Link-layer switches

Ethernet defines the frame format and transmission over a LAN. Link-layer switches are the devices that receive those Ethernet frames and forward them to the correct destination.

A switch receives link-layer frames and forwards them to the right outgoing link.

Switches are transparent to hosts and routers:

Sometimes, more frames arrive at a switch's output than the link can handle:

Forwarding and filtering

Switches operate at Layer 2 (link layer) using MAC addresses (not IP addresses) to forward frames.

They use a MAC (switch) table to decide what to do with frames:

The switch table contains entries for some (but not necessarily all) of the hosts' and routers' network interfaces on a LAN.

Each entry contains:

Example:

------------------------------------------
Address             | Interface     | Time
------------------------------------------
62-FE-F7-11-89-A3   | 1             | 9:32
------------------------------------------
7C-BA-B2-B4-91-10   | 3             | 9:36
------------------------------------------

When a frame arrives with destination MAC address DD-DD-DD-DD-DD-DD on interface x, the switch performs a lookup and three cases are possible:

Case Behavior

1. No entry for the destination DD-DD-DD-DD-DD-DD

The switch does not know where DD-DD-DD-DD-DD-DD is.

It floods the frame out all interfaces except x.

2. Destination DD-DD-DD-DD-DD-DD maps to interface x

The destination is reachable via the same port the frame arrived on.

The switch performs the filtering function by discarding the frame.

This can happen when:

  • the destination device is on a shared segment (e.g., behind a hub or another switch)
  • the MAC table is wrong or stale
  • the host sends a frame to itself (rare but possible)

3. Destination DD-DD-DD-DD-DD-DD maps to interface y

The frame is sent to the outgoing interface y only.

As long as the switch table is complete and accurate:

Self-learning

Switches build and maintain their tables automatically.

Initially, the table is empty. For every incoming frame, the switch records:

This tells the switch which LAN segment the sender is on.

As hosts transmit frames, the switch gradually learns which interface each active device is reachable through.

Entries are removed after they have not been seen for a certain aging time, allowing the table to adapt when devices are removed or replaced.

Because the table is built automatically, switches are plug-and-play devices: simply connect the network cables, and no manual configuration is required.

Modern Ethernet switches support full-duplex communication, allowing each interface to transmit and receive simultaneously.

Properties of link-layer switching

Compared with broadcast LANs (such as buses or hub-based star topologies), switches offer several advantages:

  1. no collisions:
    • unlike a hub, a switch forwards frames only where they are needed
    • because traffic is not shared by all devices, multiple communications can occur at the same time without collisions
  2. heterogeneous links:
    • because a switch isolates one link from another, different links can use different speeds and transmission media
    • allowing older and newer devices to coexist on the same LAN
  3. simplified management:
    • switches can detect and isolate malfunctioning devices, such as a jabbering adapter that continuously transmits Ethernet frames
    • switches can collect traffic statistics (such as bandwidth usage and traffic types) to help monitor and troubleshoot the network

Switch poisoning

A switch normally forwards frames only to the port where the destination MAC address is known.

However, switches still flood certain types of traffic, including:

MAC flooding (also called CAM table overflow) is an attack that tries to overload the switch's MAC address table.

The attacker:

When the MAC table is full:

This increased flooding makes it easier for an attacker to observe traffic that would normally be isolated.

Although MAC flooding is possible, it is difficult to carry out successfully against modern network equipment. Many switches implement protections such as:

As a result, switched LANs are generally much more resistant to sniffing attacks than hub-based Ethernet networks or wireless LANs.

Previous Ethernet All ⏎ Next VLANs

A Kemar Joint