Link-layer switches
Ethernet defines the frame format and transmission over a LAN. Link-layer switches are the devices that receive those Ethernet frames and forward them to the correct destination.
A switch receives link-layer frames and forwards them to the right outgoing link.
Switches are transparent to hosts and routers:
- a host or router sends a frame to another host or router, not to the switch
- it just puts the frame on the LAN
- it does not know or care that a switch will forward it
Sometimes, more frames arrive at a switch's output than the link can handle:
- this can cause temporary overload
- to handle this, switches use buffers (queues) on output ports
- this is similar to how routers buffer packets on outgoing links
Forwarding and filtering
Switches operate at Layer 2 (link layer) using MAC addresses (not IP addresses) to forward frames.
They use a MAC (switch) table to decide what to do with frames:
- filtering: decide whether to drop a frame
- forwarding: decide which interface(s) to send a frame to
The switch table contains entries for some (but not necessarily all) of the hosts' and routers' network interfaces on a LAN.
Each entry contains:
- a MAC address
- the interface (port) where that MAC address is reachable
- an aging timer (used to remove stale entries after inactivity)
Example:
------------------------------------------
Address | Interface | Time
------------------------------------------
62-FE-F7-11-89-A3 | 1 | 9:32
------------------------------------------
7C-BA-B2-B4-91-10 | 3 | 9:36
------------------------------------------
When a frame arrives with destination MAC address DD-DD-DD-DD-DD-DD on interface x, the switch performs a lookup and three cases are possible:
| Case | Behavior |
|---|---|
|
1. No entry for the destination |
The switch does not know where It floods the frame out all interfaces except |
|
2. Destination |
The destination is reachable via the same port the frame arrived on. The switch performs the filtering function by discarding the frame. This can happen when:
|
|
3. Destination |
The frame is sent to the outgoing interface |
As long as the switch table is complete and accurate:
- the switch can forward unicast frames without broadcasting (flooding) unknown destinations
- in this sense, a switch is smarter than a hub
Self-learning
Switches build and maintain their tables automatically.
Initially, the table is empty. For every incoming frame, the switch records:
- the frame's source MAC address
- the interface on which the frame arrived
- the time the address was last seen
This tells the switch which LAN segment the sender is on.
As hosts transmit frames, the switch gradually learns which interface each active device is reachable through.
Entries are removed after they have not been seen for a certain aging time, allowing the table to adapt when devices are removed or replaced.
Because the table is built automatically, switches are plug-and-play devices: simply connect the network cables, and no manual configuration is required.
Modern Ethernet switches support full-duplex communication, allowing each interface to transmit and receive simultaneously.
Properties of link-layer switching
Compared with broadcast LANs (such as buses or hub-based star topologies), switches offer several advantages:
- no collisions:
- unlike a hub, a switch forwards frames only where they are needed
- because traffic is not shared by all devices, multiple communications can occur at the same time without collisions
- heterogeneous links:
- because a switch isolates one link from another, different links can use different speeds and transmission media
- allowing older and newer devices to coexist on the same LAN
- simplified management:
- switches can detect and isolate malfunctioning devices, such as a jabbering adapter that continuously transmits Ethernet frames
- switches can collect traffic statistics (such as bandwidth usage and traffic types) to help monitor and troubleshoot the network
Switch poisoning
A switch normally forwards frames only to the port where the destination MAC address is known.
However, switches still flood certain types of traffic, including:
- broadcast frames (destination MAC address
FF–FF–FF–FF–FF–FF) - unknown unicast frames (frames whose destination MAC address is not in the switch's table)
MAC flooding (also called CAM table overflow) is an attack that tries to overload the switch's MAC address table.
The attacker:
- sends a large number of frames
- each with a different fake source MAC address
- causing the switch's MAC table to fill up with fake entries
When the MAC table is full:
- the switch may be unable to learn new legitimate MAC addresses
- as a result, it may start flooding more unknown unicast frames instead of forwarding them only to the correct destination port
This increased flooding makes it easier for an attacker to observe traffic that would normally be isolated.
Although MAC flooding is possible, it is difficult to carry out successfully against modern network equipment. Many switches implement protections such as:
- port security (limiting the number of MAC addresses per port)
- MAC address limits per interface
- storm control and rate limiting
As a result, switched LANs are generally much more resistant to sniffing attacks than hub-based Ethernet networks or wireless LANs.