The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

arp delete

Prev Next

This command removes a single MAC or IP address association from the ARP table. It is used in conjunction with Trellix IPS ARP spoofing detection feature. This command might also be used in situations where a machine on the network is replaced with new hardware.

Syntax:

arp delete <IP address>

Parameter

Description

IP address

This is a 32-bit IP address number indicated by four numbers separated by periods (X.X.X.X), where X indicates a number between 0-255.

Example:

The following example shows that the IP address 209.165.202.255 is removed from the ARP table.

arp delete 209.165.202.255

Applicable to:

NS-series and Virtual IPS Sensors. For Virtual Security System instances, this command is available in debug mode.