skip to content

Ethernet

How frames move inside one LAN: MAC-addressed frames with a CRC trailer, switches that learn where each MAC lives, and 802.1Q tags that split a switch into VLANs. Most first-hop faults start here.

on this pageshow

explore

questions

20

What is an Ethernet MAC address, and what do its OUI and the group and local bits of its first octet tell you?

level: juniorimportance: must knowfreq 60%

answer

  1. 48 bits, six octets
  2. who assigned the prefix
  3. lowest bit of the first octet
  4. the bit beside it
  5. all ones

basics

~20 s

A MAC address is Ethernet's 48-bit interface identifier. A global one starts with an IEEE-assigned prefix, usually a 24-bit OUI; in the first octet, the lowest bit marks a group address and the next bit a locally administered one.

solid answer

~40 s

A **MAC address** is the 48-bit identifier Ethernet writes into every frame's destination and source fields, shown as six hex octets such as `00-00-5E-00-53-01`. A globally unique one (an EUI-48) begins with a prefix the IEEE Registration Authority assigns, most often a 24-bit **OUI**, and the assignee numbers the rest. Two bits of the first octet have fixed meanings (RFC 9542): the least significant, the **I/G or group bit**, is 0 for unicast and 1 for multicast or broadcast; the next one, the **U/L or local bit**, is 0 for a globally assigned address and 1 for a locally administered one, which no OUI holder controls. All 48 bits set, `ff-ff-ff-ff-ff-ff`, is the **broadcast** address every station on the segment accepts.

go deeper

for a junior

Recall the shape: 48 bits as six hex octets, a 24-bit OUI naming the assignee, and ff-ff-ff-ff-ff-ff as broadcast. Know that the address only matters on the local link.

for a middle

Explain the group and local bits as the two lowest bits of the first octet and read them from the second hex digit. Separate global, local, unicast and group addresses with a real example of each.

for a senior

Show why a MAC is not proof of identity: software sets it, local addresses carry no registry meaning, and the OUI names a chip maker more often than a product. Tie that to how much policy you would hang on it.

for a principal

Frame the address space as a governance trade-off: global uniqueness from a registry versus local assignment by operators and software. Discuss what an organisation loses in inventory and auditing once local addresses become the norm.

## What a MAC address is Every Ethernet frame carries two **MAC (Media Access Control) addresses**: the destination, which tells receivers whether the frame is for them, and the source, which names the interface that sent it. Each is **48 bits**, written as six octets in hex, separated by hyphens (`00-00-5E-00-53-01`, the form RFC 9542 uses) or colons (`00:00:5e:00:53:01`). A MAC address only means something on one link: a router strips the frame and builds a new one for the next link, so the addresses never cross the router the way an IP address does. RFC 9542, which restates the IEEE 802 rules for IETF use and obsoletes RFC 7042, calls a globally unique 48-bit MAC address an **EUI-48** and says the old term "MAC-48" is obsolete. ## Reading the prefix: OUIs and longer blocks A global address is split between the IEEE Registration Authority and whoever it assigned a block to. The authority assigns a prefix; the holder numbers the remaining bits. | Block | Prefix length | Bits the holder controls | |---|---|---| | MA-L (the classic **OUI**) | 24 bits | 24 | | MA-M | 28 bits | 20 | | MA-S | 36 bits | 12 | So the first three octets of a global address usually identify the **assignee** of the block: often the maker of the network chip or adapter, not the brand or model of the device it ended up in. The IANA, for example, holds OUI `00-00-5E`, and RFC 9542 sets aside `00-00-5E-00-53-00` to `00-00-5E-00-53-FF` as documentation addresses. ## The two special bits in the first octet The low-order bits of the first octet are not part of anyone's numbering; they describe the address itself (RFC 9542 section 2.1.1): - **I/G (individual/group) bit**, value `0x01`, which RFC 9542 calls the M bit: 0 means **unicast**, one interface; 1 means a **group** address, multicast or broadcast. - **U/L (universal/local) bit**, value `0x02`, which RFC 9542 calls the X bit: 0 means the address is **global**, under the control of the prefix's owner; 1 means it is **locally administered**, assigned by the local operator or software, and the holder of a matching OUI has no authority over it. Because both bits sit in the low nibble of the first octet, you can read them from the **second hex digit**: | Second hex digit of the first octet | Group bit | Local bit | Meaning | |---|---|---|---| | 0, 4, 8, C | 0 | 0 | global unicast | | 1, 5, 9, D | 1 | 0 | global group | | 2, 6, A, E | 0 | 1 | local unicast | | 3, 7, B, F | 1 | 1 | local group | IEEE 802.3 transmits each octet least significant bit first, which is why the group bit sits at the bottom of the first octet: it is the very first address bit on the wire, so a receiver knows at once that the destination is a group address. ## Unicast, multicast and broadcast in practice 1. `00-00-5E-00-53-01` starts `00`: group bit 0, local bit 0, a global unicast address from IANA's OUI. 2. `01-00-5E-00-00-01` starts `01`: the group bit is set. It is the Ethernet address for the IPv4 all-hosts group 224.0.0.1 (RFC 1112). 3. `33-33-00-00-00-01` starts `33`: both bits set. It is a group address for IPv6 multicast (RFC 2464), and RFC 9542 notes that every `33-33` address has the local bit on. 4. `ff-ff-ff-ff-ff-ff` has all 48 bits set: the **broadcast** address, which every station on the segment accepts (RFC 894 maps IPv4 broadcast to it). A source address is always an individual address; the group bit is meaningful only in the destination. ## Common misreadings - Treating the OUI as a device fingerprint. It names the block's assignee, and only when the local bit is 0. - Assuming the address is fixed. The maker stores a global address, but software can make an interface send any address, so a MAC proves nothing about who sent a frame. - Reading the bits from the wrong end. The group and local bits are the two **least** significant bits of the first octet, not the top two. - Calling any address that starts with `01` a vendor address; that leading `1` is the group bit.

  • How many addresses does one 24-bit OUI give its holder?
    The holder controls the other 24 bits, so 2 to the 24th, 16,777,216 unicast EUI-48 addresses with the group bit clear. RFC 9542 adds that only the OUI's assignee may form group addresses from it, by setting the group bit in the first octet. Large makers therefore hold several OUIs, and smaller holders get an MA-M or MA-S block with 20 or 12 bits to number.
  • Can software change the MAC address an interface sends, and what does that mean for trust?
    Yes. The global address the maker stores is a default, not a lock; the operating system writes whatever source address it is told to into each frame, and locally administered addresses exist precisely so operators and software can assign their own. RFC 9542's security considerations warn that MAC addresses can be spoofed and that a known device can return with a new one, so a MAC is a hint, never an authenticated identity.

saying these in an interview costs you the question

  • The OUI tells you the brand and model of the device.
  • A MAC address is burned in and software cannot change what is sent.
  • The group and local bits are the two most significant bits of the first octet.
  • Ethernet's broadcast address is 00-00-00-00-00-00.
  • An address starting 01 is simply another vendor's unicast address.
  • MAC addresses travel unchanged end to end across routers.
open as a page

In a rack cabling audit, how does LLDP tell you which switch and port a server's network interface is plugged into?

level: juniorimportance: must knowfreq 32%

basics

~20 s

LLDP devices periodically announce their identity and the port each frame left from, to a multicast address standard switches do not forward. A server that hears its switch's frame learns the switch name and port number at the other end of its cable.

open as a page

How does an Ethernet switch differ from a hub, and what are collision domains and broadcast domains?

level: juniorimportance: must knowfreq 68%

basics

~20 s

A hub repeats every bit out every port, so its hosts share one collision domain; a switch forwards whole frames by destination MAC, so each port is its own collision domain. Neither splits a VLAN's broadcast domain; a router does.

open as a page

In Ethernet switching, what is a VLAN, and how does an access port differ from a trunk port?

level: juniorimportance: must knowfreq 68%

basics

~20 s

A VLAN is a separate broadcast domain carved out of shared switches. An access port belongs to one VLAN and carries untagged frames for an unaware host; a trunk carries many VLANs between switches, marking each frame with an 802.1Q VLAN ID.

open as a page

What fields make up an Ethernet II frame, and why is an untagged frame between 64 and 1,518 bytes long?

level: middleimportance: must knowfreq 46%

basics

~20 s

An Ethernet II frame is destination MAC (6 bytes), source MAC (6), EtherType (2), payload (46-1,500) and a 4-byte CRC: 64 to 1,518 bytes. The preamble and start delimiter precede it on the wire and are not counted.

open as a page

How does an Ethernet switch learn MAC addresses, and when does it forward, filter or flood a frame?

level: middleimportance: must knowfreq 60%

basics

~20 s

An Ethernet switch records each frame's source MAC against its arrival port. A known destination goes out that one port, or is discarded if that is the arrival port; unknown-unicast, broadcast and multicast frames flood to every other port.

open as a page

Why can't two hosts in different VLANs talk at layer 2, and how do router-on-a-stick and a switch virtual interface route between them?

level: middleimportance: must knowfreq 55%

basics

~20 s

Different VLANs are separate broadcast domains and subnets, so ARP never crosses between them and a layer 2 path does not exist; traffic must be routed. Router-on-a-stick puts every VLAN's gateway on one tagged link; a switch virtual interface puts them inside a layer 3 switch.

open as a page

How does LLDP differ from CDP, and why would a network built from several vendors' switches run LLDP?

level: juniorimportance: should knowfreq 24%

basics

~20 s

LLDP and CDP both advertise a device's identity, port and capabilities to its direct neighbour, but LLDP is the IEEE 802.1AB standard any vendor implements, while CDP is one vendor's proprietary protocol. Mixed-vendor networks run LLDP so every device can see every other.

open as a page

Which three TLVs open every LLDP frame, and how does the Time To Live TLV let a neighbour forget a device that disappeared?

level: middleimportance: should knowfreq 16%

basics

~20 s

Every LLDPDU opens with Chassis ID, Port ID and Time To Live. The TTL says how many seconds to keep the sender's information: without a fresh advertisement the entry ages out, and a TTL of 0 deletes it at once.

open as a page

Why does an Ethernet switch age out MAC address table entries, and what happens to traffic for a host that falls silent?

level: middleimportance: should knowfreq 33%

basics

~20 s

Ageing removes MAC table entries not refreshed by a frame from that source within the ageing time (802.1D recommends 300 s), so moved or departed hosts do not linger. Frames to a host whose entry aged out are flooded until it transmits again.

open as a page

What does an IEEE 802.1Q tag add to an Ethernet frame, and why does its 12-bit VLAN ID allow only 4,094 VLANs?

level: middleimportance: should knowfreq 40%

basics

~20 s

An 802.1Q tag inserts 4 bytes after the source MAC: TPID 0x8100, then a 3-bit priority (PCP), a 1-bit drop-eligible flag (DEI) and a 12-bit VLAN ID. Twelve bits give 4,096 values; 0 and 4095 are reserved, leaving 1-4094.

open as a page

On an IEEE 802.1Q trunk, how are native-VLAN frames and the allowed-VLAN list handled, and what breaks when the two ends disagree?

level: middleimportance: should knowfreq 32%

basics

~20 s

Native-VLAN frames cross an 802.1Q trunk untagged, and the receiver files any untagged frame into its own native VLAN; the allowed list decides which VLANs cross at all. A native mismatch silently joins two VLANs; an allowed-list mismatch cuts one off.

open as a page

Two servers on one Ethernet segment use a 9,000-byte MTU; small requests work but bulk TCP transfers stall through a switch passing only standard frames — what is happening, and why does nothing report it?

level: seniorimportance: should knowfreq 30%

basics

~20 s

The switch silently discards frames above its maximum frame size. Small packets fit, but both servers derive large TCP segments from their 9,000-byte MTU. No router is on the path, so no ICMP error ever tells the sender to shrink.

open as a page

How can you recognise a randomised MAC address from its bits, and what breaks when a network treats MAC addresses as stable device identities?

level: seniorimportance: should knowfreq 22%

basics

~20 s

A randomised MAC sets the local (U/L) bit and clears the group bit, so its second hex digit is 2, 6, A or E. Anything keyed to a stable MAC breaks: address leases, allow-lists, portal sessions and device inventories.

open as a page

What does an LLDP-speaking access switch reveal to a laptop plugged into an unused office wall port, and how would you limit it?

level: seniorimportance: should knowfreq 20%

basics

~20 s

A transmitting access port tells any laptop the switch's name, model and software release, its management address, the port's VLAN and often the voice VLAN. Stop LLDP transmit on untrusted ports, trim TLVs where phones need them, and authenticate ports.

open as a page

What is a MAC flooding attack on an Ethernet switch, what does the attacker gain, and how do per-port MAC limits stop it?

level: seniorimportance: should knowfreq 36%

basics

~20 s

MAC flooding fills an Ethernet switch's MAC table with forged source addresses, so real hosts cannot be learned and frames to them flood across the VLAN, where the attacker captures them. Per-port MAC limits cap the addresses one port may teach.

open as a page

What two trunk and access-port weaknesses allow Ethernet VLAN hopping, and which configuration choices close each one?

level: seniorimportance: should knowfreq 30%

basics

~20 s

VLAN hopping relies on two weaknesses: the native VLAN crossing a trunk untagged, and an edge port that auto-negotiates trunking. Using a native VLAN no host sits in (or tagging it) and fixing edge ports as access ports with negotiation off closes both.

open as a page

Which destination MAC does Ethernet use for IPv4 broadcast, IPv4 multicast and IPv6 multicast packets, and why can several groups share one MAC?

level: middleimportance: nice to knowfreq 15%

basics

~20 s

IPv4 broadcast goes to ff-ff-ff-ff-ff-ff. IPv4 multicast copies the group's low 23 bits under 01-00-5E (RFC 1112); IPv6 multicast puts the group's last 32 bits after 33-33 (RFC 2464). The bits left out let groups share a MAC.

open as a page

How does LLDP-MED let an IP phone on an access switch port learn its voice VLAN and negotiate its PoE power?

level: middleimportance: nice to knowfreq 12%

basics

~20 s

LLDP-MED, a TIA extension carried in ordinary LLDP frames, has the switch advertise a Network Policy TLV giving the voice VLAN ID, priority and DSCP, and lets phone and switch exchange Extended Power-via-MDI TLVs to agree an exact power draw.

open as a page

How do store-and-forward and cut-through Ethernet switching differ, and what does each trade between latency and error handling?

level: seniorimportance: nice to knowfreq 22%

basics

~20 s

A store-and-forward switch receives the whole frame and checks its FCS before sending, adding one frame's serialisation delay per hop. A cut-through switch starts sending once it has read the destination MAC, cutting latency but passing on corrupted frames.

open as a page