Articles

Switching and MAC learning in operation: reading and controlling the MAC address table

How a Cisco IOS-XE switch stores what it has learned, how to read, populate, age and clear the MAC address table, and what its entries actually tell you about a Layer 2 network.

Reading: 4 minNetworking

Article cover: Switching and MAC learning in operation: reading and controlling the MAC address table

On a switch you rarely configure forwarding: a Cisco IOS-XE switch learns MAC addresses by itself, and the operational skill is reading what it learned. The MAC address table maps a MAC (Media Access Control) address inside a VLAN to the port it was last seen on. An entry is either dynamic — learned and aged out when the source goes quiet — or static — entered by hand and never aged. Reading it shows where an address was last seen.

The model: a live map, per switch and per VLAN

The mechanism belongs to the L1 sheet and is not repeated here: the switch learns from the source address of every frame and forwards by the destination. What this sheet adds is the resulting table. It is not a routing table or a map of the physical network: it records the direction each address was last heard from, on this switch, in this VLAN. Two switches keep two partial tables, and a device that has just moved may still be listed behind its old port until the entry ages or is refreshed.

one entry:  { MAC address | VLAN | port }  ->  type: dynamic or static

dynamic entry
  frame from that source seen again   -> refresh timer (stays known)
  no frame for the aging time         -> removed            (aged out)
  default aging: 300 s (global, applied per VLAN)

static entry
  configured by hand                  -> never aged, survives reload
  same MAC configured elsewhere       -> moves, not duplicated

forwarding (unchanged from L1)
  destination known on another port   -> one port
  destination unknown / broadcast     -> flooded in the VLAN

Terminology

MAC address table — also the forwarding table or FDB: the per-VLAN map of address to port. Dynamic entry — learned and aged. Static entry — manual, never aged. Aging — removing a dynamic entry after it stays silent. Flooding — sending a frame out every port in the VLAN except the arrival port. MAC move (flap) — the same address on a different port.

The mechanism, step by step

  1. Learn. Every frame carries a source MAC. The switch records {source MAC, ingress VLAN, ingress port} as a dynamic entry and refreshes an existing one’s timer.
  2. Store one table per VLAN. The same address can sit behind port 3 in VLAN 10 and port 7 in VLAN 20. An address known in one VLAN is unknown in another until learned or configured there.
  3. Age it out. Aging is global but applied per VLAN: after the aging time with no frame from that address, the dynamic entry is removed. Cisco documents the default as 300 seconds and a range of 10 to 1,000,000; 0 disables aging. Static entries are never aged (spanning tree can accelerate aging on a topology change).
  4. Read it. show mac address-table lists entries with their VLAN, type and port; show mac address-table address answers where an address is seen; show mac address-table static shows only the manual ones. Read the port as the direction traffic last arrived from, not a physical position.
  5. Control it. Add a fixed mapping or a drop entry; change how long dynamic entries live; remove learned entries; and, only with care, disable learning on a VLAN.

The commands, and what each one does

Warnings first. clear mac address-table dynamic deletes what the switch learned, so traffic to those addresses is flooded until it is relearned — brief but real, and not for tidying up. Disabling learning on a VLAN is more serious: Cisco documents that on a VLAN with more than two ports, or one with an SVI, every packet entering it is flooded in the Layer 2 domain. It is meant for two-port VLANs, not as a general control. Aging set to 0 never frees stale entries.

! 1. read what the switch has learned
show mac address-table
show mac address-table address <mac-address>
show mac address-table static
show mac address-table aging-time

! 2. add a fixed (static) entry, or drop a specific unicast address
mac address-table static <mac-address> vlan <vlan-id> interface <interface-id>
mac address-table static <mac-address> vlan <vlan-id> drop

! 3. change the aging time of dynamic entries (global config; default 300 s)
mac address-table aging-time <seconds> [vlan <vlan-id>]

! 4. remove learned entries (privileged EXEC; causes brief flooding)
clear mac address-table dynamic
clear mac address-table dynamic address <mac-address>
clear mac address-table dynamic interface <interface-id>
clear mac address-table dynamic vlan <vlan-id>

! 5. disable learning on a VLAN (flooding risk; see warning above)
no mac address-table learning vlan <vlan-id>

In the output, read the VLAN, the address, the type and the port. A static line for the switch’s switched virtual interface is normal. A destination missing from an expected VLAN is a learning or flood question, not a routing one.

Limits and the common error

The table shows where an address was last seen, not where the device is. A MAC address is local to one link and rewritten at every hop, so each switch’s map is partial; two switches disagreeing is normal — a workstation can appear behind an uplink. Capacity is the second limit: a loop the spanning-tree instance did not block makes the same addresses jump between ports — MAC moves — and can exhaust the table. A flapping table is a symptom to diagnose (the STP sheet’s subject), not a fault in the table. Cisco offers traps on change, move and threshold, so a table can be watched without polling it.

The common error is treating the table as a topology or a security control. It is neither: it is a cache rebuilt from traffic, and it proves nothing about identity. A MAC address is set in software — RFC 7042 treats a Local-bit address as one under the administrator’s control — so any host can claim another.

Level and prerequisites. L2 — operational. It presupposes the L1 sheet on learning and forwarding (Ethernet frames and MAC tables) and what unicast, broadcast and multicast mean. It names, but does not re-teach, VLANs and 802.1Q (a sibling L2 sheet), and refers to spanning tree rather than developing loops.

Where to go next

References

  • IEEE Std 802.1D-2004 — Media Access Control (MAC) Bridges (standard; full text not freely available; superseded by IEEE 802.1Q-2014).
  • RFC 7042 — IANA/IETF and IEEE 802 parameters; the Group and Local bits of a MAC address (BCP 141).
  • Cisco — System Management Configuration Guide, Cisco IOS XE (Catalyst 9300): Administering the Device, the MAC address table and its management.
  • Cisco — Command Reference, Cisco IOS XE (Catalyst 9300): the switch commands used above.
  • Cisco support documentation — Troubleshoot MAC Address Table Manager on Catalyst 9000 Switches.
Nodrius Field Kit — cover

Get the Nodrius Field Kit

Enter your email and we'll send you the complete Field Kit: eight technical resources in one download.

Your email address is sent to Nodrius and used to deliver the Field Kit to you by email. Marketing messages are separate and optional: the checkbox does not affect your download, and you are only added to our updates list if you tick it. Privacy Policy.

Privacy & cookies

This site does not use cookies, analytics or tracking, and it does not profile you. There is nothing technical to switch off, so Accept and Reject change nothing about how the site works: either choice lets you browse everything normally.

The only difference is what your browser remembers: your choice is stored on this device so this notice is not shown again. It contains no identifier, it is not shared with anyone, and the site sets no cookie for it.

What we do with your data
How your email address is used when you ask for a Resource, how long it is kept and which rights you have — in the Privacy Policy.
What the site stores in your browser
Nothing: no cookies, no local storage, no third-party content — in the Cookie Policy.