE:20 interface=bridge comment="printer"

4. Switch the LAN to reply-only

/interface bridge set bridge arp=reply-only

Set it on the interface where the DHCP server runs: usually the bridge, or a VLAN interface. Turn on Safe Mode first; if the computer you are using has a hand-typed address and no ARP entry, you lose the connection (Winbox by MAC address still works).

Check

  • On a test phone, set a fixed address by hand: it should get no internet.
  • Switch the phone back to DHCP: it should work at once.

Hotspot and PPPoE

  • PPPoE: customers get their address inside the PPPoE session, so this is not needed there.
  • Hotspot: leave ARP enabled on the hotspot interface. The hotspot has its own handling of devices with hand-typed addresses, and users must log in before they get anywhere.

Undo

/interface bridge set bridge arp=enabled

Combine it with a limit per user and blocked devices stay blocked: see block a device by MAC address.

Questions and answers

What does ARP reply-only do on MikroTik?

The router stops learning devices by itself and only talks to devices in its ARP list: DHCP leases (with add-arp=yes) and entries you added.

Will reply-only lock me out of my MikroTik?

It can, if your computer has a hand-typed address with no ARP entry. Use Safe Mode, and Winbox by MAC address still works on the LAN.

Do I need ARP reply-only with PPPoE?

No. PPPoE customers receive their address inside the session and cannot choose their own.

Related guides

Start the free trial See pricing