Local Area Networks / Laboratory
LABORATORY 02

LAN switching: the MAC table, ARP, domains

Duration: 2 hours Platform: the workbench in this page, or Packet Tracer Background: laboratory 1, lecture 3 PDF: download the notes RO versiunea română

A switch receives a new device and, within a few milliseconds, knows where it is - without anybody having told it anything. This exercise takes the mechanism apart, step by step: you empty the MAC table, fill it while watching, compare the switch with a hub on the same topology, and see literally what a collision domain means.

1What we take apart today

In laboratory 1 you issued a ping and it worked. Nobody explained why the switch knew where to send the frame. Today you find out, and the answer has only three rules.

The ruleWhat the switch does
it learnsFor every frame that comes in, it notes the source MAC address and the port it came in on. Nobody tells it anything: it works it out by itself.
it looks upIt looks at the destination MAC address. If it finds it in the table, it sends the frame only out of that port (unicast).
it floodsIf it does not find it - or if the destination is broadcast - it sends the frame out of every port except the one it came in on (flood).

There is a fourth, rarer situation: if the destination is on the very port of arrival, the switch discards the frame (drop) - the two hosts hear each other directly anyway.

collision domain
The portion of the network in which two hosts cannot transmit at the same time without garbling each other. Every switch port creates a separate one. A hub merges them all into a single one - and from this comes the whole difference in performance between the two.
broadcast domain
The portion of the network reached by a message sent "to everyone". It stops at a router (or at the boundary of a VLAN, from laboratory 3). Neither the switch nor the hub stops it.
ARP
The protocol that translates an IP address into a MAC address. A host knows whom it wants to talk to (192.168.5.11), but it needs the number of the network card in order to compose the frame. It asks in broadcast, receives a unicast answer and remembers that answer for a few minutes.

2Equipment needed

QtyEquipmentModelPacket Tracer categoryWhat it is for here
1Switch2960Network Devices → Switchesthe "intelligent" part of the topology
1HubHub-PTNetwork Devices → Hubsthe term of comparison
6ComputerPC-PTEnd Devices → End DevicesPC-A … PC-F
7Copper cableCopper Straight-ThroughConnections → Connectionsevery link

Optionally, for the last assignment: one more 2960 switch and a Copper Cross-Over cable.

What can be done in the workbench in this page and what requires Packet Tracer The workbench in this page covers: the MAC table and emptying it, the behaviour of the hub, ARP, the management address on VLAN 1, port security with a violation provoked by moving a cable.
Packet Tracer is required for: Simulation mode with envelopes followed step by step, measuring times under simultaneous traffic, an actual SSH session, and the real ageing of entries over time.

3The topology to build

PC-A.10 PC-B.11 PC-C.12 SW12960 · VLAN1 .2 HUB1Hub-PT PC-D.13 PC-E.14 PC-F.15 Fa0/1 Fa0/2 Fa0/3 Fa0/4 3 domains one single collision domain the whole network: 192.168.5.0/24
Fig. 1 - The same network, two philosophies of interconnection. On the left, every host has its own collision domain. On the right, all three share one.
DeviceIP addressMaskPort on SW1 / HUB1
PC-A192.168.5.10255.255.255.0SW1 Fa0/1
PC-B192.168.5.11255.255.255.0SW1 Fa0/2
PC-C192.168.5.12255.255.255.0SW1 Fa0/3
PC-D, PC-E, PC-F192.168.5.13 – .15255.255.255.0HUB1
SW1192.168.5.2 (VLAN 1)255.255.255.0-

There is no router and no gateway is needed: every host is in the same network. The SW1 Fa0/4 – HUB1 link is made with straight-through cable.

4The workbench

The topology of figure 1, cabled and addressed. Every section that follows can be done here; open it in a tab beside the text and work as you read.

5The MAC table, watched as it fills

  1. Note the MAC addresses of the hosts

    For every host, open the terminal (in Packet Tracer: Desktop → Command Prompt) and run:

    on every host
    ipconfig /all
    

    Note the Physical Address field - it is the MAC address. You will need these six values at every step that follows; without them, the table of the switch is a meaningless string of digits.

  2. Empty the table and check that it is empty
    on SW1
    Switch> enable
    Switch# clear mac address-table dynamic
    Switch# show mac address-table
    

    No entry must appear. If some still do, it means traffic has passed in the meantime - repeat the two commands one straight after the other.

  3. A single frame, and look at what has happened

    From PC-A, issue a single ping towards PC-B, then come straight back to SW1:

    on PC-A
    ping -n 1 192.168.5.11
    
    on SW1
    SW1# show mac address-table
    
    Question

    How many entries appeared, and where did the switch learn each of them from?

    See the answer

    Two: the MAC of PC-A on Fa0/1 and the MAC of PC-B on Fa0/2. The first was learned from the ARP request of PC-A - a broadcast, therefore flooded out of every port. The second, from the ARP reply of PC-B. The ping itself had nothing left to teach: by the time it left, the switch already knew everything.

    The conclusion that matters: the switch does not learn from ping. It learns from any frame that passes through it, whatever it contains.

  4. The three actions, one at a time

    Empty the table again and run the scenarios in the order below. In Packet Tracer switch to Simulation and filter on ICMP and ARP, so that you see the envelopes. In the workbench in this page, watch the MAC table after each step.

    ScenarioWhat the switch doesHow you check
    PC-A → PC-B, with the table emptyflood: the frame leaves out of every port except Fa0/1the table was empty, so the destination was unknown
    PC-B → PC-A, straight afterwardsunicast: only out of Fa0/1show mac address-table already contains PC-A
    PC-A → broadcastflood, alwaysin Packet Tracer: ping 192.168.5.255
  5. The ageing of entries
    on SW1
    SW1# show mac address-table aging-time
    SW1# configure terminal
    SW1(config)# mac address-table aging-time 30
    SW1(config)# end
    

    The default value is 300 seconds. Reduce it to 30, generate traffic from PC-C, then leave the network quiet and watch the table every 15 seconds: the entry disappears. (The passage of time can only be observed in Packet Tracer; in the workbench in this page the command is accepted, but the table does not age by itself.)

    Why ageing is needed If you move PC-C from Fa0/3 to Fa0/5, the switch would carry on sending its traffic out of the old port - indefinitely. In practice, the first frame sent by PC-C from the new port corrects the entry at once; ageing covers the case where the host has left and no longer speaks at all.

    Check this right now, in the workbench: pick PC-C, in the Cables panel press unplug, then connect towards SW1 : Fa0/5. Issue a ping from PC-C and look again at show mac address-table: the entry has moved to the new port by itself.

6Switch versus hub

The right-hand part of the topology exists for one reason only: so that you see the difference instead of imagining it.

  1. Traffic through the hub

    From PC-D issue a ping towards PC-E. In Packet Tracer, in Simulation, follow the envelope.

    The hub sends it out of every port - including to PC-F, which has nothing to do with this conversation, and back towards the switch. PC-F receives the frame, looks at the destination MAC address, finds that it is not its own and discards it. Time and bandwidth spent for nothing, on every single frame.

    In the workbench in this page, check the consequence on the switch: after a ping between two hosts attached to the hub, show mac address-table on SW1 shows both addresses on the same port, Fa0/4. The switch has no way of separating them: from its point of view, everything beyond the hub sits on a single wire.

  2. The collision, provoked Packet Tracer only

    Go back to Realtime. Open the terminals on PC-D and PC-F at the same time and launch from both, as close together in time as you can:

    on PC-D and PC-F, almost simultaneously
    ping -n 200 -l 1400 192.168.5.10
    

    Compare the response times with those obtained when you run alone. Repeat the experiment replacing the hub with a second switch and observe the difference.

  3. Count the domains
    Exercise

    For the topology of figure 1, how many collision domains and how many broadcast domains are there?

    See the answer

    Collision domains: 5. SW1 creates one on each port: Fa0/1, Fa0/2, Fa0/3 and Fa0/4 - that is 4. The hub, together with PC-D, PC-E, PC-F and the link towards the switch, forms a single domain - the fifth. Careful: the SW1–HUB1 link belongs to the domain of the hub, not to a separate one.

    Broadcast domains: 1. There is no router and no VLAN, so all six hosts hear each other in broadcast. A ping 192.168.5.255 from PC-A reaches everybody.

7ARP, with the cache emptied

  1. Clear the cache and look at the request
    on PC-A
    arp -d
    arp -a
    ping -n 1 192.168.5.12
    arp -a
    

    The first display must say No ARP Entries Found. After the ping, the address of PC-C appears together with its MAC. This is the whole mechanism: a question, an answer, a note remembered for a few minutes.

    In Packet Tracer, follow the ARP request in Simulation and read from Outbound PDU Details:

    • the destination MAC address of the frame: FFFF.FFFF.FFFF - broadcast;
    • the Target MAC field of the ARP packet: zeros - exactly what is being asked for;
    • the Target IP field: the address of PC-C.

    Every host receives the request. Only PC-C answers; the others ignore it silently.

  2. The effect of the cache

    Issue ping 192.168.5.12 straight after arp -d and then once more. The first time the first packet is lost; the second time, none is. The difference is exactly the cost of ARP resolution.

    Remember the symptom In a network with problems, pings that "work, but fail the first time" almost always point to a matter of ARP, not of routing. It is the first thing you strike off the list.

8Managing the switch

So far we have configured the switch sitting at its console. In order to manage it remotely, it needs an IP address and a means of access protected by a password.

The commands below are typed line by line. Those beginning with ! are comments - they are not typed.

the management configuration of SW1
Switch> enable
Switch# configure terminal
Switch(config)# hostname SW1
SW1(config)# no ip domain-lookup

! the management address sits on the VLAN 1 virtual interface
SW1(config)# interface vlan 1
SW1(config-if)# ip address 192.168.5.2 255.255.255.0
SW1(config-if)# no shutdown
SW1(config-if)# exit

! the password for privileged mode
SW1(config)# enable secret Cisco123
SW1(config)# service password-encryption

SW1(config)# end
SW1# copy running-config startup-config

Check from two places:

on SW1
SW1# show ip interface brief

Vlan1 must appear with 192.168.5.2 and up / up. If it appears as administratively down, you forgot no shutdown on the VLAN interface.

on PC-A
ping 192.168.5.2

Remote access

For a true SSH session, a domain name, a key and a user are also needed. These commands are demonstrated in Packet Tracer:

on SW1, in Packet Tracer
SW1(config)# ip domain-name retele.local
SW1(config)# crypto key generate rsa
! when asked about the key length, answer 1024
SW1(config)# username admin privilege 15 secret Admin123
SW1(config)# line vty 0 4
SW1(config-line)# transport input ssh
SW1(config-line)# login local
SW1(config-line)# exit
SW1(config)# banner motd #Authorized access only#
on PC-A
ssh -l admin 192.168.5.2
The address on VLAN 1 does not make the switch a router It is merely a point of contact for administration. The switch carries on switching on the basis of MAC addresses and will route nothing between networks. If it must be managed from another network, it additionally needs ip default-gateway.

9Port security

A switch port accepts, by default, any MAC address presented to it. Port security limits the number of addresses that may be learned on a port and decides what happens when the limit is exceeded - the first defence against the CAM overflow attack from lecture 12.

on the port of PC-A
SW1# configure terminal
SW1(config)# interface fastEthernet 0/1
SW1(config-if)# switchport mode access
SW1(config-if)# switchport port-security
SW1(config-if)# switchport port-security maximum 1
SW1(config-if)# switchport port-security mac-address sticky
SW1(config-if)# switchport port-security violation shutdown
SW1(config-if)# end

SW1# show port-security
SW1# show port-security interface fastEthernet 0/1
SW1# show running-config

Issue a ping from PC-A, then look again at show running-config: the MAC address of PC-A has been "stuck" automatically into the configuration. That is what sticky does.

Provoke the violation

In the workbench in this page, moving the cable is done from the Cables panel:

  1. Pick PC-A and press unplug on port Fa0.
  2. Pick PC-C, press unplug, then connect and choose SW1 : Fa0/1.
  3. Issue a ping from PC-C towards PC-B.
  4. On SW1: show interfaces status - the port appears as err-disabled.
bringing the port back up
SW1# configure terminal
SW1(config)# interface fastEthernet 0/1
SW1(config-if)# shutdown
SW1(config-if)# no shutdown
SW1(config-if)# end
The port shuts down again immediately As long as PC-C sits on that port, the violation repeats at the first frame: the address stuck in the configuration is still that of PC-A. The port stays usable only if you put PC-A back or if you delete the stuck address. This is exactly the behaviour of real networks - and the reason why a tired administrator chooses restrict.
ActionExcess framesCounterNotificationThe port
protectdiscardednonostays up
restrictdiscardedyesSNMP + syslogstays up
shutdown-yesSNMP + syslogerr-disabled
Choose the action sensibly shutdown looks the safest, but it means that any user who changes their laptop is left without a network until somebody comes to bring the port back up. In most office networks, restrict is the right compromise: it blocks suspicious traffic, but reports instead of punishing.

10Assignments

  • Build the topology and verify complete connectivity between all six hosts
  • Document, with screenshots, the three actions of the switch: unicast, flood, drop
  • Justify in writing the number of collision and broadcast domains in the topology
  • Compare the response times through the hub and through the switch, under simultaneous traffic
  • Configure the management of SW1 completely and demonstrate a successful SSH connection
  • Configure port security on all three access ports, with restrict, and provoke a violation on one of them
  • Add a second switch attached to SW1 and explain what happens to the domains

11Going further

Who receives what

Consider the topology of figure 1, with the MAC table of SW1 completely empty. The following three operations are carried out, in order:

  1. PC-C sends a unicast frame towards PC-A
  2. PC-D sends a unicast frame towards PC-A
  3. PC-B sends a unicast frame towards PC-D

For each operation, state: which entries are added to the MAC table of SW1, what action the switch takes, and which of the six hosts actually receive the frame.

See the solution

1. PC-C → PC-A. SW1 learns the MAC of PC-C on Fa0/3. The destination is unknown, hence flood out of Fa0/1, Fa0/2, Fa0/4. Receiving the frame: PC-A, PC-B and, through the hub, PC-D, PC-E, PC-F. Only PC-A processes it; the rest discard it.

2. PC-D → PC-A. The frame comes in on Fa0/4, so SW1 learns the MAC of PC-D on Fa0/4 - the port facing the hub. The destination PC-A is still unknown (PC-A has transmitted nothing so far), hence flood again, out of Fa0/1, Fa0/2, Fa0/3. Receiving it: PC-A, PC-B, PC-C. In addition, PC-E and PC-F receive the frame directly from the hub, which repeats it out of every port.

3. PC-B → PC-D. SW1 learns the MAC of PC-B on Fa0/2. The destination PC-D is known, on Fa0/4, so this time unicast: the frame leaves out of Fa0/4 only. It is received, however, by PC-D, PC-E and PC-F - because the hub knows how to do nothing but repeat.

The conclusion that matters: the switch became selective after the first frame of each host. The hub never does. And an attacker connected to the hub sees all the traffic, without doing absolutely anything.

12Self-check questions

13Deliverables

DeliverableFormatWeight
The Packet Tracer file, with management and port security configured.pkt35 %
The documentation of the three actions of the switch, with screenshotsdocument25 %
The analysis of the collision and broadcast domains, justifieddocument20 %
The solution to the challenge, with the reasoning step by stepdocument20 %