skip to content

Why does an Ethernet switch age out MAC address table entries, and what happens to traffic for a host that falls silent?

level: middleimportance: should knowfreq 33%

answer

  1. entries are refreshed, not permanent
  2. idle timer per address
  3. 802.1D's recommended default
  4. aged out means unknown unicast

basics

~20 s

Ageing removes MAC table entries not refreshed by a frame from that source within the ageing time (802.1D recommends 300 s), so moved or departed hosts do not linger. Frames to a host whose entry aged out are flooded until it transmits again.

solid answer

~50 s

Every learned entry carries a timestamp that is reset each time a frame arrives **from** that address; if no such frame arrives within the **ageing time**, the entry is removed. IEEE 802.1D recommends a default of 300 seconds, which the Bridge MIB (RFC 4188) records in `dot1dTpAgingTime`, settable from 10 to 1,000,000 seconds. Ageing exists because the table is finite and locations go stale: hosts are unplugged, moved, or replaced. The cost is that a host which only receives eventually drops out of the table, after which every frame to it is **unknown unicast** and is flooded across its VLAN until it sends something. The classic case is a router whose ARP entry for a host outlives the switch's MAC entry: the router keeps sending unicast frames, the switch keeps flooding them, and the usual fix is to keep the ARP refresh shorter than the MAC ageing time.

go deeper

for a junior

Remember that learned MAC entries are temporary: they are refreshed by frames the host sends and removed after an idle period, 300 seconds by the IEEE recommendation.

for a middle

Explain the refresh rule precisely (traffic from the host, not to it), why ageing exists, and that an aged-out destination is flooded rather than dropped.

for a senior

Diagnose unicast flooding from mismatched ARP and MAC timers under asymmetric routing, and pick a fix that addresses the timer relationship rather than masking it.

for a principal

Treat ageing as a trade between flooding volume, convergence after moves and exposure to table-exhaustion attacks, and set per-segment policy for receive-only hosts instead of one global value.

## What ageing is An Ethernet switch learns each host's location from the **source MAC address** of the frames it sends, storing the address with the port it arrived on. Each entry also carries the time it was last refreshed. **Ageing** is the rule that removes an entry when no frame **from** that address has been seen for longer than the **ageing time**. - The timer is **refreshed by traffic from the host**, not by traffic to it. A host that receives a steady stream but never sends still ages out. - The timer is **per entry**: busy hosts stay, idle ones go. - Statically configured entries normally do not age; dynamically learned ones always do. ## The value and whose it is The default comes from the IEEE bridging standard, not from an RFC. The Bridge MIB (RFC 4188) describes its `dot1dTpAgingTime` object as "the timeout period in seconds for aging out dynamically-learned forwarding information" and notes that "802.1D-1998 recommends a default of 300 seconds". The same object allows any value from 10 to 1,000,000 seconds, so the 300-second figure is a recommended default that operators and implementations may change, not a fixed protocol constant. ## Why a switch ages entries at all 1. **Table space.** The table has a fixed size in hardware. Without ageing, every MAC address ever seen (guests, replaced laptops, short-lived virtual machines) would stay until the table filled. 2. **Stale locations.** When a host moves to another port or another switch, its old entry points the wrong way. Ageing guarantees a wrong entry eventually disappears even if the host never speaks from its new place. (If it does speak, the switch overwrites the entry immediately; ageing is the fallback, not the main mechanism.) 3. **Removed hosts.** A switched-off host's entry is reclaimed instead of occupying a slot. ## What a silent host costs Once a host's entry ages out, the switch no longer knows its port. A frame addressed to it is now **unknown unicast**, and the switch **floods** it out every port in the VLAN except the arrival port. Nothing breaks: the host still receives the frame. But: - every other host on the VLAN receives and discards traffic that was never meant for it; - a large stream (a backup, a log feed, a video stream) to a receive-only host can consume bandwidth on every port in the VLAN; - every host on the VLAN can now capture that traffic, which matters for privacy. ## The classic production case: asymmetric routing The textbook symptom is **unicast flooding caused by mismatched timers**. 1. A router has the host in its **ARP cache** (the IPv4 table that maps the host's IP address to its MAC address). ARP cache lifetimes are an implementation choice, and some routers keep entries for hours. 2. Return traffic from the host leaves through a **different** router or path, so the switch never sees the host's frames on this segment. 3. After the ageing time the switch forgets the host; the first router, still holding a valid ARP entry, keeps sending unicast frames to the host's MAC address without re-asking. 4. The switch floods every one of those frames, for as long as the ARP entry lives. | Timer | Owner | Typical relationship | |---|---|---| | MAC ageing | the switch (802.1D recommends 300 s) | the shorter one | | ARP cache lifetime | the router or host (implementation choice) | often much longer | The usual fixes keep the two consistent: make the router refresh ARP entries more often than the switch ages MAC entries (the ARP exchange makes the host transmit, which relearns it), or raise the MAC ageing time on that VLAN, or add a static entry for a host that legitimately never transmits. ## Choosing the ageing time - **Too short**: quiet hosts age out constantly and their traffic floods. - **Too long**: a host that moved but stays silent is black-holed at its old port for longer, and the table holds more dead entries. RFC 4188's security section adds that a large value "may simplify forwarding table overflow attacks", because spoofed addresses then stay longer. ## Finding it in practice Flooding to a silent host shows up as unexpected unicast traffic for another host's MAC address arriving on unrelated ports, and as that host's entry missing from the switch's table while traffic to it continues.

  • A laptop is moved from one switch port to another; when does the switch learn the new location?
    As soon as the laptop sends any frame from the new port: learning overwrites the entry with the new port at once. Until then, frames for it still go to the old port and are lost there. Ageing only matters if the laptop stays silent: after the ageing time the stale entry goes, frames flood, and the laptop receives them again.
  • Why not simply set a very long MAC ageing time to stop unicast flooding?
    A long ageing time keeps stale entries: a host that moved but stays silent is black-holed at its old port for longer, and dead entries hold table slots. RFC 4188 also notes that a large ageing value may simplify forwarding-table overflow attacks. Aligning the router's ARP refresh with the MAC ageing time fixes the flooding without those costs.

saying these in an interview costs you the question

  • MAC entries expire a fixed 300 seconds after first being learned, whatever traffic follows.
  • Frames for a host whose MAC entry aged out are dropped until it speaks.
  • RFC 4188 makes the 300-second ageing time a fixed protocol constant.
  • Traffic sent to a host keeps its MAC table entry from ageing out.
  • A moved host stays unreachable until its old MAC entry ages out, even after it sends.