Find the vendor name of a device by entering an OUI or a MAC address
How do I identify the MAC Address of a Docker container interface?
A Docker container interface can present an address in the range 02:42:00:00:00:00 to 02:42:ff:ff:ff:ff. Docker's address generator builds it from two fixed rules and the container's address: the first octet is 02, which makes the address unicast and locally administered, the second is 42, and the remaining four octets repeat the container's IPv4 address. An address in that range is therefore a strong indication that the interface belongs to a container rather than to a registered device.
A lookup of such an address returns no vendor, and that is expected rather than an error: the address was assigned by the container runtime, not by the IEEE Registration Authority, so no organization is registered for it.
Why the prefix starts with 02:42
- The first byte of any EUI-48 address carries two control bits. The least-significant bit must be 0 so the address is unicast, and the second-least-significant bit is set to 1 to mark the address as locally administered. 02 is the first octet with both bits set that way and nothing else.
- Because the address is locally administered, no IEEE registration applies to it, and the runtime is free to use the remaining bytes as long as it does not collide with another local address.
- 42 is Docker's own choice for the second octet, which also avoids the 02:00 space used by some other locally administered addresses.
What the rest of the address encodes
The last four octets repeat the container's IPv4 address in hexadecimal, so the address is not random: two containers with the known addresses 172.17.0.2 and 172.17.0.3 produce 02:42:AC:11:00:02 and 02:42:AC:11:00:03. When no address is available at generation time the generator fills those octets randomly instead, so the pattern does not hold for every interface.
Limits of this rule
- It describes the default bridge network. Other Docker network drivers, and addresses configured
explicitly with
--mac-address, can use different values. - The prefix is not reserved by any standard, and it is not unique to Docker: any tool is free to generate a locally administered address, and some do. Treat the range as a likely origin, not as proof.
- The implementation below is the one published for Docker v19.03. Later versions can change it, so check the generator in the version you run.
The generator published for Docker v19.03:
func genMAC(ip net.IP) net.HardwareAddr {
hw := make(net.HardwareAddr, 6)
// The first byte of the MAC address has to comply with these rules:
// 1. Unicast: Set the least-significant bit to 0.
// 2. Address is locally administered: Set the second-least-significant bit (U/L) to 1.
hw[0] = 0x02
// The first 24 bits of the MAC represent the Organizationally Unique Identifier (OUI).
// Since this address is locally administered, we can do whatever we want as long as
// it doesn't conflict with other addresses.
hw[1] = 0x42
// Fill the remaining 4 bytes based on the input
if ip == nil {
rand.Read(hw[2:])
} else {
copy(hw[2:], ip.To4())
}
return hw
}
Paste a container address into the MAC address lookup to confirm that no vendor is registered for it. Related guides: randomized and locally administered addresses and why devices randomize their address.
Related questions
Sources and review
Last reviewed: . Technical claims on this page follow the primary sources below; operating-system interfaces change between releases, so check them against your own device version.