A switch receives a new device and, within a few milliseconds, knows where it is - without anybody having told it anything. This exercise takes the mechanism apart, step by step: you empty the MAC table, fill it while watching, compare the switch with a hub on the same topology, and see literally what a collision domain means.
1What we take apart today
In laboratory 1 you issued a ping and it worked. Nobody explained why the switch knew where to send the frame. Today you find out, and the answer has only three rules.
| The rule | What the switch does |
|---|---|
| it learns | For every frame that comes in, it notes the source MAC address and the port it came in on. Nobody tells it anything: it works it out by itself. |
| it looks up | It looks at the destination MAC address. If it finds it in the table, it sends the frame only out of that port (unicast). |
| it floods | If it does not find it - or if the destination is broadcast - it sends the frame out of every port except the one it came in on (flood). |
There is a fourth, rarer situation: if the destination is on the very port of arrival, the switch discards the frame (drop) - the two hosts hear each other directly anyway.
192.168.5.11), but it needs the number of the network card in order to compose the frame. It
asks in broadcast, receives a unicast answer and remembers that answer for a few minutes.2Equipment needed
| Qty | Equipment | Model | Packet Tracer category | What it is for here |
|---|---|---|---|---|
| 1 | Switch | 2960 | Network Devices → Switches | the "intelligent" part of the topology |
| 1 | Hub | Hub-PT | Network Devices → Hubs | the term of comparison |
| 6 | Computer | PC-PT | End Devices → End Devices | PC-A … PC-F |
| 7 | Copper cable | Copper Straight-Through | Connections → Connections | every link |
Optionally, for the last assignment: one more 2960 switch and a
Copper Cross-Over cable.
Packet Tracer is required for: Simulation mode with envelopes followed step by step, measuring times under simultaneous traffic, an actual SSH session, and the real ageing of entries over time.
3The topology to build
| Device | IP address | Mask | Port on SW1 / HUB1 |
|---|---|---|---|
| PC-A | 192.168.5.10 | 255.255.255.0 | SW1 Fa0/1 |
| PC-B | 192.168.5.11 | 255.255.255.0 | SW1 Fa0/2 |
| PC-C | 192.168.5.12 | 255.255.255.0 | SW1 Fa0/3 |
| PC-D, PC-E, PC-F | 192.168.5.13 – .15 | 255.255.255.0 | HUB1 |
| SW1 | 192.168.5.2 (VLAN 1) | 255.255.255.0 | - |
There is no router and no gateway is needed: every host is in the same network. The SW1 Fa0/4 – HUB1 link is made with straight-through cable.
4The workbench
The topology of figure 1, cabled and addressed. Every section that follows can be done here; open it in a tab beside the text and work as you read.
5The MAC table, watched as it fills
- Note the MAC addresses of the hosts
For every host, open the terminal (in Packet Tracer: Desktop → Command Prompt) and run:
on every hostipconfig /all
Note the Physical Address field - it is the MAC address. You will need these six values at every step that follows; without them, the table of the switch is a meaningless string of digits.
- Empty the table and check that it is empty
on SW1
Switch> enable Switch# clear mac address-table dynamic Switch# show mac address-table
No entry must appear. If some still do, it means traffic has passed in the meantime - repeat the two commands one straight after the other.
- A single frame, and look at what has happened
From PC-A, issue a single ping towards PC-B, then come straight back to SW1:
on PC-Aping -n 1 192.168.5.11
on SW1SW1# show mac address-table
QuestionHow many entries appeared, and where did the switch learn each of them from?
See the answer
Two: the MAC of PC-A on Fa0/1 and the MAC of PC-B on Fa0/2. The first was learned from the ARP request of PC-A - a broadcast, therefore flooded out of every port. The second, from the ARP reply of PC-B. The ping itself had nothing left to teach: by the time it left, the switch already knew everything.
The conclusion that matters: the switch does not learn from ping. It learns from any frame that passes through it, whatever it contains.
- The three actions, one at a time
Empty the table again and run the scenarios in the order below. In Packet Tracer switch to Simulation and filter on ICMP and ARP, so that you see the envelopes. In the workbench in this page, watch the MAC table after each step.
Scenario What the switch does How you check PC-A → PC-B, with the table empty flood: the frame leaves out of every port except Fa0/1 the table was empty, so the destination was unknown PC-B → PC-A, straight afterwards unicast: only out of Fa0/1 show mac address-tablealready contains PC-APC-A → broadcast flood, always in Packet Tracer: ping 192.168.5.255 - The ageing of entries
on SW1
SW1# show mac address-table aging-time SW1# configure terminal SW1(config)# mac address-table aging-time 30 SW1(config)# end
The default value is 300 seconds. Reduce it to 30, generate traffic from PC-C, then leave the network quiet and watch the table every 15 seconds: the entry disappears. (The passage of time can only be observed in Packet Tracer; in the workbench in this page the command is accepted, but the table does not age by itself.)
Why ageing is needed If you move PC-C from Fa0/3 to Fa0/5, the switch would carry on sending its traffic out of the old port - indefinitely. In practice, the first frame sent by PC-C from the new port corrects the entry at once; ageing covers the case where the host has left and no longer speaks at all.Check this right now, in the workbench: pick PC-C, in the Cables panel press unplug, then connect towards
SW1 : Fa0/5. Issue a ping from PC-C and look again atshow mac address-table: the entry has moved to the new port by itself.
6Switch versus hub
The right-hand part of the topology exists for one reason only: so that you see the difference instead of imagining it.
- Traffic through the hub
From PC-D issue a ping towards PC-E. In Packet Tracer, in Simulation, follow the envelope.
The hub sends it out of every port - including to PC-F, which has nothing to do with this conversation, and back towards the switch. PC-F receives the frame, looks at the destination MAC address, finds that it is not its own and discards it. Time and bandwidth spent for nothing, on every single frame.
In the workbench in this page, check the consequence on the switch: after a ping between two hosts attached to the hub,
show mac address-tableon SW1 shows both addresses on the same port, Fa0/4. The switch has no way of separating them: from its point of view, everything beyond the hub sits on a single wire. - The collision, provoked Packet Tracer only
Go back to Realtime. Open the terminals on PC-D and PC-F at the same time and launch from both, as close together in time as you can:
on PC-D and PC-F, almost simultaneouslyping -n 200 -l 1400 192.168.5.10
Compare the response times with those obtained when you run alone. Repeat the experiment replacing the hub with a second switch and observe the difference.
- Count the domains
Exercise
For the topology of figure 1, how many collision domains and how many broadcast domains are there?
See the answer
Collision domains: 5. SW1 creates one on each port: Fa0/1, Fa0/2, Fa0/3 and Fa0/4 - that is 4. The hub, together with PC-D, PC-E, PC-F and the link towards the switch, forms a single domain - the fifth. Careful: the SW1–HUB1 link belongs to the domain of the hub, not to a separate one.
Broadcast domains: 1. There is no router and no VLAN, so all six hosts hear each other in broadcast. A
ping 192.168.5.255from PC-A reaches everybody.
7ARP, with the cache emptied
- Clear the cache and look at the request
on PC-A
arp -d arp -a ping -n 1 192.168.5.12 arp -a
The first display must say
No ARP Entries Found. After the ping, the address of PC-C appears together with its MAC. This is the whole mechanism: a question, an answer, a note remembered for a few minutes.In Packet Tracer, follow the ARP request in Simulation and read from Outbound PDU Details:
- the destination MAC address of the frame:
FFFF.FFFF.FFFF- broadcast; - the Target MAC field of the ARP packet: zeros - exactly what is being asked for;
- the Target IP field: the address of PC-C.
Every host receives the request. Only PC-C answers; the others ignore it silently.
- the destination MAC address of the frame:
- The effect of the cache
Issue
ping 192.168.5.12straight afterarp -dand then once more. The first time the first packet is lost; the second time, none is. The difference is exactly the cost of ARP resolution.Remember the symptom In a network with problems, pings that "work, but fail the first time" almost always point to a matter of ARP, not of routing. It is the first thing you strike off the list.
8Managing the switch
So far we have configured the switch sitting at its console. In order to manage it remotely, it needs an IP address and a means of access protected by a password.
The commands below are typed line by line. Those beginning with ! are comments - they are
not typed.
Switch> enable Switch# configure terminal Switch(config)# hostname SW1 SW1(config)# no ip domain-lookup ! the management address sits on the VLAN 1 virtual interface SW1(config)# interface vlan 1 SW1(config-if)# ip address 192.168.5.2 255.255.255.0 SW1(config-if)# no shutdown SW1(config-if)# exit ! the password for privileged mode SW1(config)# enable secret Cisco123 SW1(config)# service password-encryption SW1(config)# end SW1# copy running-config startup-config
Check from two places:
SW1# show ip interface brief
Vlan1 must appear with 192.168.5.2 and up / up. If it appears as
administratively down, you forgot no shutdown on the VLAN interface.
ping 192.168.5.2
Remote access
For a true SSH session, a domain name, a key and a user are also needed. These commands are demonstrated in Packet Tracer:
SW1(config)# ip domain-name retele.local SW1(config)# crypto key generate rsa ! when asked about the key length, answer 1024 SW1(config)# username admin privilege 15 secret Admin123 SW1(config)# line vty 0 4 SW1(config-line)# transport input ssh SW1(config-line)# login local SW1(config-line)# exit SW1(config)# banner motd #Authorized access only#
ssh -l admin 192.168.5.2
ip default-gateway.9Port security
A switch port accepts, by default, any MAC address presented to it. Port security limits the number of addresses that may be learned on a port and decides what happens when the limit is exceeded - the first defence against the CAM overflow attack from lecture 12.
SW1# configure terminal SW1(config)# interface fastEthernet 0/1 SW1(config-if)# switchport mode access SW1(config-if)# switchport port-security SW1(config-if)# switchport port-security maximum 1 SW1(config-if)# switchport port-security mac-address sticky SW1(config-if)# switchport port-security violation shutdown SW1(config-if)# end SW1# show port-security SW1# show port-security interface fastEthernet 0/1 SW1# show running-config
Issue a ping from PC-A, then look again at show running-config: the MAC address of PC-A has
been "stuck" automatically into the configuration. That is what sticky does.
Provoke the violation
In the workbench in this page, moving the cable is done from the Cables panel:
- Pick PC-A and press unplug on port
Fa0. - Pick PC-C, press unplug, then connect and choose
SW1 : Fa0/1. - Issue a ping from PC-C towards PC-B.
- On SW1:
show interfaces status- the port appears aserr-disabled.
SW1# configure terminal SW1(config)# interface fastEthernet 0/1 SW1(config-if)# shutdown SW1(config-if)# no shutdown SW1(config-if)# end
restrict.| Action | Excess frames | Counter | Notification | The port |
|---|---|---|---|---|
protect | discarded | no | no | stays up |
restrict | discarded | yes | SNMP + syslog | stays up |
shutdown | - | yes | SNMP + syslog | err-disabled |
shutdown looks the safest, but it means that any user who changes their laptop is left without
a network until somebody comes to bring the port back up. In most office networks,
restrict is the right compromise: it blocks suspicious traffic, but reports instead of
punishing.10Assignments
- Build the topology and verify complete connectivity between all six hosts
- Document, with screenshots, the three actions of the switch: unicast, flood, drop
- Justify in writing the number of collision and broadcast domains in the topology
- Compare the response times through the hub and through the switch, under simultaneous traffic
- Configure the management of SW1 completely and demonstrate a successful SSH connection
- Configure port security on all three access ports, with
restrict, and provoke a violation on one of them - Add a second switch attached to SW1 and explain what happens to the domains
11Going further
Consider the topology of figure 1, with the MAC table of SW1 completely empty. The following three operations are carried out, in order:
- PC-C sends a unicast frame towards PC-A
- PC-D sends a unicast frame towards PC-A
- PC-B sends a unicast frame towards PC-D
For each operation, state: which entries are added to the MAC table of SW1, what action the switch takes, and which of the six hosts actually receive the frame.
See the solution
1. PC-C → PC-A. SW1 learns the MAC of PC-C on Fa0/3. The destination is unknown, hence flood out of Fa0/1, Fa0/2, Fa0/4. Receiving the frame: PC-A, PC-B and, through the hub, PC-D, PC-E, PC-F. Only PC-A processes it; the rest discard it.
2. PC-D → PC-A. The frame comes in on Fa0/4, so SW1 learns the MAC of PC-D on Fa0/4 - the port facing the hub. The destination PC-A is still unknown (PC-A has transmitted nothing so far), hence flood again, out of Fa0/1, Fa0/2, Fa0/3. Receiving it: PC-A, PC-B, PC-C. In addition, PC-E and PC-F receive the frame directly from the hub, which repeats it out of every port.
3. PC-B → PC-D. SW1 learns the MAC of PC-B on Fa0/2. The destination PC-D is known, on Fa0/4, so this time unicast: the frame leaves out of Fa0/4 only. It is received, however, by PC-D, PC-E and PC-F - because the hub knows how to do nothing but repeat.
The conclusion that matters: the switch became selective after the first frame of each host. The hub never does. And an attacker connected to the hub sees all the traffic, without doing absolutely anything.
12Self-check questions
13Deliverables
| Deliverable | Format | Weight |
|---|---|---|
| The Packet Tracer file, with management and port security configured | .pkt | 35 % |
| The documentation of the three actions of the switch, with screenshots | document | 25 % |
| The analysis of the collision and broadcast domains, justified | document | 20 % |
| The solution to the challenge, with the reasoning step by step | document | 20 % |