1.3 Layer 2 Operation, ARP, and 802.1Q Tagging
Key Takeaways
Ethernet switches populate their MAC address (CAM) table dynamically by inspecting the Source MAC address of arriving frames; they forward, flood, or filter frames based on the Destination MAC address.
When a switch receives a frame destined for an unknown unicast address, a broadcast address, or an unregistered multicast address, it floods the frame out all ports within that VLAN except the ingress port.
The Address Resolution Protocol (ARP) resolves known Layer 3 IPv4 addresses into Layer 2 physical MAC addresses using broadcast requests and unicast replies.
The IEEE 802.1Q standard inserts a 4-byte tag into the Ethernet frame containing a 12-bit VLAN Identifier (VID), supporting up to 4,094 usable VLANs to segment broadcast domains.
In Aruba AOS-CX, access ports carry untagged frames for a single VLAN, whereas trunk ports carry tagged frames for multiple VLANs while transmitting Native VLAN traffic untagged by default.
Layer 2 Operation, ARP, and 802.1Q Tagging
Quick Summary: Layer 2 operations dictate how data moves across a local broadcast domain. Ethernet switches maintain a MAC address table (CAM table) by learning source MAC addresses from incoming frames and forwarding frames based on destination MAC addresses. Within a local subnet, devices use the Address Resolution Protocol (ARP) to resolve known Layer 3 IPv4 addresses to physical MAC addresses. To partition large physical networks into isolated broadcast domains, enterprise switches use VLANs standardized by IEEE 802.1Q, tagging frames across trunk links while delivering untagged frames to end-user access ports.
Ethernet Framing and MAC Addressing
Ethernet is the ubiquitous Layer 2 protocol in enterprise campus networks, standardized under IEEE 802.3.
The IEEE 802.3 Ethernet Frame Structure
An Ethernet frame consists of specific fields required for physical synchronization, addressing, payload delivery, and error detection:
| Field | Length | Description |
|---|---|---|
| Preamble | 7 bytes | Alternating pattern of 1s and 0s (10101010) allowing the receiver to synchronize clock timing. |
| Start Frame Delimiter (SFD) | 1 byte | Binary sequence 10101011 indicating that addressing fields immediately follow. |
| Destination MAC Address | 6 bytes (48 bits) | Physical hardware address of the intended recipient device or multicast/broadcast address. |
| Source MAC Address | 6 bytes (48 bits) | Physical hardware address of the transmitting network interface controller (NIC). |
| EtherType / Length | 2 bytes | Identifies the encapsulated Layer 3 protocol (e.g., 0x0800 for IPv4, 0x86DD for IPv6, 0x0806 for ARP, 0x8100 for 802.1Q). |
| Payload (Data) | 46 to 1500 bytes | The encapsulated Layer 3 packet. If data is less than 46 bytes, padding is added to reach the 64-byte minimum. |
| Frame Check Sequence (FCS) | 4 bytes | 32-bit Cyclic Redundancy Check (CRC-32) used to verify that no bits were corrupted during transit. |
- Minimum Frame Size: 64 bytes (excluding Preamble and SFD). Frames smaller than 64 bytes are called runts and are dropped as collisions or corrupt fragments.
- Maximum Standard Frame Size: 1518 bytes (or 1522 bytes when an IEEE 802.1Q tag is present). Frames exceeding this without jumbo frame configuration are called giants.
MAC Address Architecture
A Media Access Control (MAC) address is a 48-bit (6-octet) hexadecimal physical address globally assigned to a network interface controller:
- Organizationally Unique Identifier (OUI - First 24 bits / 3 octets): Assigned by the IEEE Registration Authority to identify hardware manufacturers (e.g., Hewlett Packard Enterprise / Aruba).
- Network Interface Controller Specific (NIC - Last 24 bits / 3 octets): Assigned by the vendor uniquely to each physical or virtual interface.
- Individual / Group (I/G) Bit: The least significant bit of the first octet:
0: Unicast address (identifies a single unique device).1: Multicast or Broadcast address (e.g.,FF:FF:FF:FF:FF:FFwhere all 48 bits are 1s).
- Universal / Local (U/L) Bit: The second least significant bit of the first octet:
0: Globally Unique address administered by the IEEE.1: Locally Administered address configured manually by an administrator or hypervisor.
Switch Forwarding Logic and the MAC Address Table
Ethernet switches maintain a local forwarding database called the MAC address table (stored in high-speed Content Addressable Memory, or CAM). The table maps [VLAN ID, MAC Address, Egress Port, Aging Timer].
When a switch receives a frame on an interface, it executes four fundamental operations:
- Learning (Source MAC): The switch examines the Source MAC address of every incoming frame. If the address is not in the MAC address table for that VLAN, the switch creates a new entry recording the MAC address, ingress port, and VLAN. If the entry already exists, the switch resets its aging timer.
- Flooding (Unknown Unicast, Broadcast, Multicast): If the Destination MAC address is not found in the table (an unknown unicast frame), or if the destination is a broadcast (
FF:FF:FF:FF:FF:FF) or unregistered multicast, the switch floods the frame out all active interfaces assigned to that VLAN except the port on which it arrived. - Forwarding (Known Unicast): If the destination MAC address matches an existing entry for that VLAN, the switch forwards the frame exclusively out the corresponding egress port.
- Filtering: If the destination MAC address is associated with the exact same port on which the frame was received (such as when an unmanaged hub connects multiple hosts to a single switch port), the switch drops (filters) the frame.
- Aging: To accommodate host moves and disconnections, dynamic MAC entries are purged if no new frames with that source MAC arrive within the aging window. In Aruba AOS-CX switches, the default MAC aging timer is 300 seconds (5 minutes).
Address Resolution Protocol (ARP)
Host devices need a mechanism to resolve a known Layer 3 IPv4 address into a Layer 2 physical MAC address before they can transmit an Ethernet frame.
The ARP Process Step-by-Step
Assume Host A (10.1.10.10, MAC AAAA.AAAA.AAAA) needs to communicate with Host B (10.1.10.50, MAC BBBB.BBBB.BBBB) in the same VLAN:
- ARP Request (Broadcast): Host A checks its local ARP cache. If Host B's MAC is missing, Host A generates an ARP Request:
- "Who has IPv4 address 10.1.10.50? Tell 10.1.10.10."
- Encapsulated in an Ethernet frame with Destination MAC
FF:FF:FF:FF:FF:FF. - The switch floods the broadcast frame out all ports in VLAN 10.
- ARP Processing: Every host in VLAN 10 receives and decapsulates the frame. Hosts with other IP addresses discard it. Host B recognizes its own IP address and adds Host A's mapping (
10.1.10.10toAAAA.AAAA.AAAA) to its local ARP cache. - ARP Reply (Unicast): Host B creates an ARP Reply:
- "10.1.10.50 is at BBBB.BBBB.BBBB."
- Encapsulated with Destination MAC
AAAA.AAAA.AAAA(unicast directly to Host A). - The switch forwards the frame out Host A's port.
- Communication: Host A updates its ARP cache and transmits its queued application data directly to Host B.
Gratuitous ARP (GARP)
A Gratuitous ARP is an unrequested ARP broadcast sent by a host advertising its own IP and MAC address (Source IP = Target IP). It serves two essential purposes in campus networks:
- Duplicate IP Address Detection: If another host replies, an IP address conflict exists.
- Updating Network Caches: When a server switches active NICs in a team, or when an Aruba Virtual Switching Extension (VSX) pair or VRRP gateway performs a failover, a GARP immediately updates switch MAC tables and neighboring ARP caches without waiting for timers to expire.
IEEE 802.1Q VLAN Tagging
A Virtual Local Area Network (VLAN) divides a physical switch into multiple isolated logical broadcast domains. By default, devices in different VLANs cannot communicate at Layer 2; traffic must traverse a Layer 3 routing device.
The 802.1Q Tag Format
When frames travel across links connecting switches together (trunk links), they must be tagged with their VLAN identity. The IEEE 802.1Q standard inserts a 4-byte tag directly into the Ethernet frame between the Source MAC and EtherType fields:
- Tag Protocol Identifier (TPID - 16 bits): Always set to
0x8100to indicate an 802.1Q-tagged frame follows. - Tag Control Information (TCI - 16 bits):
- Priority Code Point (PCP - 3 bits): Implements IEEE 802.1p Layer 2 Quality of Service (QoS) prioritization (values 0 to 7).
- Drop Eligible Indicator (DEI - 1 bit): Formerly Canonical Format Indicator (CFI). Marks frames that can be dropped during network congestion.
- VLAN Identifier (VID - 12 bits): Identifies the VLAN. A 12-bit binary number provides possible values:
0: Priority-tagged frame (uses PCP QoS without a specific VLAN ID).1: Default VLAN on switches.1 to 4094: Usable VLAN range for data, voice, and management.4095: Reserved for system implementation.
Access vs. Trunk Ports in Aruba AOS-CX
| Port Mode | Typical Connection | 802.1Q Tagging Behavior | Native VLAN Handling |
|---|---|---|---|
| Access Port | End-user workstations, printers, IP phones | Untagged: Strips tags on egress; assigns incoming untagged frames to the configured access VLAN. | Not applicable (port belongs to only one VLAN). |
| Trunk Port | Switch-to-switch uplinks, APs, hypervisors | Tagged: Encapsulates frames with an 802.1Q tag for all allowed VLANs. | Transmits the configured Native VLAN untagged; untagged frames received are placed in the Native VLAN. |
Security Best Practice: By default, Aruba switches use VLAN 1 as the native VLAN on trunks. To protect against VLAN hopping attacks, network administrators configure an unused non-default VLAN (e.g., VLAN 999) as the native VLAN across all inter-switch trunks.
Aruba AOS-CX Configuration and Verification
On Aruba AOS-CX switches, configuring VLANs, access ports, and trunks follows a structured syntax:
! Step 1: Create VLANs in the database
switch# configure terminal
switch(config)# vlan 10
switch(config-vlan-10)# name DATA_CLIENTS
switch(config-vlan-10)# vlan 20
switch(config-vlan-20)# name VOICE_PHONES
switch(config-vlan-20)# exit
! Step 2: Configure an Access Port for a user workstation
switch(config)# interface 1/1/1
switch(config-if)# description User_Workstation_Desk01
switch(config-if)# no routing
switch(config-if)# vlan access 10
switch(config-if)# exit
! Step 3: Configure a Trunk Port uplink to an aggregation switch
switch(config)# interface 1/1/48
switch(config-if)# description Uplink_to_Core
switch(config-if)# no routing
switch(config-if)# vlan trunk native 999
switch(config-if)# vlan trunk allowed 10,20,999
switch(config-if)# exit
AOS-CX detail: the native VLAN is forwarded only if it is also in the allowed list.
vlan trunk native 999without999invlan trunk allowedleaves untagged traffic with nowhere to go.
Essential Verification Commands
show vlan: Displays all configured VLANs, state, and port membership.show mac-address-table: Shows learned MAC addresses, associated VLANs, and physical egress ports.show arp: Displays the Layer 3 to Layer 2 address mappings on routed interfaces.show interface 1/1/48 brief: Displays operational port status, speed, and mode.show vlan port 1/1/48: Lists the tagged and untagged VLANs active on the port.
Common Exam Traps
- Learning vs. Forwarding Lookups: A frequent question tests which MAC address is used for which operation. Switches learn from the Source MAC address; switches forward based on the Destination MAC address.
- Access Port Tagging: Misunderstanding that an access port sends tagged frames to a PC. Standard access ports always transmit untagged frames to end devices.
- VLAN ID Bit Depth: Forgetting the size of the VID field: it is exactly 12 bits (yielding 4,096 theoretical IDs, with 4,094 usable IDs from 1 to 4094).
- Native VLAN Mismatch: If Switch A has native VLAN 10 and Switch B has native VLAN 20 across a trunk, untagged traffic from VLAN 10 will cross the link and emerge inside VLAN 20 without routing, causing security breaches and spanning tree inconsistencies.
An Aruba CX switch receives a frame on port 1/1/5 with a source MAC address of 00:50:56:AB:CD:EF and a destination MAC address of 00:0C:29:12:34:56. The destination MAC address is not currently present in the switch's MAC address table for VLAN 10. How does the switch process this frame?
The switch drops the frame and sends an ICMP Destination Unreachable message back to the source on port 1/1/5
The switch learns the source MAC on port 1/1/5 in VLAN 10 and floods the frame to all other ports in VLAN 10
The switch broadcasts an ARP request out every port in VLAN 10 to locate the destination before forwarding
The switch adds the destination MAC to port 1/1/5 and forwards the frame out the default gateway interface
In the IEEE 802.1Q tagging standard, how many bits are allocated specifically for the VLAN Identifier (VID), and what is the maximum number of usable VLANs supported?
16 bits, supporting up to 65,534 usable VLANs
12 bits, supporting up to 4,094 usable VLANs
8 bits, supporting up to 254 usable VLANs
10 bits, supporting up to 1,024 usable VLANs
An administrator configures port 1/1/24 on an Aruba CX 6200 switch as an uplink to another switch using the commands: 'no routing', 'vlan trunk native 1', and 'vlan trunk allowed 10,20'. When the switch transmits a frame belonging to VLAN 10 across this link, how is the frame formatted on the wire?
The frame is transmitted with an IEEE 802.1Q header containing VID 10
The frame is transmitted untagged because it is an access transmission
The frame is stripped of its Layer 2 header and routed at Layer 3
The frame is encapsulated with a proprietary Aruba header
Sections you finish are checked off in the contents.