skip to content

How does an Ethernet switch learn MAC addresses, and when does it forward, filter or flood a frame?

level: middleimportance: must knowfreq 60%

answer

  1. learn from where frames come from
  2. source MAC against arrival port
  3. known, same port, or unknown
  4. everything but the arrival port

basics

~20 s

An Ethernet switch records each frame's source MAC against its arrival port. A known destination goes out that one port, or is discarded if that is the arrival port; unknown-unicast, broadcast and multicast frames flood to every other port.

solid answer

~50 s

A switch builds its MAC address table passively, by **source-address learning**: for every arriving frame it records the source MAC with the arrival port and a timestamp, overwriting the entry if the host has moved. The forwarding decision uses the **destination** MAC: if the table knows it on another port, the frame goes out that port only (**forward**); if it is known on the arrival port, the frame is discarded because the destination already saw it on that segment (**filter**); if it is unknown, or is the broadcast address, or is a multicast group the switch is not snooping, the frame is **flooded** out every port in the VLAN except the arrival port. Replies then teach the switch where the other hosts are, so flooding dies away after the first exchange. Entries that are not refreshed age out.

code

pseudocode · 13 lines
pseudocode
on frame F arriving on port P in VLAN V:
    if F.src is a unicast address:
        table[V, F.src] = (port: P, lastSeen: now)    # learn or refresh
    if F.dst is a group address (I/G bit = 1):
        flood F to every port in V except P            # broadcast, multicast
    else if (V, F.dst) in table:
        out = table[V, F.dst].port
        if out == P:
            discard F                                   # filter: same segment
        else:
            send F out port out                         # forward
    else:
        flood F to every port in V except P            # unknown unicast

go deeper

for a junior

Remember the pair: learn from the source address and arrival port, decide using the destination address. Unknown destinations and broadcasts are flooded to all other ports.

for a middle

Walk the three-host trace frame by frame: what is learned, which frames flood, and why flooding stops after the first reply. Name filtering as the third outcome.

for a senior

Explain the operational edges: moved hosts relearned only when they speak, silent hosts flooded, table exhaustion forcing flooding, and using the table to trace a host to its port.

for a principal

Weigh passive learning's simplicity against its costs at scale: flooding volume, table sizing in dense virtualised racks, and when a control-plane-driven address distribution is worth its complexity.

## The table and the two addresses An Ethernet switch keeps a **MAC address table**, which the IEEE bridging standard calls the **filtering database** and the Bridge MIB (RFC 4188) models as the forwarding database: each entry maps a unicast MAC address to the port it was last seen on, with an age. Every frame carries two addresses, and the switch uses them for two different jobs: - the **source MAC** tells the switch **where a host is**: it just sent a frame in through this port. This is used for **learning**. - the **destination MAC** tells the switch **where the frame wants to go**. This is used for the **forwarding decision**. The switch never asks anyone where a host is. The switch sends no query of its own to locate hosts and needs no configuration: it watches traffic, which is why this is called **transparent bridging**. ## The three forwarding outcomes 1. **Forward**: the destination is in the table on a different port, so the frame goes out that one port only. 2. **Filter**: the destination is in the table on the **same** port the frame arrived on (for example two hosts behind a hub or another switch on that port), so the frame is discarded; the destination has already received it on that segment. 3. **Flood**: the frame goes out **every port in the VLAN except the arrival port** when the destination is - an **unknown unicast** address (not in the table, never learned or aged out), - the **broadcast** address `ff:ff:ff:ff:ff:ff`, - a **multicast** (group) address, unless the switch does IGMP or MLD snooping (RFC 4541, an Informational RFC) to restrict it to interested ports. The arrival port is always excluded: sending a frame back where it came from would only duplicate it on that segment. ## A fresh switch with three hosts Take a switch that has just powered on with an empty table. Host A (`00-00-5E-00-53-0A`, a documentation address from RFC 9542) is on port 1, B (`...-0B`) on port 2, C (`...-0C`) on port 3. | Step | Frame | Switch learns | Forwarding decision | |---|---|---|---| | 1 | A to broadcast (A's ARP request for B) | A is on port 1 | Flood to ports 2 and 3 | | 2 | B to A (B's unicast ARP reply) | B is on port 2 | A is known on port 1: forward to port 1 only | | 3 | A to B (the data) | refresh A on port 1 | B is known on port 2: forward to port 2 only | | 4 | A to C (A already had C's MAC cached) | refresh A | C is unknown: flood to ports 2 and 3 | | 5 | C to A (the reply) | C is on port 3 | forward to port 1 only | After step 5 every host is known and no more unicast is flooded. Note step 1: the switch learns from a broadcast frame, because learning looks only at the source, which in a valid frame is always a single station's address. ## The loop in pseudocode The code example shows the receive loop. Two details matter: learning happens **before** the forwarding decision on every frame, and only **unicast** source addresses are learned (a group address in the source field is not a valid station location). ## What learning gets wrong, and what limits it - **A host that moves** (cable moved, laptop re-docked, virtual machine migrated) is relearned the instant it sends a frame from its new port; until then, frames for it go to the old port. - **A host that never sends** is never learned, or ages out, and frames for it are flooded every time. Ageing has its own rules: idle entries are removed after an ageing time, which IEEE 802.1D recommends defaulting to 300 seconds. - **The table is finite.** If it fills, new addresses cannot be learned, and their traffic is flooded; an attack that fills it on purpose is called MAC flooding. - **Loops break learning.** With two paths between switches, a flooded frame returns on another port and the source address flaps between ports; preventing that is the spanning tree protocol's job, not the learning algorithm's. ## Finding a host from its MAC address Because the table maps addresses to ports, it is also the standard way to find where a host is plugged in: look its MAC up on one switch, follow that port to the next switch if it is an uplink, and repeat until the port is an edge port. The Bridge MIB's forwarding-database table (`dot1dTpFdbTable`) exposes exactly that mapping for management tools.

  • Why does a switch learn from the source address rather than the destination?
    The source address is evidence of location: a frame from that host has just arrived through this port, so the host is reachable that way. The destination says only where the frame wants to go, which is exactly what the switch does not yet know. Learning from destinations would record guesses, not observations.
  • How would you find which switch port a host is plugged into, given its MAC address?
    Make the host send something so it is learned, then look its MAC up in the switch's MAC address table, which the Bridge MIB (RFC 4188) exposes as the forwarding-database table. If the port is an uplink to another switch, repeat on that switch. The trail ends at an edge port carrying only that host's address, or a handful behind a phone or hypervisor.
  • Does an Ethernet switch learn anything from a broadcast frame?
    Yes. Learning uses only the source address, and a valid frame's source is always a single station, so a broadcast such as an ARP request teaches the switch where its sender is. The broadcast destination affects only the forwarding decision, which is to flood.

A new office mailroom clerk learns where people sit from the return address on each envelope and the desk it was collected from; post for someone not yet seen is photocopied to every desk.

saying these in an interview costs you the question

  • A switch learns the destination MAC addresses of the frames it forwards.
  • A switch drops unknown-unicast frames until it has learned the address.
  • Flooding sends the frame out every port, including the one it came in on.
  • The switch sends ARP requests to discover which port a host is on.
  • A learned MAC entry stays in the table until the switch reboots.