Ethernet switching connects devices inside a local area network and forwards traffic using Layer 2 MAC addresses. Understanding frame forwarding, MAC address learning and broadcast domains is essential for configuring and troubleshooting switched networks.
This guide explains how switching works from the moment a frame enters a switch until it leaves the correct port. These concepts form an important part of the CCNA course and provide the foundation for VLANs, trunking, Spanning Tree Protocol and network security.
What Does an Ethernet Switch Do?
An Ethernet switch receives frames, examines their source and destination MAC addresses, and decides where to forward them. It learns which devices are connected to which ports by recording source MAC addresses in its MAC address table.
A switch mainly performs three Layer 2 functions:
- Learning: Records source MAC addresses and incoming ports.
- Forwarding or filtering: Sends a frame through the required port or keeps it on the local segment.
- Flooding: Copies broadcasts and unknown unicast frames to other eligible ports in the same VLAN.
Consider this physical topology:
PC-A -------- Fa0/1
\
SW1 -------- Fa0/24 -------- Router
/
PC-B -------- Fa0/2
Server ------- Fa0/3If PC-A sends a frame to PC-B, SW1 uses its MAC address table to determine whether PC-B is reachable through Fa0/2. It does not need to send the frame to the router because both devices are in the same Layer 2 network.
Switches, hubs and routers
| Device | Main forwarding information | Traffic handling | Broadcast boundary |
|---|---|---|---|
| Hub | None | Repeats bits through all other ports | No |
| Layer 2 switch | MAC address table | Forwards Ethernet frames | No, unless VLANs separate ports |
| Router | IP routing table | Forwards packets between networks | Yes |
Each switch port creates a separate collision domain. However, all ports in the same VLAN remain part of one broadcast domain.
What Is Inside an Ethernet Frame?
An Ethernet frame is the Layer 2 unit that carries data across a switched LAN. It contains destination and source MAC addresses, a type or length field, the payload and a Frame Check Sequence used for error detection.
A standard untagged Ethernet II frame can be visualised as follows:
| Destination MAC | Source MAC | EtherType | Data and Padding | FCS |
| 6 bytes | 6 bytes | 2 bytes | 46-1500 bytes | 4 B |The fields have these purposes:
| Field | Purpose |
|---|---|
| Destination MAC | Identifies the intended Layer 2 receiver |
| Source MAC | Identifies the interface that transmitted the frame |
| EtherType | Identifies the upper-layer protocol, such as IPv4 or ARP |
| Data | Carries the Layer 3 packet or other payload |
| Padding | Brings a short payload up to the minimum frame size |
| FCS | Allows the receiver to detect transmission errors |
The minimum Ethernet frame size from the destination MAC address through the FCS is 64 bytes. The usual maximum for an untagged frame is 1518 bytes, excluding the preamble and Start Frame Delimiter.
MAC addresses are 48 bits long and are commonly written as six hexadecimal pairs, for example:
00:1A:2B:3C:4D:5EA unicast frame is addressed to one interface. A broadcast frame uses FF:FF:FF:FF:FF:FF, while multicast addresses identify a selected group of receivers.
How Does a Switch Build Its MAC Address Table?
A switch learns a MAC address from the source address of an incoming frame, not from its destination address. It associates that source MAC address with the receiving port and the frame's VLAN.
Suppose SW1 initially has an empty MAC address table:
PC-A: 00AA.AAAA.AAAA -- Fa0/1
PC-B: 00BB.BBBB.BBBB -- Fa0/2When PC-A transmits a frame into Fa0/1, the switch performs this learning action:
Source MAC 00AA.AAAA.AAAA arrived on Fa0/1
Add: VLAN 1, MAC 00AA.AAAA.AAAA, Port Fa0/1The resulting table contains:
VLAN MAC Address Type Port
---- ----------- -------- -----
1 00aa.aaaa.aaaa DYNAMIC Fa0/1If PC-B replies, the switch learns 00bb.bbbb.bbbb through Fa0/2. The switch can then forward later unicast traffic directly between Fa0/1 and Fa0/2.
MAC table entries are scoped by VLAN. The same table therefore stores the VLAN, MAC address, entry type and outgoing interface rather than only the MAC address.
Dynamic entries expire after an ageing period when the switch stops receiving frames from that source. Many Cisco switches use a default around 300 seconds, but the value can vary by platform and configuration, so it should be verified rather than assumed.
How Does a Switch Forward a Frame?
After learning the source address, a switch looks up the destination MAC address in its table. It then forwards, filters or floods the frame according to the lookup result.
There are four common outcomes.
1. Known unicast forwarding
If the destination MAC exists on another active port in the same VLAN, the switch forwards the frame only through that port.
Frame enters Fa0/1
Source: 00AA.AAAA.AAAA
Destination: 00BB.BBBB.BBBB
Table says: 00BB.BBBB.BBBB is on Fa0/2
Result: Forward through Fa0/2 onlyThis selective forwarding is a major difference between a switch and a hub.
2. Same-port filtering
If the destination MAC is learned on the same port where the frame arrived, the switch does not forward the frame through another port. This situation can occur when multiple devices are behind another switch or shared segment connected to that interface.
3. Unknown unicast flooding
If the destination is not in the MAC address table, the switch floods the frame through all other forwarding ports in the same VLAN. It does not send the frame back through the incoming port.
Flooding gives the unknown destination an opportunity to receive and answer. When the destination replies, the switch learns its source MAC address, allowing later traffic to be forwarded as known unicast.
4. Broadcast flooding
A frame addressed to FFFF.FFFF.FFFF is copied to all other forwarding ports in the same VLAN. Common examples include ARP requests and some DHCP messages.
A switch does not normally forward a Layer 2 broadcast into another VLAN. A router or Layer 3 switch is required for communication between different IP subnets and VLANs.
What Is a Broadcast Domain?
A broadcast domain is the group of interfaces that can receive a Layer 2 broadcast sent by one member. By default, all active ports in the same VLAN belong to the same broadcast domain.
Imagine one switch with four ports assigned to VLAN 10:
VLAN 10 broadcast domain
PC-A -- Fa0/1 ----[ SW1 ]---- Fa0/2 -- PC-B
| |
Fa0/3 Fa0/4
| |
Server PrinterIf PC-A sends an ARP request with the destination FFFF.FFFF.FFFF, SW1 forwards it through Fa0/2, Fa0/3 and Fa0/4. It does not return the frame through Fa0/1.
If Fa0/4 is moved to VLAN 20, the printer no longer receives VLAN 10 broadcasts. VLAN 10 and VLAN 20 are separate broadcast domains even when their access ports are on the same physical switch.
| Network design | Number of broadcast domains |
|---|---|
| One switch with all ports in one VLAN | 1 |
| Two connected switches carrying one VLAN | 1 |
| One switch using VLAN 10 and VLAN 20 | 2 |
| Two LANs separated by a router | 2 |
Broadcast domains should not be confused with collision domains. Each full-duplex switch port is an individual collision domain, while a VLAN can include many switch ports and still form one broadcast domain.
How Do ARP and Switching Work Together?
ARP maps an IPv4 address to a MAC address on the local network, while the switch maps that MAC address to a physical port. ARP tables are maintained by end devices, whereas MAC address tables are maintained by switches.
Assume PC-A wants to ping PC-B but knows only PC-B's IPv4 address:
- PC-A checks whether PC-B is local using its IP address and subnet mask.
- PC-A checks its ARP cache for PC-B's MAC address.
- If no entry exists, PC-A sends a broadcast ARP request.
- The switch learns PC-A's source MAC and floods the request within the VLAN.
- PC-B sends a unicast ARP reply containing its MAC address.
- The switch learns PC-B's source MAC from the reply.
- PC-A can now place ICMP packets inside unicast Ethernet frames addressed to PC-B.
This is why the first ping may take slightly longer than later pings: ARP resolution and MAC learning may need to occur first.
Practical Cisco Lab: Observe MAC Address Learning
This lab demonstrates how a Cisco switch learns and uses MAC addresses. Connect two PCs to a switch, place both ports in VLAN 10 and assign the PCs addresses in the same subnet.
PC-A: 192.168.10.10/24, connected to Fa0/1
PC-B: 192.168.10.20/24, connected to Fa0/2Configure the access ports:
Switch> enable
Switch# configure terminal
Switch(config)# vlan 10
Switch(config-vlan)# name USERS
Switch(config-vlan)# exit
Switch(config)# interface range fastEthernet 0/1 - 2
Switch(config-if-range)# switchport mode access
Switch(config-if-range)# switchport access vlan 10
Switch(config-if-range)# no shutdown
Switch(config-if-range)# endCheck the table before generating traffic:
Switch# show mac address-table dynamic vlan 10
Mac Address Table
-------------------------------------------
Vlan Mac Address Type Ports
---- ----------- -------- -----An empty result does not necessarily indicate a fault. The switch learns a device only after receiving a frame from it.
From PC-A, ping PC-B:
C:\> ping 192.168.10.20
Reply from 192.168.10.20: bytes=32 time<1ms TTL=128
Reply from 192.168.10.20: bytes=32 time<1ms TTL=128Check the table again:
Switch# show mac address-table dynamic vlan 10
Mac Address Table
-------------------------------------------
Vlan Mac Address Type Ports
---- ----------- -------- -----
10 00aa.aaaa.aaaa DYNAMIC Fa0/1
10 00bb.bbbb.bbbb DYNAMIC Fa0/2The output shows that the switch learned PC-A through Fa0/1 and PC-B through Fa0/2. DYNAMIC means the entries were learned from received traffic rather than manually configured.
To remove all dynamic entries during a controlled lab, use:
Switch# clear mac address-table dynamicClearing the table temporarily causes unknown unicast flooding until the switch relearns the active source addresses. Use this command carefully on a production network.
How Do You Troubleshoot a Switching Problem?
Start at the physical layer, verify the VLAN and port state, inspect MAC learning, and then test ARP and IP connectivity. Avoid changing configurations until the failing layer has been identified.
Step 1: Check port status
Switch# show interfaces statusConfirm that the expected interfaces show connected and are assigned to the correct VLAN. A port displaying notconnect, disabled or err-disabled requires further investigation.
Step 2: Verify the interface configuration
Switch# show running-config interface fastEthernet 0/1
Switch# show interfaces fastEthernet 0/1 switchportCheck access mode, access VLAN and administrative status. Two hosts in different VLANs cannot communicate directly at Layer 2.
Step 3: Confirm MAC address learning
Switch# show mac address-table interface fastEthernet 0/1If no MAC address appears after the device sends traffic, check the cable, network adapter, interface counters, port security and VLAN assignment. If the same MAC repeatedly moves between ports, investigate a cabling loop, duplicate Layer 2 path or unstable downstream connection.
Step 4: Check errors and dropped frames
Switch# show interfaces fastEthernet 0/1
Switch# show interfaces counters errorsLook for CRC errors, input errors, late collisions or excessive drops. CRC errors commonly point to cabling, connector or physical-interface problems, though the complete interface context should be reviewed.
Step 5: Check ARP on the endpoint
On Windows:
C:\> arp -aOn Linux:
ip neighbour showAn incomplete neighbour entry means ARP resolution did not finish. Check whether both hosts use the correct subnet mask and belong to the same VLAN.
Step 6: Consider Spanning Tree state
A physically connected switch port may not forward frames if Spanning Tree has placed it in a blocking or discarding role. Use show spanning-tree vlan 10 and review the port role and state; for a deeper explanation, see Spanning Tree Protocol, root bridges and port states.
For a broader diagnostic workflow covering multiple OSI layers, follow this layer-by-layer network troubleshooting method.
Common Switching Mistakes
Several basic errors can produce similar symptoms:
- Assuming a switch learns from the destination MAC instead of the source MAC.
- Treating the switch MAC table and a host's ARP table as the same thing.
- Expecting devices in separate VLANs to communicate without Layer 3 routing.
- Assuming an empty MAC table proves that a port is faulty before generating traffic.
- Forgetting that unknown unicasts and broadcasts are flooded only within the relevant VLAN.
- Clearing the MAC table in production without considering the temporary increase in flooding.
- Ignoring an STP-blocked link because its physical status is still up.
Summary
Ethernet switches learn source MAC addresses, associate them with ports and VLANs, and examine destination MAC addresses to make forwarding decisions. Known unicasts are forwarded selectively, while unknown unicasts and broadcasts are flooded through eligible ports in the same VLAN.
A MAC address table explains where Layer 2 devices have been observed, while an ARP table maps local IPv4 addresses to MAC addresses. VLANs divide broadcast domains, routers connect IP networks, and Spanning Tree prevents Layer 2 loops from creating repeated frames.
Reviewed by Network Rhinos networking trainers.
To practise switching, VLANs, routing and Cisco IOS troubleshooting in guided labs, review the CCNA course and request current batch details.
