A MAC address table is the list a switch keeps of which MAC address it last saw on which port. It is built automatically from source addresses. A destination that is in the table is forwarded out one port; a destination that is not is flooded to every port in the VLAN.
- Built from the source address of every frame, never the destination
- An unknown destination is flooded, then learned from the reply
- Entries age out after about five minutes of silence
- One address on a port is a device. Many is an uplink
- Filling the table is the overflow attack, and port security ends it
On this page
The three rulesThe three rules: learning, forwarding and flooding
A switch does three things with every frame it receives, and there are no others.
Learning. Read the source MAC address, and record it in the CAM table against the port the frame came in on and the VLAN that port belongs to. If the address is already in the table on that port, reset its timer. If it is in the table on a different port, move it, because the device evidently moved.
Forwarding. Look up the destination MAC address in the table. If it is there, send the frame out that port and no other. This forwarding decision is what makes a switch a switch rather than a hub.
Flooding. If the destination is not in the MAC address table, send the frame out every port in that VLAN except the one it arrived on. The real destination replies, that reply teaches the switch where it is, and every subsequent frame is forwarded rather than flooded.
Two consequences follow that people find counterintuitive.
A switch never learns from a destination address. MAC learning happens from source addresses only. So devices that receive frames and never send any are invisible to the switch, which is why silent devices get flooded to repeatedly.
Flooding is normal, not a fault. Every conversation with a new destination starts with one flooded frame. A network with constant flooding has a problem; a network with occasional flooding is working.
AgingMAC address aging, and why entries disappear
An entry sits in the MAC address table for as long as the switch keeps hearing from that address, and aging removes it after a period of silence. Five minutes is the usual default aging time.
The aging timer exists because devices move and switches would otherwise fill up with MAC addresses that left months ago. It also produces two behaviors worth recognizing.
A quiet device gets flooded to. A printer that speaks once an hour has aged out of the CAM table between jobs, so the first frame to it each time is flooded to every port in the VLAN. Harmless, and it looks alarming in a capture.
The ARP timer and the MAC timer disagree. A host's ARP cache commonly holds an entry for a shorter period than a switch holds its MAC entry, or the reverse depending on the platform.
When the ARP entry lives longer than the MAC address table entry, the host keeps sending frames to an address the switch has forgotten, and the switch floods every one of them. This is the usual cause of steady low level flooding in an otherwise healthy network, and the fix is aligning the two timers rather than chasing a fault.
Finding a deviceFinding which port a device is on
This is the everyday use of the table, and it is the fastest way to locate a machine in a building.
Start from the IP address if that is all you have. Ping it, then read the ARP table on the router or on your own machine to get the MAC address. The ping matters: it forces the device to reply, which populates both tables.
ping 10.0.5.20
arp -a | findstr 10.0.5.20 Windows
ip neigh | grep 10.0.5.20 Linux
Then look the MAC up on the switch.
show mac address-table address 00c0.1234.5678
show mac address-table | include 00c0
Follow it hop by hop. If the port it names is an uplink to another switch, the device is not there, it is somewhere beyond it. Log into that switch and repeat. You walk the path until the port is an access port with one address on it, and that is the port.
A port with many addresses is an uplink. A port with exactly one is where something is plugged in. That distinction is the whole technique, and it works on any vendor.
A switch that runs LLDP has already done the walk. Following uplinks by hand works and it is slow. LLDP has each switch announce itself to its neighbors, so one command names the switch and the port on the far end of every uplink, and the hop by hop search only has to cover the last one.
| What the table shows for a port | What it means |
|---|---|
| One address | An access port with one device on it |
| A handful of addresses | A device with a virtual switch behind it, or a small unmanaged switch |
| Many addresses | An uplink to another switch. Follow it |
| Nothing | Nothing has transmitted there recently |
The attackThe CAM table overflow attack, and what stops it
The CAM table has a fixed size, and the attack that follows from that is old, easy and still worth understanding.
An attacker on the network sends a flood of frames with randomly generated source MAC addresses. The switch learns each one dutifully, and once the CAM table is full it has no room for legitimate entries.
A switch that cannot look up a destination floods it, so the attacker now receives traffic intended for other machines simply by being on a port. The tool that does this has existed for decades and takes one command.
Two things stop it, and one of them is the answer.
Port security is the control. It limits how many MAC addresses a switch port may learn dynamically, and what happens when that limit is exceeded: the port can be shut down, or it can discard frames from further addresses.
A limit of one or two on an access port ends the attack outright, because the attack needs the port to accept thousands.
Dynamic ARP inspection and DHCP snooping help nearby. They address adjacent attacks rather than this one, and they are usually configured together, so a switch hardened for one is hardened for all three.
The reason to bother is that the attack turns a switched network back into a hub, and everything anybody assumed about traffic not being visible stops being true.
PitfallsWhere people go wrong
Expecting to find a device that has not transmitted. The table learns from sources only. Ping the device first, which makes it speak, then look.
Reading an uplink port as the answer. A port with forty addresses is a path to another switch, not forty devices in one socket. Follow it rather than reporting it.
Treating any flooding as a fault. Every new conversation starts with one flooded frame. It is continuous flooding that is worth investigating.
Ignoring mismatched ARP and MAC timers. When the ARP entry outlives the MAC entry, the host keeps sending to something the switch forgot, and every frame is flooded. It looks like a mystery and it is a timer.
Leaving port security off on access ports. It is the control that ends the overflow attack, and the limit that stops it is one or two addresses per port.
Setting port security to shut down on a desk port. Somebody plugs in a personal switch, the port disables itself, and now it is a ticket. Restricting is usually the better action on user ports and shutting down is right on ports that should never move.
Assuming the table is per switch rather than per VLAN. MAC address table entries are held per VLAN, so the same address can legitimately appear twice on a switch carrying more than one.
ComparisonTwo tables that get confused, and what each one answers
| Criterion | MAC address table | ARP cache |
|---|---|---|
| Lives on | A switch | A host or router |
| Maps | A MAC to a port | An IP to a MAC |
| Layer | 2 | Between 2 and 3 |
| Built from | Source addresses seen | Requests and replies |
| Typical lifetime | Commonly 300 seconds | Seconds to minutes |
| Miss behavior | Flood to every port | Broadcast a request |
| Used to find | Which port a device is on | Which MAC an address has |
The two are used together and constantly confused. Finding a device starts in the ARP cache, which turns an IP address into a MAC address, and finishes in the MAC address table, which turns that MAC address into a port.
FAQFrequently asked questions
What is a MAC address table?
The list a switch keeps of which MAC address it last saw on which port, within which VLAN. It is what lets a switch send a frame out one port instead of all of them.
Is a CAM table the same thing?
Yes. CAM refers to the content addressable memory the MAC address table lives in, and the two names are used interchangeably.
How does a switch build the MAC address table?
MAC learning is automatic, from the source address of every frame it receives. Nobody configures it, and the switch never learns from a destination address.
What happens when the destination is not in the table?
The switch floods the frame out every port in that VLAN except the one it arrived on. The reply teaches it where the destination is, and subsequent frames are forwarded normally.
How long do MAC address table entries last?
Commonly five minutes of silence, and the aging timer resets each time the address is seen. Devices that transmit rarely age out between transmissions.
Why does my network flood traffic constantly?
Usually because the ARP cache on a host holds an entry longer than the switch holds its MAC entry, so the host keeps sending to an address the switch has forgotten. Aligning the timers fixes it.
How do I find which switch port a device is on?
Ping it so that it transmits, read its MAC address from the ARP table, then look that address up on the switch. If the port is an uplink, repeat on the next switch along.
How do I tell an uplink from an access port in the table?
By how many addresses it shows. One address is a device, many addresses is a path to another switch.
What is a CAM table overflow attack?
Flooding the switch with random source addresses until the table is full, so legitimate lookups fail and the switch floods traffic the attacker can then see.
How do I prevent it?
Port security, limiting how many addresses a port may learn. A limit of one or two on an access port removes the attack, because it depends on the port accepting thousands.
Should port security shut the port down?
On ports that should never change, yes. On desk ports, restricting is usually better, because a shutdown turns somebody plugging in a small switch into a support call.
Is the table shared across VLANs?
No. Entries are held per VLAN, so one address can appear more than once on a switch carrying several.
What is the command to see it?
show mac address-table on most switches, with address or interface to narrow it. The exact syntax varies by vendor and the concept does not.
What is unknown unicast flooding?
When a switch receives a frame for a MAC address that is not in its table, it sends the frame out of every port in the VLAN except the one it arrived on.
That is unknown unicast flooding. It is normal in small amounts, and heavy flooding points to a table that is too small, aging out too fast, or under attack.
What does MAC address stand for, and what is the MAC address meaning?
MAC stands for media access control. The MAC address meaning is a hardware identifier for a network interface, used to deliver frames on the local network. It is sometimes called the physical address or the burned in address, although most operating systems let you change it.
What is the MAC address format?
The MAC address format is 48 bits, written as six pairs of hexadecimal digits separated by colons or hyphens, such as 00:1A:2B:3C:4D:5E. The first three pairs are the manufacturer's identifier, assigned by the IEEE, and the last three identify the individual interface.
Keep readingRelated concepts
Read next · Switching Spanning Tree Protocol A loop makes the same address appear on two ports in turn, and the table flapping between them is the symptom. Open this next11 min- Switching · 14 min What Is a VLAN? Entries are held per VLAN, which is why the same address can appear twice on one switch.
- Fundamentals · 13 min ARP Explained, and the One Thing Everyone Gets Wrong About It Finding a device starts here, because the ARP cache is what turns an IP address into the MAC address you then look up.
- Fundamentals · 10 min What a Network Hub Is, and Why the Switch Replaced It What a network hub is, why it floods every port, and why switches replaced it.
- Fundamentals · 11 min What a Node Is, and Why the Word Changes Meaning How a forwarding node decides.
- Protocols · 10 min What LLDP Is, and Why It Answers the Port Question What this replaces.
- Design · 12 min Star Topology, and Why the Building Decided It How the central hub decides where data goes.
- Network fundamentals · 9 min Wake on LAN, and How the Magic Packet Powers a Machine On Why wake on lan targets the MAC and not the IP address.
- Network fundamentals · 9 min Ethernet Frame Format, Field by Field Where the two addresses at the front of the frame are learned and looked up.
- Switching · 9 min EtherChannel, Bundling Several Links Into One The switching that an EtherChannel bundles uplinks for.