The physical layer moves bits, but it does not know for whom. The data link layer fills precisely that gap: it packages bits into frames, gives every interface a name unique in the world, settles who is allowed to speak on a shared medium and - through the switch - builds the map of the local network by itself, without anyone telling it anything.
1Recap5 min
- Layer 1, the physical layer, turns bits into a signal: voltages, light or radio waves.
- The medium may be guided (copper, fibre) or unguided (radio). A shared medium means several parties speak over the same support.
- Each layer adds its own header - a process called encapsulation.
- This lecture climbs to layer 2: MAC addresses, frames, switching.
Learning outcomes
- Explain the role of layer 2 and its division into the LLC and MAC sublayers
- Read an Ethernet frame field by field and say what each is for
- Recognise a unicast, multicast or broadcast MAC address
- Explain CSMA/CD and say why it has disappeared from modern networks
- Correctly count the collision and broadcast domains in a topology
- Describe the three actions of a switch: learning, forwarding, flooding
- Compare store-and-forward and cut-through switching
2What the physical layer lacks7 min
The physical layer manages a stream of bits. That is all. It has three important shortcomings, and layer 2 exists precisely to make up for them:
| The physical layer cannot... | The data link layer... |
|---|---|
| identify the hosts on the medium | identifies them by addressing |
| say where a message begins and ends | organises the stream into frames |
| communicate directly with software | offers a well-defined service to layer 3 |
Imagine receiving an endless string of letters, with no spaces and no punctuation. To make sense of it, you have to know where one word ends and another begins.
A frame does exactly this for bits: it groups them into a package with a clear beginning, a clear end, the address of the recipient and a checksum that says whether it arrived intact.
3The two sublayers: LLC and MAC7 min
Layer 2 sits exactly at the boundary between hardware and software, so it was divided into two sublayers, each looking in a different direction.
| Sublayer | Who it talks to | What it does | Standard |
|---|---|---|---|
| LLC | software (layer 3) | multiplexes the upper-layer protocols, provides flow control; the medium is of no concern to it | IEEE 802.2 |
| MAC | the medium (layer 1) | builds the frame, decides who transmits and when; depends entirely on the technology | 802.3, 802.11, FDDI |
This is exactly the separation that lets a laptop move from cable to Wi-Fi without any open application noticing.
4Encapsulation at layer 27 min
For data to reach the right recipient, extra information is needed, and it is added by layer 2 and organised into frames. Most layer 2 protocols - not Ethernet alone - use the same set of fields:
| Field | What it is for |
|---|---|
| Start of frame | a bit sequence announcing the beginning; without it the receiver would not know where to start counting |
| Addresses | the MAC addresses of the source and the destination |
| Type / length | which layer 3 protocol is encapsulated, or the length of the data |
| Data | the message itself, that is, everything layer 3 built |
| CRC / FCS | a checksum that allows transmission errors to be detected |
Other layer 2 protocols you will meet in WANs: PPP, Frame Relay, ATM, and historically Token Ring. All of them solve the same problems, with different trade-offs.
5The Ethernet frame, field by field12 min
The structure of the frame is almost identical for every Ethernet implementation, from 10 Mbps to 100 Gbps. This is a remarkable feat of engineering: the speed has grown ten thousandfold and the format has stayed.
A Cyclic Redundancy Check is a kind of "fingerprint" of the message: the transmitter computes it through a mathematical operation over all the bits and attaches it at the end. The receiver recomputes the same fingerprint and compares.
If the values differ, something was damaged along the way. The CRC does not say what was damaged and cannot repair it - it only raises its hand. This is a deliberate choice: detection is cheap, correction would be expensive, and at the error rate of a modern cable it is more efficient to retransmit the whole frame.
You will meet the MTU again in tunnelling (lecture 9), where the extra header shrinks the space available, and in OSPF (lecture 10), where a mismatched MTU between two routers blocks the adjacency in a state you would otherwise be unable to explain.
6The MAC address10 min
Ethernet identifies each interface by a 48-bit address, written in hexadecimal. It is written into the ROM of the network card at the factory.
The IEEE sells 24-bit blocks (OUI - Organizationally Unique Identifier) to equipment manufacturers. Each manufacturer receives a prefix of its own and fills in the rest as it pleases, so long as it does not repeat itself.
The result: 248 ≈ 281 million million possible addresses, divided up administratively, with no authority checking each individual card. The system works because every manufacturer has an interest in not producing two identical cards.
A practical observation: from the first three bytes of a MAC address you can determine the manufacturer. There are public databases for this, and in troubleshooting it is surprisingly useful.
The MAC address has two essential properties, both with direct consequences for what follows in the course:
- It is flat - it contains no hierarchy whatever. From the address
00:FC:42:3E:34:99absolutely nothing can be deduced about where that card is. - It has local scope - it is visible and usable only inside the broadcast domain. Beyond the first router, nobody sees it any more.
It is precisely these two properties that make layer 3 necessary, the subject of lecture 5.
The three types of address
| Type | How to recognise it | Example | Who accepts it |
|---|---|---|---|
| Unicast | first byte even (least significant bit = 0) | 00:10:A7:22:FE:63 | a single interface |
| Multicast | first byte odd (least significant bit = 1) | 01:00:5E:00:A1:11 | the hosts subscribed to that group |
| Broadcast | all 48 bits set to 1 | FF:FF:FF:FF:FF:FF | every host in the domain |
Which of the following addresses are multicast? 02:00:00:00:00:01,
01:80:C2:00:00:00, 33:33:00:00:00:01, FF:FF:FF:FF:FF:FF
See the answer
02 = 00000010 - the last bit is 0, so unicast. (The next bit, set to 1,
means "locally administered", that is, set by software rather than at the factory.)
01 = 00000001 - the last bit is 1, so multicast. This particular address,
01:80:C2:00:00:00, is the one Spanning Tree messages travel on, in lecture 4.
33 = 00110011 - the last bit is 1, so multicast. The prefix
33:33 is reserved for IPv6 multicast.
FF:FF:FF:FF:FF:FF is broadcast - technically a special case of multicast, in
which the group is "everybody".
7The characteristic times of an Ethernet network7 min
Three time quantities explain nearly all the "odd" values in the Ethernet standard.
| Quantity | Definition | 10 Mbps | 100 Mbps | 1 Gbps |
|---|---|---|---|---|
| Bit time | the duration of a single bit on the wire | 100 ns | 10 ns | 1 ns |
| Slot time | the time the signal needs to cross the longest segment and return | 512 bit times = 64 bytes | 4096 bit times = 512 bytes | |
| Interframe gap | the mandatory minimum pause between two successive frames | 96 bit times | ||
On a shared medium, a host must still be transmitting at the moment a possible collision gets back to it. If it finished earlier, it would carry on quite happily, convinced all had gone well - and nobody would retransmit the lost frame.
The minimum frame is exactly long enough to last one slot time. Shorter frames, the debris of collisions, are called runt frames and are discarded.
The interframe gap has a different role: it gives slow hosts time to process the current frame and prepare for the next. At 1 Gbps it means 96 nanoseconds - an eternity for the electronics, nothing at all for the traffic.
8The shared medium and CSMA/CD12 min
Ethernet was designed for a multiple-access medium: a single coaxial cable to which every host was attached. In such a medium two hosts may begin transmitting at exactly the same moment, and their signals overlap. The result is called a collision, and the frames involved become unusable.
The mechanism nevertheless remains essential to understand, for three reasons: it explains the minimum frame size, it explains the maximum segment distances, and - above all - it is the idea Wi-Fi had to reinvent, in the form of the CSMA/CA of lecture 11, because in the air collisions cannot be detected.
9Collision and broadcast domains9 min
The broadcast domain is the group of hosts that receive a broadcast frame sent by any one of them. The larger it is, the more useless traffic every host has to process.
| Device | Collision domain | Broadcast domain |
|---|---|---|
| Hub / repeater | extends it | extends it |
| Switch / bridge | bounds it - one per port | extends it |
| Router | bounds it | bounds it - one per interface |
Collision domains: start from each cable. A cable leading to a switch or router port has a domain of its own. A hub, by contrast, joins all the cables connected to it into a single domain.
Broadcast domains: the same reasoning, except that this time switches join as well - only routers separate. In practice: count how many "islands" remain if you cut the network at every router interface.
A router has two interfaces. On the first there is a switch with 4 hosts; on the second, a hub with 3 hosts. How many collision domains and how many broadcast domains are there?
See the solution
Collision domains: 6. The switch creates one for each of the 4 links to hosts, plus one for the link to the router - so 5. The hub, together with its 3 hosts and the link to the router, forms a single domain. Total 5 + 1 = 6.
Broadcast domains: 2. One for each router interface. All 4 hosts on the switch hear one another's broadcasts; all 3 on the hub likewise; but the two groups do not hear each other.
The classic trap: the switch–router link is a collision domain in its own right, easily forgotten. And the hub–router link is not a separate domain - it is part of the hub's domain.
10How a switch works13 min
Here is the most elegant part of the whole lecture. Nobody configures a switch with the map of the network: it builds it itself, from a single clever observation.
No configuration is needed, no discovery protocol, no central authority. The information is already there, in every frame that passes - it need only be read and remembered.
The associations are kept in the CAM table (Content Addressable Memory), also called the MAC address table. For every frame received, the switch always performs the same two steps, in this order:
- Learning. It reads the source MAC. If it is not in the table, it adds the pair (source MAC, ingress port). If it is already there, it resets its age counter.
- Forwarding. It reads the destination MAC and looks it up in the table. Three
outcomes are possible:
- found, on a different port → unicast: send the frame out of that port alone;
- found, on the ingress port itself → drop: the destination is on the same side, so resending would be pointless;
- not found, or a broadcast/multicast address → flood: send it out of every port except the one it came in on.
- Clear the table. Send a frame from A to C. Observe: the switch learns A, but does not know where C is, so it floods.
- Now send from C to A. The switch learns C as well, and it already knows A, so unicast.
- Send from A to C again. This time it is unicast straight away.
What you have seen: the network teaches itself after the first exchange, and the useless traffic disappears of its own accord. No administrator intervened.
Ageing of entries
Each entry in the table has an age associated with it, reset by every frame received from that address. When the age exceeds a threshold - 300 seconds by default on Cisco equipment - the entry is deleted.
Why must entries be deleted? What would happen if the table were permanent?
See the answer
If you move a computer from port 3 to port 7, the switch would go on sending traffic for it out of port 3 - for ever, although there is nobody there any more.
In practice the problem resolves itself much sooner: the first frame the computer sends from its new port corrects the entry immediately. Ageing covers the case where the host has left and no longer speaks at all - otherwise the table would fill up, over time, with ghosts.
There is also a security reason: a full table makes the switch flood all traffic, which is exactly the aim of the CAM overflow attack in lecture 12.
11Switching methods6 min
How long does a switch wait before making its decision? There are three answers, with three different trade-offs.
| Method | What it waits for before forwarding | Latency | Corrupt frames |
|---|---|---|---|
| Store-and-forward | the whole frame; it checks the length and the FCS | high, grows with frame size | stopped |
| Fragment-free | the first 64 bytes | medium, fixed | runt frames stopped, the rest pass |
| Fast-forward (cut-through) | only the destination address - the first 6 bytes after the preamble | minimal, fixed | all pass |
The trade-off is plain: the more the switch reads before deciding, the better it filters, but the longer it delays.
Cut-through survives in data centres and in financial trading, where microseconds genuinely matter.
12The Ethernet family, in brief5 min
Ethernet appeared in 1973 at Xerox PARC, built by Bob Metcalfe and David Boggs, with a bandwidth of 2.94 Mbps. The name comes from "ether" - the hypothetical substance through which light was once believed to propagate. In 1983 the IEEE turned the industrial DIX standard (DEC–Intel–Xerox) into the 802.3 standard, which holds to this day.
| Generation | Year | Standard | Speed | Coding | CSMA/CD |
|---|---|---|---|---|---|
| Fast Ethernet | 1995 | 100BASE-TX / FX | 100 Mbps | 4B/5B + MLT-3 or NRZ-I | yes (half-duplex) |
| Gigabit Ethernet | 1998–1999 | 1000BASE-T / SX / LX | 1 Gbps | PAM-5 or 8B/10B | optional |
| 10 Gigabit | 2002 | 10GBASE-T / SR / LR | 10 Gbps | various | no - full-duplex only |
| 40 / 100 Gigabit | 2010 | 802.3ba | 40 / 100 Gbps | multiple, over several lanes | no |
The frame format has stayed the same. A frame captured today on a 100 Gbps link has exactly the same fields as one from 1983. This is the best lesson in design this course offers: a well-conceived interface outlives its implementations.
13Common mistakes4 min
- "The switch learns from the destination MAC address" It does not. It learns exclusively from the source address - the only one that says for certain where the frame came from. The destination is used only to decide where to send it. Remember the order: first learn from the source, then look up the destination.
- "A broadcast frame is also sent back out of the ingress port" Never. Flooding means "out of every port except the one it came in on". Otherwise an instant loop would be created, even with no redundant cables.
- "The 64-byte minimum size is an arbitrary convention" It comes straight from the slot time: the host must still be transmitting when the collision gets back to it. 64 bytes = 512 bit times = the slot time at 10 and 100 Mbps.
- "A 24-port switch has 24 broadcast domains" It has 24 collision domains and a single broadcast domain. A switch separates collision, but extends broadcast. Separating broadcast takes a router - or VLANs, in lecture 4.
- "The FCS corrects errors" It only detects them. A frame with a bad FCS is discarded, and retransmission is the business of the upper layers. Detection at layer 2, recovery at layer 4.
14Summary and glossary5 min
- Layer 2 adds what the physical layer lacked: identity (MAC addresses), delimitation (frames) and error detection (the FCS).
- The MAC address is flat and local - two limitations that make layer 3 necessary.
- CSMA/CD solved the problem of the shared medium; full-duplex switching made it unnecessary.
- A switch builds the map of the network by itself, from the source MAC addresses of the frames that pass through it.
- A switch separates collision domains and extends broadcast ones - and the whole of the next lecture starts from there.
15Self-check questions6 min
16Further reading and bibliography2 min
A switch solves collisions but leaves a single broadcast domain however large the network grows - and it does not tolerate loops. The next lecture attacks both problems: VLANs for segmentation and Spanning Tree for redundancy without loops.
In laboratory 2 you will clear a real CAM table, fill it while watching it frame by frame, and compare, on the same topology, a switch with a hub.
- IEEE 802.3 - the frame format and the CSMA/CD mechanism
- IEEE 802.1D - the operation of a transparent bridge
- The public IEEE OUI registry, for identifying the manufacturer from a MAC address
- Andrew S. Tanenbaum, Computer Networks, chapter 4 - the medium access sublayer
- Charles Spurgeon, Ethernet: The Definitive Guide