Ethernet frames, MAC addresses, and frame switching

Ethernet II frame

Bits on an Ethernet LAN are organized into frames: header + data + trailer. Several frame types exist; Ethernet II is the most common and is what usually carries IP packets.

The fields, in order:

The switch reads these headers (specifically the destination MAC) to make forwarding decisions.

MTU and jumbo frames

Max payload is the MTU, 1500 bytes. With Ethernet overhead (preamble excluded), the max frame is 1518 bytes, and anything bigger is a jumbo frame, used in some environments.

Tunneling shrinks MTU. Tunnel protocol info has to fit inside the payload, and since the payload can’t grow, the MTU drops: GRE adds 24 bytes of overhead (4 GRE + 20 for the extra IP header), so a GRE tunnel’s MTU automatically becomes 1476.

Verify with show ip interface <name>: a physical interface shows MTU 1500, a tunnel interface shows 1476.

MAC addresses

12 hex digits, 48 bits: each hex digit is 4 bits, since counting to 15 takes 4 bits in binary. Hex is base 16, symbols 0-9 plus A-F where A-F is 10-15, and upper or lowercase are both fine.

Formatting varies by OS. The same address three ways: 0000.0c43.2e08 (Cisco IOS), 00:00:0c:43:2e:08 (Linux), 00-00-0C-43-2E-08 (Windows). Copying between systems means reformatting.

Two special bits in the first octet

Meaningful only in the destination address field:

Unicast, broadcast, multicast

These exist at L2 (MAC) and also at L3 (IP):

Frame switching and the MAC address table

The MAC table maps MAC addresses to switch ports, plus the VLAN.

Switches learn on ingress: when a frame enters a port, the switch records the frame’s source MAC against that port. They forward based on the destination MAC: look it up in the table, send out the mapped port.

Example flow: PC A (port 1) ARPs for PC B. The ARP is a broadcast, so it floods the VLAN. PC B (port 3) replies; when that reply ingresses port 3, the switch learns B’s MAC there. From then on, traffic between A and B is forwarded directly, no flooding.