What the MAC address table is
Every switch keeps a list called the MAC address table (also called the CAM table, after the Content Addressable Memory it is stored in). Each row says: “this MAC address is reached through this port”.
| MAC address | Port | VLAN | Age |
|---|---|---|---|
02:00:00:00:00:aa | Port 1 | 1 | 12 s |
02:00:00:00:00:bb | Port 2 | 1 | 45 s |
02:00:00:00:00:01 | Port 8 (to the router) | 1 | 3 s |
Nobody types these rows in. The switch fills the table by itself, simply by reading the frames that pass through it. The VLAN column matters on larger networks, where one switch is split into several separate LANs. On a home switch, everything is in one VLAN.
💡 In simple terms: a switch is like a receptionist who notes which desk each person is sitting at by watching where their outgoing letters come from. After a while, incoming letters go straight to the right desk instead of being shouted across the room.
Why switches learn
A hub repeated every frame to every port. Every device received everything, only one device could send at a time, and anyone could see everyone else's traffic. A switch fixes this by sending each frame only out of the port that leads to the destination. To do that, it must know where every device is. Learning is how it finds out, without any configuration.
Where this happens
MAC learning is a Layer 2 job. It happens inside every Ethernet switch, from a five-port desk switch to the switch built into your home router to large office switches. To forward a frame, the switch reads only the Ethernet header: the destination and source MAC addresses. It does not need to look at IP addresses.
The four actions
For every frame that arrives, a switch learns from the source address, then does one of three things with the frame:
| Action | When | Result |
|---|---|---|
| Learn | Always, using the source MAC address | Records MAC address + port + VLAN in the MAC address table |
| Forward | The destination MAC address is in the table, on another port | Sent out of that one port only |
| Filter | The destination MAC address is on the same port the frame arrived on | Dropped: the destination is on that side already |
| Flood | The destination is unknown or a broadcast (or multicast, without IGMP snooping) | Sent out of every port in the VLAN except the incoming one |
Watch a switch learn
A sends a frame to B
The frame arrives on Gi1/0/1. The switch doesn't know where B is yet.
| VLAN | MAC address | Port |
|---|---|---|
| 10 | 0200.0000.0010 | — |
| 10 | 0200.0000.0020 | — |
0200.0000.0010 → 0200.0000.0020
Step by step: from an empty table
A switch has just been powered on. PC A (…:aa) is on port 1, PC B (…:bb) is on port 2 and PC C (…:cc) is on port 3. The MAC address table is empty.
- 1. 1. A sends to B. The switch learns “…:aa is on port 1”.
- 2. 2. …:bb is unknown, so it floods out of ports 2 and 3. PC C sees that the destination is not its MAC address and discards the frame.
- 3. 3. B replies to A. The switch learns “…:bb is on port 2”. It already knows where …:aa is, so it forwards the frame out of port 1 only.
- 4. 4. From now on, frames between A and B go straight to the right port. PC C sees none of them.
| After step | MAC address table | Decision for that frame |
|---|---|---|
| 1–2 | …:aa → port 1 | Flood (destination unknown) |
| 3 | …:aa → port 1, …:bb → port 2 | Forward to port 1 |
| 4 | Unchanged (ages refreshed) | Forward to port 2 |
What is in the frame (and what is not changed)
The switch makes its decision from the two MAC address fields, and it does not rewrite the frame. The frame that leaves has the same destination MAC address, source MAC address, EtherType and payload as the frame that arrived. (On trunk links, a switch can add or remove a VLAN tag, which the VLAN lesson explains.)
| Field | Used for |
|---|---|
| Source MAC address | Learning: “this address is behind the incoming port” |
| Destination MAC address | Forwarding: which port (or ports) to send the frame out of |
| FCS | Error check on store-and-forward switches; damaged frames are dropped |
| IP addresses, ports, data | Not read at all by a Layer 2 switch |
Flooding: unknown unicast and broadcasts
The switch floods a frame in two very different situations:
- Unknown unicast: the frame is for one device, but the switch has not yet learned where that device is. Flooding is a temporary measure: “send it everywhere, and the right device will accept it”. The reply teaches the switch where the device is, and flooding for that address stops.
- Broadcast (
ff:ff:ff:ff:ff:ff): the frame really is for everyone, such as an ARP request or a DHCP Discover. The switch always floods these, no matter what is in its table.
Either way, a flooded frame goes out of every port in the same VLAN except the one it came in on. Routers do not forward it, so it stops at the router.
Learn more: Unicast, Broadcast and MulticastBroadcast Domains
Filtering
Situation: PC A and PC B are both connected to a small desk switch, which connects to one port on the main switch. When A sends to B, the main switch may also receive a copy of the frame, for example while the desk switch is still learning and floods it.
- 1. The frame reaches the main switch. Its MAC address table says PC B is on Gi1/0/5.
- 2. Same port: dropped. PC B is reached through the same port the frame came in on, so sending it back would be pointless. The main switch filters (drops) it.
Notice that one switch port can have many MAC addresses behind it. The main switch learns both …:aa and …:bb on Gi1/0/5. That is normal for a port leading to another switch, an access point or a router.
MAC address aging
Entries aren't permanent. If a MAC address isn't seen as a source for 300 seconds (the Cisco default), its entry is removed. This keeps the table up to date when devices move or are switched off, and it frees space. Depending on the platform, a table holds from a few thousand to hundreds of thousands of entries.
If a device moves before its entry ages out, the switch updates the entry as soon as it sees that MAC address as a source on a new port. In each VLAN, a MAC address can be on only one port at a time.
A real-world example: moving desks
Sam unplugs a laptop from port 4 on the second floor and plugs it into port 17 an hour later. The old entry has already aged out, so any frame sent to the laptop before it sends anything is flooded. The laptop's own first frame (often an ARP or DHCP message as it reconnects) teaches the switch the new port, and traffic flows normally again within a second. Nobody had to change anything on the switch.
When MAC learning goes wrong
| Problem | What you notice | Why |
|---|---|---|
| Switching loop | The network freezes; one MAC address seems to “flap” between two ports | Two paths between switches with no Spanning Tree: broadcasts loop endlessly, and the switch keeps relearning the same MAC address on different ports |
| Table full | Every PC suddenly sees other people's traffic; the network slows down | No space to learn new addresses, so their frames are unknown unicast and get flooded (sometimes caused deliberately by a “MAC flooding” attack) |
| Duplicate MAC | Two devices lose their connection in turns | The same MAC address is learned on two ports, so the switch keeps moving the entry |
| One-way traffic | Constant flooding of traffic for one silent device | A device that only receives (such as some displays) is never learned, because it never sends a frame |
Seen on a real switch
You do not need to configure anything for learning to work. If you have access to a managed switch, you can view the MAC address table. This is Cisco IOS output:
SW1#show mac address-table dynamic Mac Address Table ------------------------------------------- Vlan Mac Address Type Ports ---- ----------- -------- ----- 10 0200.0000.0010 DYNAMIC Gi1/0/1 10 0200.0000.0020 DYNAMIC Gi1/0/2 20 0200.0000.0030 DYNAMIC Gi1/0/3 Total Mac Addresses for this criterion: 3
show mac address-table address 0200.0000.0020Find which port a specific device is on. This is useful for tracing a device through several switches.
clear mac address-table dynamicRemove all learned entries. The switch relearns them as traffic flows, so expect brief flooding.
Matching it up from a PC
To find which switch port a PC is on, first get its MAC address from the PC (ipconfig /all on Windows, ip link on Linux). Then look for that MAC address in the switch's table. If you can't reach the PC itself, ping it from another PC on the same LAN and run arp -a to see its MAC address. The ping also makes the device send replies, so the switch learns its port.
Common mistakes
- Thinking the switch learns destination addresses. It learns only source addresses, because only the source tells it which port a device is behind.
- Confusing the MAC address table with the ARP table. A switch's MAC address table maps MAC address → port. A PC's ARP table maps IP address → MAC address.
- Thinking flooding means something is broken. Brief flooding of unknown unicast frames is normal, and broadcasts are always flooded.
- Expecting a switch to stop broadcasts. A switch floods them to every port in the VLAN. Broadcasts stop only at a router (the edge of the broadcast domain).
- Assuming there is only one MAC address per port. A port connected to another switch or an access point can have many MAC addresses behind it.
- The MAC address table maps MAC address → port (and VLAN).
- Switches learn from the source MAC and forward using the destination MAC.
- Known unicast: forward out of one port. Unknown unicast and broadcast: flood. Destination on the same port: filter.
- Entries age out after about 5 minutes of silence, so the table stays up to date.
- The switch does not change the MAC addresses or the data; it only chooses where to send the frame.
Check yourself
A switch receives a frame for a MAC address that is not in its MAC address table. What does it do?
PC A sends a frame to PC B through a switch. Which MAC address does the switch add to its table from this frame?
The MAC address table says …:bb is on port 2. A frame for …:bb arrives on port 2. What happens?
A laptop has sent nothing for 10 minutes. A frame for it arrives at the switch. What does the switch do (with default settings)?
Where to go next
Next, learn about the cables that connect switches, or see how a PC finds the destination MAC address to put in each frame.
Learn more: Ethernet Physical Layer StandardsCopper CablingARP Fundamentals