How Switching Works: MAC Tables, Frames and Broadcasts

CCNA 9 min readPublished 28 September 2026

Quick answer

Learn how Ethernet switches process frames, build MAC address tables and handle broadcasts. Includes Cisco IOS commands, a practical lab and troubleshooting steps.

Ethernet switching connects devices inside a local area network and forwards traffic using Layer 2 MAC addresses. Understanding frame forwarding, MAC address learning and broadcast domains is essential for configuring and troubleshooting switched networks.

This guide explains how switching works from the moment a frame enters a switch until it leaves the correct port. These concepts form an important part of the CCNA course and provide the foundation for VLANs, trunking, Spanning Tree Protocol and network security.

What Does an Ethernet Switch Do?

An Ethernet switch receives frames, examines their source and destination MAC addresses, and decides where to forward them. It learns which devices are connected to which ports by recording source MAC addresses in its MAC address table.

A switch mainly performs three Layer 2 functions:

  1. Learning: Records source MAC addresses and incoming ports.
  2. Forwarding or filtering: Sends a frame through the required port or keeps it on the local segment.
  3. Flooding: Copies broadcasts and unknown unicast frames to other eligible ports in the same VLAN.

Consider this physical topology:

PC-A -------- Fa0/1
                  \
                   SW1 -------- Fa0/24 -------- Router
                  /
PC-B -------- Fa0/2

Server ------- Fa0/3

If PC-A sends a frame to PC-B, SW1 uses its MAC address table to determine whether PC-B is reachable through Fa0/2. It does not need to send the frame to the router because both devices are in the same Layer 2 network.

Switches, hubs and routers

DeviceMain forwarding informationTraffic handlingBroadcast boundary
HubNoneRepeats bits through all other portsNo
Layer 2 switchMAC address tableForwards Ethernet framesNo, unless VLANs separate ports
RouterIP routing tableForwards packets between networksYes

Each switch port creates a separate collision domain. However, all ports in the same VLAN remain part of one broadcast domain.

What Is Inside an Ethernet Frame?

An Ethernet frame is the Layer 2 unit that carries data across a switched LAN. It contains destination and source MAC addresses, a type or length field, the payload and a Frame Check Sequence used for error detection.

A standard untagged Ethernet II frame can be visualised as follows:

| Destination MAC | Source MAC | EtherType | Data and Padding | FCS |
|     6 bytes     |   6 bytes  |  2 bytes  |  46-1500 bytes   | 4 B |

The fields have these purposes:

FieldPurpose
Destination MACIdentifies the intended Layer 2 receiver
Source MACIdentifies the interface that transmitted the frame
EtherTypeIdentifies the upper-layer protocol, such as IPv4 or ARP
DataCarries the Layer 3 packet or other payload
PaddingBrings a short payload up to the minimum frame size
FCSAllows the receiver to detect transmission errors

The minimum Ethernet frame size from the destination MAC address through the FCS is 64 bytes. The usual maximum for an untagged frame is 1518 bytes, excluding the preamble and Start Frame Delimiter.

MAC addresses are 48 bits long and are commonly written as six hexadecimal pairs, for example:

00:1A:2B:3C:4D:5E

A unicast frame is addressed to one interface. A broadcast frame uses FF:FF:FF:FF:FF:FF, while multicast addresses identify a selected group of receivers.

How Does a Switch Build Its MAC Address Table?

A switch learns a MAC address from the source address of an incoming frame, not from its destination address. It associates that source MAC address with the receiving port and the frame's VLAN.

Suppose SW1 initially has an empty MAC address table:

PC-A: 00AA.AAAA.AAAA -- Fa0/1
PC-B: 00BB.BBBB.BBBB -- Fa0/2

When PC-A transmits a frame into Fa0/1, the switch performs this learning action:

Source MAC 00AA.AAAA.AAAA arrived on Fa0/1
Add: VLAN 1, MAC 00AA.AAAA.AAAA, Port Fa0/1

The resulting table contains:

VLAN    MAC Address       Type       Port
----    -----------       --------   -----
1       00aa.aaaa.aaaa    DYNAMIC    Fa0/1

If PC-B replies, the switch learns 00bb.bbbb.bbbb through Fa0/2. The switch can then forward later unicast traffic directly between Fa0/1 and Fa0/2.

MAC table entries are scoped by VLAN. The same table therefore stores the VLAN, MAC address, entry type and outgoing interface rather than only the MAC address.

Dynamic entries expire after an ageing period when the switch stops receiving frames from that source. Many Cisco switches use a default around 300 seconds, but the value can vary by platform and configuration, so it should be verified rather than assumed.

How Does a Switch Forward a Frame?

After learning the source address, a switch looks up the destination MAC address in its table. It then forwards, filters or floods the frame according to the lookup result.

There are four common outcomes.

1. Known unicast forwarding

If the destination MAC exists on another active port in the same VLAN, the switch forwards the frame only through that port.

Frame enters Fa0/1
Source:      00AA.AAAA.AAAA
Destination: 00BB.BBBB.BBBB
Table says:  00BB.BBBB.BBBB is on Fa0/2
Result:      Forward through Fa0/2 only

This selective forwarding is a major difference between a switch and a hub.

2. Same-port filtering

If the destination MAC is learned on the same port where the frame arrived, the switch does not forward the frame through another port. This situation can occur when multiple devices are behind another switch or shared segment connected to that interface.

3. Unknown unicast flooding

If the destination is not in the MAC address table, the switch floods the frame through all other forwarding ports in the same VLAN. It does not send the frame back through the incoming port.

Flooding gives the unknown destination an opportunity to receive and answer. When the destination replies, the switch learns its source MAC address, allowing later traffic to be forwarded as known unicast.

4. Broadcast flooding

A frame addressed to FFFF.FFFF.FFFF is copied to all other forwarding ports in the same VLAN. Common examples include ARP requests and some DHCP messages.

A switch does not normally forward a Layer 2 broadcast into another VLAN. A router or Layer 3 switch is required for communication between different IP subnets and VLANs.

What Is a Broadcast Domain?

A broadcast domain is the group of interfaces that can receive a Layer 2 broadcast sent by one member. By default, all active ports in the same VLAN belong to the same broadcast domain.

Imagine one switch with four ports assigned to VLAN 10:

                VLAN 10 broadcast domain

PC-A -- Fa0/1 ----[ SW1 ]---- Fa0/2 -- PC-B
                    |  |
                  Fa0/3 Fa0/4
                    |    |
                 Server Printer

If PC-A sends an ARP request with the destination FFFF.FFFF.FFFF, SW1 forwards it through Fa0/2, Fa0/3 and Fa0/4. It does not return the frame through Fa0/1.

If Fa0/4 is moved to VLAN 20, the printer no longer receives VLAN 10 broadcasts. VLAN 10 and VLAN 20 are separate broadcast domains even when their access ports are on the same physical switch.

Network designNumber of broadcast domains
One switch with all ports in one VLAN1
Two connected switches carrying one VLAN1
One switch using VLAN 10 and VLAN 202
Two LANs separated by a router2

Broadcast domains should not be confused with collision domains. Each full-duplex switch port is an individual collision domain, while a VLAN can include many switch ports and still form one broadcast domain.

How Do ARP and Switching Work Together?

ARP maps an IPv4 address to a MAC address on the local network, while the switch maps that MAC address to a physical port. ARP tables are maintained by end devices, whereas MAC address tables are maintained by switches.

Assume PC-A wants to ping PC-B but knows only PC-B's IPv4 address:

  1. PC-A checks whether PC-B is local using its IP address and subnet mask.
  2. PC-A checks its ARP cache for PC-B's MAC address.
  3. If no entry exists, PC-A sends a broadcast ARP request.
  4. The switch learns PC-A's source MAC and floods the request within the VLAN.
  5. PC-B sends a unicast ARP reply containing its MAC address.
  6. The switch learns PC-B's source MAC from the reply.
  7. PC-A can now place ICMP packets inside unicast Ethernet frames addressed to PC-B.

This is why the first ping may take slightly longer than later pings: ARP resolution and MAC learning may need to occur first.

Practical Cisco Lab: Observe MAC Address Learning

This lab demonstrates how a Cisco switch learns and uses MAC addresses. Connect two PCs to a switch, place both ports in VLAN 10 and assign the PCs addresses in the same subnet.

PC-A: 192.168.10.10/24, connected to Fa0/1
PC-B: 192.168.10.20/24, connected to Fa0/2

Configure the access ports:

Switch> enable
Switch# configure terminal
Switch(config)# vlan 10
Switch(config-vlan)# name USERS
Switch(config-vlan)# exit
Switch(config)# interface range fastEthernet 0/1 - 2
Switch(config-if-range)# switchport mode access
Switch(config-if-range)# switchport access vlan 10
Switch(config-if-range)# no shutdown
Switch(config-if-range)# end

Check the table before generating traffic:

Switch# show mac address-table dynamic vlan 10
          Mac Address Table
-------------------------------------------
Vlan    Mac Address       Type        Ports
----    -----------       --------    -----

An empty result does not necessarily indicate a fault. The switch learns a device only after receiving a frame from it.

From PC-A, ping PC-B:

C:\> ping 192.168.10.20

Reply from 192.168.10.20: bytes=32 time<1ms TTL=128
Reply from 192.168.10.20: bytes=32 time<1ms TTL=128

Check the table again:

Switch# show mac address-table dynamic vlan 10
          Mac Address Table
-------------------------------------------
Vlan    Mac Address       Type        Ports
----    -----------       --------    -----
  10    00aa.aaaa.aaaa    DYNAMIC     Fa0/1
  10    00bb.bbbb.bbbb    DYNAMIC     Fa0/2

The output shows that the switch learned PC-A through Fa0/1 and PC-B through Fa0/2. DYNAMIC means the entries were learned from received traffic rather than manually configured.

To remove all dynamic entries during a controlled lab, use:

Switch# clear mac address-table dynamic

Clearing the table temporarily causes unknown unicast flooding until the switch relearns the active source addresses. Use this command carefully on a production network.

How Do You Troubleshoot a Switching Problem?

Start at the physical layer, verify the VLAN and port state, inspect MAC learning, and then test ARP and IP connectivity. Avoid changing configurations until the failing layer has been identified.

Step 1: Check port status

Switch# show interfaces status

Confirm that the expected interfaces show connected and are assigned to the correct VLAN. A port displaying notconnect, disabled or err-disabled requires further investigation.

Step 2: Verify the interface configuration

Switch# show running-config interface fastEthernet 0/1
Switch# show interfaces fastEthernet 0/1 switchport

Check access mode, access VLAN and administrative status. Two hosts in different VLANs cannot communicate directly at Layer 2.

Step 3: Confirm MAC address learning

Switch# show mac address-table interface fastEthernet 0/1

If no MAC address appears after the device sends traffic, check the cable, network adapter, interface counters, port security and VLAN assignment. If the same MAC repeatedly moves between ports, investigate a cabling loop, duplicate Layer 2 path or unstable downstream connection.

Step 4: Check errors and dropped frames

Switch# show interfaces fastEthernet 0/1
Switch# show interfaces counters errors

Look for CRC errors, input errors, late collisions or excessive drops. CRC errors commonly point to cabling, connector or physical-interface problems, though the complete interface context should be reviewed.

Step 5: Check ARP on the endpoint

On Windows:

C:\> arp -a

On Linux:

ip neighbour show

An incomplete neighbour entry means ARP resolution did not finish. Check whether both hosts use the correct subnet mask and belong to the same VLAN.

Step 6: Consider Spanning Tree state

A physically connected switch port may not forward frames if Spanning Tree has placed it in a blocking or discarding role. Use show spanning-tree vlan 10 and review the port role and state; for a deeper explanation, see Spanning Tree Protocol, root bridges and port states.

For a broader diagnostic workflow covering multiple OSI layers, follow this layer-by-layer network troubleshooting method.

Common Switching Mistakes

Several basic errors can produce similar symptoms:

  • Assuming a switch learns from the destination MAC instead of the source MAC.
  • Treating the switch MAC table and a host's ARP table as the same thing.
  • Expecting devices in separate VLANs to communicate without Layer 3 routing.
  • Assuming an empty MAC table proves that a port is faulty before generating traffic.
  • Forgetting that unknown unicasts and broadcasts are flooded only within the relevant VLAN.
  • Clearing the MAC table in production without considering the temporary increase in flooding.
  • Ignoring an STP-blocked link because its physical status is still up.

Summary

Ethernet switches learn source MAC addresses, associate them with ports and VLANs, and examine destination MAC addresses to make forwarding decisions. Known unicasts are forwarded selectively, while unknown unicasts and broadcasts are flooded through eligible ports in the same VLAN.

A MAC address table explains where Layer 2 devices have been observed, while an ARP table maps local IPv4 addresses to MAC addresses. VLANs divide broadcast domains, routers connect IP networks, and Spanning Tree prevents Layer 2 loops from creating repeated frames.

Reviewed by Network Rhinos networking trainers.

To practise switching, VLANs, routing and Cisco IOS troubleshooting in guided labs, review the CCNA course and request current batch details.

Frequently asked questions

How does a switch learn MAC addresses?

A switch reads the source MAC address of each incoming Ethernet frame. It records that address together with the receiving port and VLAN in its MAC address table.

What happens when a switch does not know the destination MAC address?

The switch treats the frame as an unknown unicast and floods it through all other forwarding ports in the same VLAN. When the destination replies, the switch learns its MAC address from the reply's source field.

What is the difference between a MAC table and an ARP table?

A switch's MAC table maps MAC addresses to switch ports and VLANs. An endpoint or router's ARP table maps local IPv4 addresses to MAC addresses.

Does a switch break up broadcast domains?

A basic Layer 2 switch does not separate broadcasts when all ports are in one VLAN. Each VLAN creates a separate broadcast domain, and Layer 3 routing is required to communicate between those domains.

Why is a device missing from the switch MAC address table?

The switch may not have received a frame from the device recently, or the dynamic entry may have aged out. Also check the cable, port status, VLAN assignment, port security and network adapter.

Does a switch forward a broadcast back through the incoming port?

No. A switch floods a broadcast through other eligible forwarding ports in the same VLAN, but it does not send the frame back through the port on which it arrived.

Related articles

Train with Network Rhinos

Hands-on CCNA, CCNP, AWS, Azure, DevOps and cybersecurity training in Chennai & Bangalore, with placement support. Talk to our team or attend a free demo class.