Routelearn.net
Course menu

Unit 4: Ethernet and CablingLesson 4.4 (4 of 9 in this unit)19 of 84 in the Network Fundamentals course

How a Switch Learns MAC Addresses

A switch starts with no knowledge of the devices connected to it, yet within seconds it sends every frame to the right port. Learn how it builds its MAC address table and how it decides to forward, flood or filter each frame.

Beginner · 13 min read · Before this: MAC addresses, The Ethernet frame

A MAC address table is the table a switch builds by recording the source MAC address of each frame it receives, together with the port (and VLAN) it arrived on. The switch uses it to forward frames for known destinations out of a single port, flood frames for unknown destinations, and filter frames whose destination is on the port they came in on.

In simple terms: The switch notes which port each device sends from. Later, when a frame is addressed to that device, the switch looks up the port and sends the frame only out of that port.

What the MAC address table is

Every switch keeps a list called the MAC address table (also called the CAM table, after the Content Addressable Memory it is stored in). Each row says: “this MAC address is reached through this port”.

MAC addressPortVLANAge
02:00:00:00:00:aaPort 1112 s
02:00:00:00:00:bbPort 2145 s
02:00:00:00:00:01Port 8 (to the router)13 s

Nobody types these rows in. The switch fills the table by itself, simply by reading the frames that pass through it. The VLAN column matters on larger networks, where one switch is split into several separate LANs. On a home switch, everything is in one VLAN.

💡 In simple terms: a switch is like a receptionist who notes which desk each person is sitting at by watching where their outgoing letters come from. After a while, incoming letters go straight to the right desk instead of being shouted across the room.

Why switches learn

A hub repeated every frame to every port. Every device received everything, only one device could send at a time, and anyone could see everyone else's traffic. A switch fixes this by sending each frame only out of the port that leads to the destination. To do that, it must know where every device is. Learning is how it finds out, without any configuration.

Where this happens

MAC learning is a Layer 2 job. It happens inside every Ethernet switch, from a five-port desk switch to the switch built into your home router to large office switches. To forward a frame, the switch reads only the Ethernet header: the destination and source MAC addresses. It does not need to look at IP addresses.

The four actions

For every frame that arrives, a switch learns from the source address, then does one of three things with the frame:

ActionWhenResult
LearnAlways, using the source MAC addressRecords MAC address + port + VLAN in the MAC address table
ForwardThe destination MAC address is in the table, on another portSent out of that one port only
FilterThe destination MAC address is on the same port the frame arrived onDropped: the destination is on that side already
FloodThe destination is unknown or a broadcast (or multicast, without IGMP snooping)Sent out of every port in the VLAN except the incoming one
Frame arrives on a port
Read the Ethernet header.
Learn the source MAC
Add or refresh the entry: source MAC address → this port. Reset its age timer.
Look up the destination MAC
Broadcast or unknown? Flood. Known on another port? Forward. Known on the same port? Filter.
Send (or drop) the frame
The MAC addresses and data in the frame are not changed.
The decision a switch makes for every frame, millions of times per second, in hardware.

Watch a switch learn

Step 1 of 7 · VLAN 10
Gi1/0/1Gi1/0/2Gi1/0/3
SW1
Layer 2 switch
Laptop A
MAC …0010
Laptop B
MAC …0020
Printer C
MAC …0030

A sends a frame to B

The frame arrives on Gi1/0/1. The switch doesn't know where B is yet.

SW1 · MAC address table
VLANMAC addressPort
100200.0000.0010—
100200.0000.0020—

0200.0000.0010 → 0200.0000.0020

Learn the source, look up the destination: known → forward to one port; unknown → flood.

Step by step: from an empty table

A switch has just been powered on. PC A (…:aa) is on port 1, PC B (…:bb) is on port 2 and PC C (…:cc) is on port 3. The MAC address table is empty.

123Switchtable starts emptyPC Aport 1 · …:aaPC Bport 2 · …:bbPC Cport 3 · …:cc
  1. 1. 1. A sends to B. The switch learns “…:aa is on port 1”.
  2. 2. 2. …:bb is unknown, so it floods out of ports 2 and 3. PC C sees that the destination is not its MAC address and discards the frame.
  3. 3. 3. B replies to A. The switch learns “…:bb is on port 2”. It already knows where …:aa is, so it forwards the frame out of port 1 only.
  4. 4. 4. From now on, frames between A and B go straight to the right port. PC C sees none of them.
After stepMAC address tableDecision for that frame
1–2…:aa → port 1Flood (destination unknown)
3…:aa → port 1, …:bb → port 2Forward to port 1
4Unchanged (ages refreshed)Forward to port 2

What is in the frame (and what is not changed)

The switch makes its decision from the two MAC address fields, and it does not rewrite the frame. The frame that leaves has the same destination MAC address, source MAC address, EtherType and payload as the frame that arrived. (On trunk links, a switch can add or remove a VLAN tag, which the VLAN lesson explains.)

FieldUsed for
Source MAC addressLearning: “this address is behind the incoming port”
Destination MAC addressForwarding: which port (or ports) to send the frame out of
FCSError check on store-and-forward switches; damaged frames are dropped
IP addresses, ports, dataNot read at all by a Layer 2 switch

Flooding: unknown unicast and broadcasts

The switch floods a frame in two very different situations:

  • Unknown unicast: the frame is for one device, but the switch has not yet learned where that device is. Flooding is a temporary measure: “send it everywhere, and the right device will accept it”. The reply teaches the switch where the device is, and flooding for that address stops.
  • Broadcast (ff:ff:ff:ff:ff:ff): the frame really is for everyone, such as an ARP request or a DHCP Discover. The switch always floods these, no matter what is in its table.

Either way, a flooded frame goes out of every port in the same VLAN except the one it came in on. Routers do not forward it, so it stops at the router.

Learn more: Unicast, Broadcast and MulticastBroadcast Domains

Filtering

Situation: PC A and PC B are both connected to a small desk switch, which connects to one port on the main switch. When A sends to B, the main switch may also receive a copy of the frame, for example while the desk switch is still learning and floods it.

Main switchGi1/0/5Desk switchPC APC B
  1. 1. The frame reaches the main switch. Its MAC address table says PC B is on Gi1/0/5.
  2. 2. Same port: dropped. PC B is reached through the same port the frame came in on, so sending it back would be pointless. The main switch filters (drops) it.

Notice that one switch port can have many MAC addresses behind it. The main switch learns both …:aa and …:bb on Gi1/0/5. That is normal for a port leading to another switch, an access point or a router.

MAC address aging

Entries aren't permanent. If a MAC address isn't seen as a source for 300 seconds (the Cisco default), its entry is removed. This keeps the table up to date when devices move or are switched off, and it frees space. Depending on the platform, a table holds from a few thousand to hundreds of thousands of entries.

If a device moves before its entry ages out, the switch updates the entry as soon as it sees that MAC address as a source on a new port. In each VLAN, a MAC address can be on only one port at a time.

A real-world example: moving desks

Sam unplugs a laptop from port 4 on the second floor and plugs it into port 17 an hour later. The old entry has already aged out, so any frame sent to the laptop before it sends anything is flooded. The laptop's own first frame (often an ARP or DHCP message as it reconnects) teaches the switch the new port, and traffic flows normally again within a second. Nobody had to change anything on the switch.

When MAC learning goes wrong

ProblemWhat you noticeWhy
Switching loopThe network freezes; one MAC address seems to “flap” between two portsTwo paths between switches with no Spanning Tree: broadcasts loop endlessly, and the switch keeps relearning the same MAC address on different ports
Table fullEvery PC suddenly sees other people's traffic; the network slows downNo space to learn new addresses, so their frames are unknown unicast and get flooded (sometimes caused deliberately by a “MAC flooding” attack)
Duplicate MACTwo devices lose their connection in turnsThe same MAC address is learned on two ports, so the switch keeps moving the entry
One-way trafficConstant flooding of traffic for one silent deviceA device that only receives (such as some displays) is never learned, because it never sends a frame

Seen on a real switch

You do not need to configure anything for learning to work. If you have access to a managed switch, you can view the MAC address table. This is Cisco IOS output:

Example output · based on Cisco documentation; exact format varies by platform and software version
SW1#show mac address-table dynamic
          Mac Address Table
-------------------------------------------
Vlan    Mac Address       Type        Ports
----    -----------       --------    -----
  10    0200.0000.0010    DYNAMIC     Gi1/0/1
  10    0200.0000.0020    DYNAMIC     Gi1/0/2
  20    0200.0000.0030    DYNAMIC     Gi1/0/3
Total Mac Addresses for this criterion: 3
What to look for: each row is one learned address in one VLAN. Ports shows where the switch sends frames for that address. If a MAC address appears on an uplink port, the device is somewhere beyond the next switch. DYNAMIC means the entry was learned from traffic and will age out, rather than configured by hand.
show mac address-table address 0200.0000.0020

Find which port a specific device is on. This is useful for tracing a device through several switches.

clear mac address-table dynamic

Remove all learned entries. The switch relearns them as traffic flows, so expect brief flooding.

Matching it up from a PC

To find which switch port a PC is on, first get its MAC address from the PC (ipconfig /all on Windows, ip link on Linux). Then look for that MAC address in the switch's table. If you can't reach the PC itself, ping it from another PC on the same LAN and run arp -a to see its MAC address. The ping also makes the device send replies, so the switch learns its port.

Common mistakes

  • Thinking the switch learns destination addresses. It learns only source addresses, because only the source tells it which port a device is behind.
  • Confusing the MAC address table with the ARP table. A switch's MAC address table maps MAC address → port. A PC's ARP table maps IP address → MAC address.
  • Thinking flooding means something is broken. Brief flooding of unknown unicast frames is normal, and broadcasts are always flooded.
  • Expecting a switch to stop broadcasts. A switch floods them to every port in the VLAN. Broadcasts stop only at a router (the edge of the broadcast domain).
  • Assuming there is only one MAC address per port. A port connected to another switch or an access point can have many MAC addresses behind it.
✅ Key takeaways
  • The MAC address table maps MAC address → port (and VLAN).
  • Switches learn from the source MAC and forward using the destination MAC.
  • Known unicast: forward out of one port. Unknown unicast and broadcast: flood. Destination on the same port: filter.
  • Entries age out after about 5 minutes of silence, so the table stays up to date.
  • The switch does not change the MAC addresses or the data; it only chooses where to send the frame.

Check yourself

Predict · scenario 1

A switch receives a frame for a MAC address that is not in its MAC address table. What does it do?

Predict · scenario 2

PC A sends a frame to PC B through a switch. Which MAC address does the switch add to its table from this frame?

Predict · scenario 3

The MAC address table says …:bb is on port 2. A frame for …:bb arrives on port 2. What happens?

Predict · scenario 4

A laptop has sent nothing for 10 minutes. A frame for it arrives at the switch. What does the switch do (with default settings)?

Where to go next

Next, learn about the cables that connect switches, or see how a PC finds the destination MAC address to put in each frame.

Learn more: Ethernet Physical Layer StandardsCopper CablingARP Fundamentals

FAQ

Does a switch learn from the destination MAC address?
No. It learns only from the source MAC address, because the sender is the one device the switch knows for certain is reachable through the incoming port. The switch uses the destination MAC address to decide where to send the frame.
What happens when the MAC address table is full?
The switch cannot learn new addresses, so frames for those devices are treated as unknown unicast and flooded out of every port in the VLAN. The network keeps working, but it slows down and every device receives traffic meant for others. This is why attackers sometimes try to fill the table on purpose.
Does a switch need IP addresses to forward frames?
No. A Layer 2 switch forwards frames using MAC addresses only. A managed switch may have an IP address of its own, but that address is only used to manage the switch, for example to log in to it remotely.
How long does a switch remember a MAC address?
A switch keeps an entry until it has not seen that address as a source for the aging time. On most switches, the default aging time is 300 seconds (5 minutes). Every new frame from the device resets the timer.