Ethernet frames, MAC addresses and how switches learn
What an Ethernet frame carries, what a MAC address identifies, and how a switch builds the table it forwards from.

An Ethernet frame is the unit a switch forwards: a header with a destination and a source address, a type field that says how to read the payload, the payload, and a trailer that lets the receiver detect corruption. A MAC (Media Access Control) address is the 48-bit identifier carried in that header. A switch needs no forwarding configuration: it learns from the frames it receives and forwards by the table it builds.
The model: learn from the source, forward by the destination
Read the whole subject through this sequence, applied to every frame on every port:
frame arrives on a port
|
v
read the SOURCE MAC and record it against that port (learning)
|
v
look up the DESTINATION MAC in the MAC address table
|
+-- known on another port ------ forward out that one port
|
+-- unknown / broadcast / group - flood within the VLAN
| (except the arrival port)
|
v
no frame from an entry for the aging time -> the entry is removed
A switch never asks who is where. It learns each address from the source field of the frames it receives, and decides from the destination field of the frame in hand. The rest of this sheet opens the frame, the MAC address it carries, and the table.
Terms. MAC address: the 48-bit identifier a frame is addressed to; link-layer address is the broader term for non-Ethernet media. MAC address table: the per-switch map from address to port, scoped to a VLAN. Flooding: sending a frame out every port in the VLAN except the arrival port.
Fields of an Ethernet frame
The frame starts with two 6-octet addresses, destination then source. A 2-octet field follows: a length in the original IEEE 802.3 framing, an EtherType naming the payload protocol in Ethernet II framing. Values of 1500 (0x05DC) and below are a length; 1536 (0x0600) and above are an EtherType. The payload follows, and the frame ends with a 4-octet frame check sequence (FCS), a CRC over the frame fields except the FCS itself.
+----------+----------+-------------+------------------+--------+
| dst MAC | src MAC | type/length | payload | FCS |
| 6 octets | 6 octets | 2 octets | 46-1500 octets |4 octets|
+----------+----------+-------------+------------------+--------+
| <- 14-octet header trailer -> |
minimum frame length 64 octets: a short payload is padded to 46
The payload ceiling is 1500 octets, the familiar Ethernet MTU.
What a MAC address identifies
A MAC address is 48 bits, written as six octets. The first three octets — the OUI (Organizationally Unique Identifier) — are assigned by IEEE to a manufacturer, and the manufacturer assigns the remaining three, so the whole value is meant to be globally unique; IEEE calls this form an EUI-48. Two bits in the first octet are not part of that identifier value and carry meaning instead:
- the I/G (Individual/Group) bit — the least significant bit of the first octet — is 0 for a unicast (individual) address and 1 for a group address, which covers multicast and broadcast;
- the U/L (Universal/Local) bit — the second least significant bit — is 0 for an address assigned by IEEE and 1 for one assigned locally by an administrator.
The broadcast address FF:FF:FF:FF:FF:FF is the all-ones group address. Everything else about a MAC address is a name, not a credential: nothing in the frame proves the sender is entitled to it.
How a switch learns and uses the MAC table
A switch keeps a MAC address table — one entry per known address, scoped to a VLAN, mapping the address to the port it was seen behind.
- Learning. For every frame that arrives, the switch reads the source MAC and records “this address is reachable out this port”, refreshing any existing entry.
- Forwarding. When a frame arrives, the switch looks up the destination MAC. If it is known and on a different port, the frame goes out that one port only.
- Flooding. If the destination is unknown, a broadcast, or a multicast with no forwarding state, the frame is sent out every port in the same VLAN except the one it arrived on. Unknown-unicast flooding is normal, not a fault: the destination’s reply teaches the switch which port reaches it.
- Aging. Every dynamic entry has a timer. If no frame arrives from that address for the aging time, the entry is removed, so a moved or disconnected device does not leave a stale entry.
The common misconception
A MAC address does not travel end to end. It identifies an interface on one link, and the frame is rebuilt at every hop. A host sending to another network addresses the frame to its own router, not to the far host: the router reads the IP header, picks a next hop, and builds a new frame with fresh link addresses. The IP addresses in the packet are preserved; the MAC addresses are not. Hosts are unaware of the switch — they address frames to a peer’s MAC and receive frames addressed to their own — so the port a frame leaves by is the switch’s decision, not theirs. The MAC table is therefore local to each switch: a switch only learns “this address is reachable through this port”, the direction traffic arrived from, not where the device physically is. Two switches on the same path hold two different tables.
A note on security
A MAC address is set in software and a frame carries no proof that the sender owns the address it claims, so a host can emit frames carrying another device’s source address. The layer-2 controls that raise the cost of that — port security, DHCP snooping, ARP inspection — are a subject of their own.
Level and prerequisites. L1 — fundamentals. No prerequisites; a rough idea of what an IP address is helps, and no hands-on configuration is required.
Where to go next
- Networking — the area this sheet belongs to.
References
- IEEE Std 802.3-2022 — IEEE Standard for Ethernet (standard; full text not freely available).
- IEEE Registration Authority — MAC address blocks (MA-L/MA-M/MA-S) and the OUI assignment.
- RFC 7042 — 48-bit MAC identifiers, the Group and Local bits (usually labelled I/G and U/L in networking documentation), and local vs. global administration.
- RFC 894 and RFC 2464 — IPv4 and IPv6 over Ethernet.
- IANA, IEEE 802 Numbers — EtherType values.
- RFC 826 and RFC 1180 — address resolution and per-hop link headers.
- Cisco documentation — MAC address learning, forwarding and aging.
- Wikipedia, Ethernet frame — secondary description of the frame layout.