Before a packet can cross the internet, it has to cross the room. That first hop is almost always Ethernet or Wi-Fi, speaking in frames addressed to hardware. This chapter takes a frame apart, shows how a switch figures out where everyone is without being told, and how a computer finds its neighbor's hardware address with one shouted question.
Common mix-up: websites can't see your MAC address. A MAC address only travels as far as the next router, which strips the Ethernet header off and writes a fresh one for the next link. By the time your packet reaches a server, it carries the MAC address of that server's own router, not yours.
Ethernet began at Xerox PARC in the 1970s as a way to share one thick coaxial cable among many computers. The cable is long gone, replaced by twisted pair, fiber and switches, but the frame format, standardized as IEEE 802.3, has barely changed. Wi-Fi (IEEE 802.11) uses a different frame on the air but the same 48-bit addresses, and access points translate between the two, so to everything above the link layer Wi-Fi looks like Ethernet.
A frame is a short, self-contained burst. Reading left to right, the order the bits go out:
| Field | Bytes | What it's for |
|---|---|---|
| Preamble | 7 | Alternating 1s and 0s (0x55 repeated), so the receiver's clock can lock onto the signal. |
| Start frame delimiter | 1 | 0xD5: the pattern breaks with two 1s in a row, meaning "the frame starts now." |
| Destination MAC | 6 | Who should keep this frame. First, so a switch can start deciding before the rest arrives. |
| Source MAC | 6 | Who sent it. Switches learn from this field. |
| EtherType | 2 | What's inside: 0x0800 IPv4, 0x86DD IPv6, 0x0806 ARP, 0x8100 means a VLAN tag follows. |
| Payload | 46–1,500 | The packet being carried. Shorter payloads are padded up to 46 bytes. |
| Frame check sequence | 4 | A CRC-32 checksum over everything from the destination address to the end of the payload. |
After the frame the sender must stay silent for an interframe gap of 96 bit times (12 bytes' worth) before starting the next one. Counting from the destination address to the checksum, a frame is 64 to 1,518 bytes long. The preamble and gap aren't usually counted as part of the frame, but they take wire time all the same, which is why a gigabit link carries at most 81,274 full-size frames a second, not 82,345.
Notice what's missing. There is no sequence number, no acknowledgment, no retry. If the checksum doesn't match, the receiver silently drops the frame. Ethernet is a best-effort delivery service; recovering from loss is TCP's job, several layers up.
The 64-byte minimum is a fossil from shared coaxial cable. Stations used CSMA/CD (carrier sense, multiple access with collision detection): listen before talking, and if two stations start at once, both detect the collision, stop, and retry after a random wait. For a sender to notice a collision, it had to still be transmitting when the corrupted signal came back from the far end of a maximum-length network. That round trip was budgeted at 512 bit times, or 64 bytes. On today's full-duplex switched links collisions can't happen, but the minimum stayed so old and new gear could interoperate.
The two-byte field after the source address has a split personality. In the original DIX Ethernet it was always a type. IEEE 802.3 first defined it as the payload length. The two coexist through a simple rule: values of 1,500 or less are a length; values of 1,536 (0x0600) or more are an EtherType. Nearly all traffic today uses EtherTypes.
The CRC-32 checksum catches every error that flips an odd number of bits, every burst of errors 32 bits long or shorter, and all but about one in four billion of everything else.
A MAC (media access control) address is 48 bits, written as six bytes in hexadecimal: 00:00:5e:00:53:01, or with dashes on Windows, 00-00-5E-00-53-01. The examples on this page come from a block reserved for documentation, so none of them belong to a real device.
The first three bytes are usually an OUI, an organizationally unique identifier the IEEE Registration Authority assigns to a manufacturer. The manufacturer numbers its devices with the other three bytes. That's how a network tool can look at an address and guess "this is a printer from such-and-such vendor." The OUI list is public.
Two bits in the first byte change the meaning of everything else.
The lowest bit of the first byte is the I/G bit (individual/group). If it's 0, the address names one interface: unicast. If it's 1, it names a group: multicast. Any network card will accept frames for its own unicast address plus whatever groups it has joined. In hex, an odd first byte means multicast.
The next bit up is the U/L bit (universal/local). If it's 0, the address was assigned by the manufacturer from its OUI. If it's 1, it was set locally by software, and the OUI part means nothing. Phones and laptops now use randomized "private" Wi-Fi addresses to make tracking harder, and they set this bit; that's why a randomized address always has 2, 6, A or E as its second hex digit. Virtual machines and VPN adapters also get locally administered addresses.
All 48 bits set, ff:ff:ff:ff:ff:ff, is the broadcast address. Every device on the network accepts a broadcast frame. It's how a computer asks a question when it doesn't yet know whom to ask.
Ethernet transmits each byte least-significant bit first. So the I/G bit, the lowest bit of the first byte, is the very first address bit on the wire. A switch knows whether a frame is unicast or multicast after reading one bit.
IP multicast maps onto Ethernet multicast with fixed prefixes. IPv4 multicast groups use 01:00:5e followed by the low 23 bits of the group address, so mDNS's 224.0.0.251 becomes 01:00:5e:00:00:fb. IPv6 uses 33:33 followed by the low 32 bits of the group: the all-nodes group ff02::1 becomes 33:33:00:00:00:01. Because 5 bits of an IPv4 group address are thrown away, 32 different groups share each MAC address, and the IP layer sorts out the rest.
Type or paste any MAC address in any common format. The decoder reads the two flag bits in the first byte and tells you what kind of address it is.
A hub is a multi-port repeater, a physical-layer device. Bits that come in one port are copied out every other port, immediately and without reading them. Plugging computers into a hub is electrically like attaching them to one shared cable. Everyone hears every frame, and each card throws away frames not addressed to it. Only one device can talk at a time, and if two start together, their signals collide and both must back off and retry. The whole hub is a single collision domain, and its capacity is shared by everyone on it.
A switch is a layer 2 device, formally a multi-port bridge. It reads each frame's destination address and sends it out only the port that leads to that device. Each port is its own segment, normally running full duplex: sending and receiving at the same time on separate wire pairs or fibers. There are no collisions at all, and two pairs of devices can talk through the switch simultaneously, each at full speed.
Hubs are essentially extinct; you'd struggle to buy one. But the hub's behavior is still worth knowing, because a switch falls back to it, one frame at a time, whenever it doesn't know where a destination lives. And Wi-Fi is, in a sense, a hub made of air: every station on a channel hears the same medium, which is why Wi-Fi uses its own collision-avoidance scheme.
Most switches are store-and-forward: they receive the whole frame, check the CRC, and only then send it on, so corrupt frames die at the first switch. Some low-latency switches use cut-through: they start sending as soon as they've read the destination address, saving a few microseconds per hop at the cost of passing on the occasional damaged frame.
Switches also live inside computers. When you create an external virtual switch in Hyper-V, Windows turns the physical network card into an uplink port of a software switch, and the host itself gets a new virtual adapter ("vEthernet") plugged into that switch alongside any virtual machines. A Windows Network Bridge does something similar between two adapters. Both are real layer 2 switches in software, and both add adapters to the machine's list, a detail that matters in the troubleshooting story later on this site.
A brand-new switch knows nothing. Its MAC address table (sometimes called the CAM table, after the content-addressable memory that holds it) starts empty. It fills that table using three simple rules, defined for bridges in IEEE 802.1D and now part of 802.1Q.
Learn. When a frame arrives, look at its source address. Whoever sent it is reachable through the port it came in on. Write that down, with a timestamp.
Forward or filter. Look up the destination address. If the table says it's on another port, send the frame out that port only. If it's on the same port the frame came in on, drop it; the recipient already heard it.
Flood. If the destination isn't in the table, or it's the broadcast address, or a multicast group the switch isn't tracking, send the frame out every port except the one it arrived on. The real recipient will answer, and its reply teaches the switch where it lives.
Entries that go unused age out, by default after 300 seconds. That way the table follows devices that move to a different port and forgets ones that leave. Try it below: watch the first frame flood, the reply go straight back, and the waste disappear as the table fills in.
Flooding has a nasty failure mode. Connect two switches with two cables, for redundancy, and a single broadcast goes out both links, comes back on the other, gets flooded again, and circles forever. Ethernet frames have no hop counter to expire them. Within seconds the links are saturated with copies: a broadcast storm. Meanwhile the switches' tables thrash as the same source address appears on different ports.
The fix is the Spanning Tree Protocol, invented by Radia Perlman at DEC in the 1980s and standardized in 802.1D. Switches exchange small messages, elect a root, and put just enough ports into a blocking state that the active links form a tree with no loops. If a link fails, a blocked port wakes up. The modern Rapid Spanning Tree Protocol (originally 802.1w) reconverges in about a second or less.
Tables are finite, too. A switch holding a few thousand entries can be overwhelmed by a flood of frames from made-up source addresses; once it's full, it floods traffic it can't place, turning itself into a hub that an attacker can eavesdrop on. Managed switches can limit how many addresses a port may learn.
Six hosts on six ports. Pick a sender and a receiver and send a frame. The switch's MAC table is shown live. Flip to a hub to compare, or split the ports into two VLANs.
Every copy that reaches a host the frame wasn't for is wasted bandwidth that host had to read and discard.
The set of devices that hear each other's broadcasts is a broadcast domain. A switch extends it: a broadcast in one port floods out all the others, and on to every switch beyond. Routers end it. A router does not forward Ethernet broadcasts from one network to another, which is one of the main reasons networks are carved into subnets at all.
Broadcasts are necessary (ARP and DHCP both depend on them), but they're a tax. Every device has to stop and look at every one. On a flat network of thousands of machines, the background chatter becomes real load. Big flat networks are also a security problem: anything on them can talk directly to anything else.
A VLAN (virtual LAN) splits one physical switch into several logical ones. Assign ports 1 to 12 to VLAN 10 and ports 13 to 24 to VLAN 20, and the switch behaves exactly as if it were two separate switches. Frames, broadcasts included, never cross from one VLAN to the other. To get between them you need a router, just as if they were separate buildings. Homes rarely bother; offices, hospitals and data centers use VLANs everywhere, to keep phones, cameras, guests and servers apart.
To carry several VLANs over one cable between switches, frames on that trunk link get a 4-byte 802.1Q tag inserted right after the source address. Ports facing ordinary devices are access ports: the switch adds the tag on the way in and strips it on the way out, so the device never knows.
| 802.1Q tag field | Bits | Meaning |
|---|---|---|
| TPID | 16 | Always 0x8100. Sits where the EtherType would be, announcing "tag follows." |
| PCP | 3 | Priority code point, 0–7, for quality of service (voice before bulk data). |
| DEI | 1 | Drop eligible indicator: discard this one first under congestion. |
| VID | 12 | The VLAN number, 1–4094. 0 means "priority only, no VLAN"; 4095 is reserved. |
A trunk port usually has one native VLAN whose frames cross untagged, for compatibility with devices that don't understand tags. Mismatched native VLANs on two ends of a trunk quietly merge two VLANs, a classic misconfiguration.
The tag adds 4 bytes, so a tagged frame can be 1,522 bytes long while still carrying a full 1,500-byte payload. The original EtherType moves to just after the tag. Some networks stack two tags (802.1ad "Q-in-Q") so a carrier can wrap customers' VLANs inside its own.
Here's the gap between layers. Your laptop wants to send an IP packet to 192.168.86.30 on the same network. To put it on the wire, it needs an Ethernet frame, and a frame needs the destination's MAC address. The laptop knows the IP address. How does it learn the MAC?
It asks, using the Address Resolution Protocol, defined in 1982 in RFC 826. The laptop broadcasts an ARP request to ff:ff:ff:ff:ff:ff, EtherType 0x0806: "Who has 192.168.86.30? Tell 192.168.86.20," with its own MAC address enclosed. Every device on the broadcast domain receives it. Only the one that owns 192.168.86.30 answers, with an ARP reply sent straight back as unicast: "192.168.86.30 is at 00:00:5e:00:53:1e."
Both sides now remember. The asker stores the answer in its ARP cache, and the target stores the asker's address too, since a reply is almost certainly about to be needed. The next thousands of packets go out without asking again. Entries expire after a while (from tens of seconds to a few minutes, depending on the operating system) so stale answers don't linger. You can see your own cache with arp -a on Windows and macOS, or ip neigh on Linux.
The crucial twist: if the destination is not on the local network, the laptop never ARPs for it at all. A server at 203.0.113.50 is somewhere across the internet; no device on this LAN will answer for it. Instead the laptop ARPs for its default gateway, the router, and sends the frame to the router's MAC address with the server's IP address inside. The IP header says where the packet is ultimately going; the Ethernet header says only who should take it next. Chapter 3 shows how the laptop decides which case it's in.
A device can announce itself with a gratuitous ARP, a request for its own address. It's used when an interface comes up, to refresh everyone's caches after a failover, and, under RFC 5227, to probe whether an address is already taken before using it.
ARP has no authentication whatsoever. Any device can send a reply claiming to be the gateway, and hosts will usually believe it. That's ARP spoofing, the oldest man-in-the-middle trick on a LAN. Managed switches defend against it with "dynamic ARP inspection," which checks replies against known DHCP leases. It's one more reason to encrypt traffic end to end.
IPv6 doesn't use ARP. It uses Neighbor Discovery (RFC 4861), which does the same job with ICMPv6 messages sent to a multicast group derived from the target address, so only a handful of devices have to look at each question instead of everyone.
A home network at 192.168.86.0/24 with a router at 192.168.86.1. Pick who's sending and where to, then step through. Try an internet server as the destination, and try the same pair twice to see the cache hit.
The largest payload a standard Ethernet frame carries is 1,500 bytes. That's the MTU, and almost every network path on the internet is built around it. Anything bigger has to be split into several packets before it reaches the link layer.
Why 1,500? It was a compromise in the original Ethernet specification, balancing the memory that buffering a frame cost in the late 1970s against the overhead of small frames. Bigger frames would save a little header overhead today, and many data-center networks use jumbo frames of about 9,000 bytes internally. But jumbo frames were never part of the IEEE standard, every device on the path must agree on the size, and the public internet has never moved off 1,500.
MTU problems are sneaky. Tunnels and VPNs wrap each packet in extra headers, so the packet inside must be smaller. WireGuard's tools default to an MTU of 1,420 on the tunnel interface; Tailscale uses 1,280, the smallest MTU IPv6 allows, so its packets fit through nearly any path. If a packet is too big for some link and the "too big" error message gets blocked by a firewall along the way, small requests work and large responses vanish. Web pages half-load; SSH connects but hangs. That's a PMTU black hole, and Chapter 13 shows how to find one.
| Device | Layer | Reads | Sends a frame to | Boundary it creates |
|---|---|---|---|---|
| Hub | 1 Physical | Nothing; copies bits | Every other port | None |
| Switch | 2 Data link | Destination MAC | The one port in its table, or all if unknown | Collision domain per port |
| Router | 3 Network | Destination IP | The next hop on the best route, with a new Ethernet header | Broadcast domain per interface |