5.4 MAC Address Table Learning, Aging, and Forwarding
Key Takeaways
Layer 2 switches maintain a MAC address table (CAM table) that maps dynamic host MAC addresses and VLAN memberships to specific physical switch interfaces.
Switch learning is governed exclusively by the Source MAC address of ingress frames, whereas forwarding decisions are determined exclusively by the Destination MAC address.
When the destination MAC is absent from the MAC table, the switch performs unknown unicast flooding, replicating the frame out all ports in the same VLAN except the ingress port.
The default dynamic MAC aging timer on AOS-CX switches is 300 seconds; entries refresh upon receiving new frames from the host and age out during periods of inactivity.
MAC address flapping—where a MAC rapidly moves between different switch ports—is a key symptom of Layer 2 loops, duplicate host MACs, or virtual machine NIC teaming misconfigurations.
MAC Address Table Learning, Aging, and Forwarding
Quick Summary: At the heart of Layer 2 campus switching is the MAC Address Table (historically termed the Content Addressable Memory or CAM table). While legacy network hubs blindly repeated electrical signals across every port, modern switches make intelligent, hardware-accelerated forwarding decisions at wire speed. An AOS-CX switch autonomously builds its MAC table by observing the Source MAC address of incoming frames and associating it with the ingress port and VLAN. When forwarding frames, the switch looks up the Destination MAC address: if known, the frame is switched directly to the destination port; if unknown, broadcast, or multicast, the frame is flooded across the originating VLAN. Understanding table aging, static entries, and MAC address flapping is essential for enterprise access layer troubleshooting.
The Function and Architecture of the MAC Address Table
A Layer 2 Ethernet switch acts as a multi-port bridge, providing dedicated bandwidth to each connected endpoint and isolating collision domains. To accomplish this, the switch maintains an internal database mapping physical MAC addresses to local switch interfaces.
In AOS-CX switches, this database is implemented in hardware lookup tables, traditionally described as Content Addressable Memory (CAM). Unlike conventional RAM, where a system supplies a memory address to retrieve stored data, CAM accepts the search query (the 48-bit MAC address and 12-bit VLAN ID) and returns the corresponding egress physical interface in a single clock cycle (nanosecond latency).
Each entry in the AOS-CX MAC address table contains four core attributes:
- VLAN ID: The specific broadcast domain in which the MAC address was learned.
- MAC Address: The 48-bit hardware address of the connected network interface (AOS-CX displays and accepts the
xx:xx:xx:xx:xx:xxformat). - Type: Indicates how the entry was established—Dynamic (learned automatically from incoming traffic) or Static (manually configured by an administrator).
- Port / Interface: The physical interface (e.g.,
1/1/5), Link Aggregation Group (e.g.,lag1), or internal virtual interface associated with the device.
The Dynamic Learning Process: Source MAC Processing
When an AOS-CX switch powers on, its MAC address table is completely empty. The switch populates its forwarding table through an autonomous, four-step dynamic learning algorithm:
+-----------------------------------------------------------------------------------------+
| DYNAMIC MAC LEARNING FLOW |
| |
| Host A [MAC: 00:50:56:aa:11:11] -> Port 1/1/1 (VLAN 10) -----> AOS-CX Switch |
| |
| Step 1: Frame arrives on Port 1/1/1 in VLAN 10. |
| Step 2: Switch inspects the SOURCE MAC address (00:50:56:aa:11:11). |
| Step 3: Switch checks CAM table for [VLAN 10 + 00:50:56:aa:11:11]: |
| - If absent: Creates new entry -> [VLAN 10, 00:50:56:aa:11:11, Port 1/1/1]. |
| - If present on same port: Resets 300-second aging timer to zero. |
| - If present on DIFFERENT port: Updates entry immediately (Host moved). |
+-----------------------------------------------------------------------------------------+
Critical Principle of Switch Learning
Exam Fundamental: A Layer 2 switch learns MAC addresses strictly from the Source MAC address of incoming frames. It never learns an endpoint's location from the Destination MAC address. Every frame received on an active port provides real-time verification of where that transmitting host is physically located.
Frame Forwarding Decisions: Destination MAC Processing
While learning is governed strictly by the Source MAC, forwarding decisions are governed strictly by the Destination MAC address and the frame's VLAN membership.
When a frame arrives, the switch ASIC evaluates the Destination MAC against its CAM table, executing one of three distinct actions:
1. Known Unicast Forwarding (Point-to-Point Switching)
- Condition: The Destination MAC is a unicast address (least significant bit of the first byte is
0), and an active entry for that MAC and VLAN exists in the MAC address table. - Action: The switch forwards the frame strictly out the single designated egress port. No other interfaces receive the frame, ensuring complete privacy and conserving link bandwidth.
2. Unknown Unicast Flooding
- Condition: The Destination MAC is a unicast address, but the switch has no recorded entry for that MAC address in the target VLAN.
- Action: Because the switch does not know which physical port hosts the destination device, it performs unknown unicast flooding. The switch replicates the frame and transmits a copy out every active port belonging to that VLAN, except the ingress port on which the frame arrived.
- Learning Response: When the destination host receives the flooded frame and sends a reply, the switch inspects the reply's Source MAC, learns the host's location, and updates its CAM table. All subsequent traffic to that host becomes known unicast forwarding.
3. Broadcast and Multicast Flooding
- Broadcast Frames (
FFFF.FFFF.FFFF): Transmitted by protocols such as ARP and DHCP. The switch floods the frame out all ports in the originating VLAN except the ingress port. - Multicast Frames (
0100.5Exx.xxxxfor IPv4,3333.xxxx.xxxxfor IPv6): By default, unmanaged switches flood multicast out all ports. On AOS-CX switches with IGMP Snooping enabled, the switch snoops IGMP join/leave messages and forwards multicast streams only to switch ports with subscribed receivers.
Filtering (Frame Dropping)
If a frame arrives on port 1/1/1 and the switch's CAM table indicates that the Destination MAC also resides on port 1/1/1 (for example, traffic traversing an external hub connected to port 1/1/1), the switch filters (drops) the frame because the destination has already received the transmission on the local shared medium.
MAC Aging Timers and Cache Management
Endpoints in enterprise campus networks are dynamic: laptops disconnect, mobile devices roam between wireless APs, and workstations enter sleep states. If a switch retained dynamic MAC entries indefinitely, the CAM table would eventually exhaust its hardware capacity, causing the switch to fall back to constant unknown unicast flooding.
To maintain table accuracy and free hardware resources, AOS-CX implements an automated MAC Aging Timer:
- Default Duration: 300 seconds (5 minutes).
- Timer Reset: Every time an incoming frame is observed with a known Source MAC, the switch resets that entry's aging countdown back to 300 seconds.
- Aging Eviction: If no frames are received from a given MAC address for 300 consecutive seconds, the switch automatically evicts the entry from the CAM table.
- Administrative Tuning: The aging timer can be adjusted globally using the
mac-address-table age-time <seconds>command (range 60 to 3600 seconds; default 300). - Topology Change Interaction: As examined in Section 5.3, when Spanning Tree receives a Topology Change Notification (TCN), switches temporarily accelerate aging (reducing the timer to the 15-second Forward Delay) to purge stale routes following a topology shift.
Static MAC Address Provisioning and Use Cases
While dynamic learning accommodates user endpoints, enterprise environments occasionally require deterministic MAC-to-port bindings that bypass learning and never expire.
An administrator configures a Static MAC Address using the following syntax:
switch(config)# static-mac 00:50:56:a1:b2:c3 vlan 10 port 1/1/10
Key Characteristics of Static MAC Entries
- Permanent Existence: Static entries are not affected by the MAC aging time. They can be assigned only to Layer 2 (non-routed) interfaces and an existing VLAN, and they persist across reboots once the configuration is saved.
- Immunity to Overwrite: If an unauthorized device on port 1/1/5 transmits frames with the spoofed source MAC
00:50:56:a1:b2:c3, the switch does not move the static entry and keeps directing traffic to interface 1/1/10. - Common Deployments: High-availability server clusters, dedicated backup appliances, non-standard industrial controllers, and network security appliances.
Diagnosing and Resolving MAC Address Flapping
MAC address flapping (also known as MAC table thrashing) occurs when a switch rapidly and repeatedly learns the exact same MAC address across two or more different interfaces within a few seconds.
When flapping occurs, the event log shows repeated MAC-move messages. AOS-CX also tracks moves directly: show mac-address-table mac-move lists the move count and history per MAC address and VLAN, and clear mac-address mac-move resets those statistics. A simplified example of the pattern to look for:
MAC 00:50:56:9a:1b:2c in VLAN 10 moved from port 1/1/1 to port 1/1/2
MAC 00:50:56:9a:1b:2c in VLAN 10 moved from port 1/1/2 to port 1/1/1
+-----------------------------------------------------------------------------------------+
| CAUSES OF MAC ADDRESS FLAPPING |
| |
| 1. Physical Layer 2 Loop: |
| Frames circulate around redundant links, arriving at different ports repeatedly. |
| |
| 2. Duplicate Hardware MAC: |
| Two physical devices (or cloned VMs) configured with identical MAC addresses. |
| |
| 3. Server Teaming Misconfiguration: |
| Server NICs connected in active-active mode without an upstream LAG (LACP) trunk. |
| |
| 4. Asymmetric Wireless Roaming: |
| Rapid Wi-Fi roaming without proper client bridge state cleanup. |
+-----------------------------------------------------------------------------------------+
Systematic Troubleshooting Methodology
- Identify the Flapping MAC: Run
show mac-address-table mac-move(or reviewshow events) to extract the specific MAC address, VLAN ID, and oscillating port pair. - Check for Layer 2 Loops: Verify Spanning Tree operational states on the affected ports (
show spanning-tree). If ports that should be blocking are in Forwarding, resolve the STP misconfiguration or check for an unmanaged switch loop. - Inspect Connected Devices: Trace physical cabling from the reported ports. If both ports connect to dual NICs on the same physical server, verify that the server's NIC team is configured for LACP and that the switch has an active Link Aggregation Group (
lag) configured across both ports. - Search for Duplicate Virtual Machines: In virtualized environments (VMware ESXi, Hyper-V, KVM), check hypervisor logs to determine whether two separate virtual machines were cloned from an identical template with static virtual MAC addresses.
AOS-CX Verification and Troubleshooting Commands
The following CLI commands provide complete visibility into the AOS-CX MAC address table:
! View the entire active MAC address table
switch# show mac-address-table
! Filter entries by specific VLAN
switch# show mac-address-table vlan 10
! Filter entries by physical interface
switch# show mac-address-table port 1/1/1
! Search for a specific host MAC address
switch# show mac-address-table address 00:50:56:aa:11:11
! Display total count of learned dynamic and static MAC entries
switch# show mac-address-table count
! Show MAC move (flapping) history
switch# show mac-address-table mac-move
! Clear MAC move statistics for one VLAN
switch# clear mac-address mac-move vlan 10
Summary Table of MAC Operations
| Operational Stage | Inspected Field | Primary Purpose / Forwarding Outcome |
|---|---|---|
| Address Learning | Source MAC Address | Adds new entry [VLAN, MAC, Port] or resets 300-second aging timer. |
| Known Unicast Forwarding | Destination MAC Address | Forwards frame strictly out the single mapped egress interface. |
| Unknown Unicast Forwarding | Destination MAC Address | Floods frame out all interfaces in the originating VLAN except ingress. |
| Broadcast Forwarding | FFFF.FFFF.FFFF | Floods frame out all interfaces in the originating VLAN except ingress. |
| Address Aging | Idle Timer Expiration | Evicts entries inactive for 300 seconds to conserve CAM memory. |
Common Exam Traps
- Learning vs. Forwarding Mismatch: A classic exam question asks which address is used to populate the CAM table. Remember: Learning is based on Source MAC; Forwarding is based on Destination MAC.
- Default Aging Duration: The default dynamic MAC aging timer on AOS-CX switches is 300 seconds (5 minutes). Do not confuse this with the Spanning Tree Forward Delay timer (15 seconds) or ARP cache timers (which typically range from 20 minutes to 4 hours on Layer 3 interfaces).
- Flooding Scope: Unknown unicast and broadcast frames are flooded only within the originating VLAN. A Layer 2 switch will never flood frames across VLAN boundaries.
- MAC Flap Meaning: MAC flapping does not indicate that a client is renewing its DHCP lease or that an interface is negotiating PoE power. It indicates a severe Layer 2 loop, a duplicate MAC conflict, or an improper multi-homed server NIC team.
How does an Aruba AOS-CX Layer 2 switch determine which interface to associate with a host's MAC address in its forwarding database?
By inspecting the Destination MAC address of incoming Ethernet frames
By querying the local ARP table for the destination IP-to-MAC mapping
By inspecting the Source MAC address and ingress VLAN of incoming Ethernet frames
By listening for Spanning Tree Bridge Protocol Data Units (BPDUs) sent by the host
What is the default dynamic MAC address aging timer on an Aruba AOS-CX switch, and what primary operational purpose does this timer serve?
3600 seconds; it minimizes ARP broadcast traffic across the campus core links each hour
15 seconds; it matches the spanning tree forward delay to ensure instant reconvergence
60 seconds; it forces hosts to re-authenticate with the RADIUS server every minute
300 seconds; it removes inactive entries so the table stays current as hosts move
An administrator investigating intermittent network slowness on an Aruba CX 6300 switch reviews the event logs and discovers multiple warnings stating: 'MAC 00:50:56:9a:1b:2c moved from port 1/1/1 to port 1/1/2'. What is the most likely cause of this behavior?
A Layer 2 loop between ports 1/1/1 and 1/1/2, or the same MAC address active on both segments
The switch is running out of TCAM memory and is demoting its Layer 3 routes to Layer 2 entries
The interface has 802.1X re-authentication enabled and is rotating the client's encryption keys
The host device is renewing its DHCP lease every 60 seconds, which re-registers its MAC address
Sections you finish are checked off in the contents.