MAC Address Learning Simulator — Ethernet Switch Forwarding & Aging Interactive

Interactive Ethernet switch MAC-learning simulator with a 3D four-port switch cutaway workbench, source learning, unknown-unicast flooding, broadcast forwarding, dynamic-entry aging and shared-segment filtering, curves & measurements, guided experiments, a model-verification bench and a knowledge-check quiz.

← Networking Labs
About this tool — how it works & FAQOpen ▾Close ▴

About the MAC Address Learning Simulator

This simulator models a four-port managed Ethernet switch learning host locations from the source address of incoming frames, and forwarding by looking up the destination address in its dynamic forwarding table. Choose a source and destination host, move Host A onto a shared segment with Host D, adjust the dynamic-entry aging time, and send test frames to watch exactly which ports receive a copy and why.

What the simulator shows

• A real-time 3D cutaway workbench of the four-port managed Ethernet switch, its switch ASIC and forwarding memory, and Hosts A, B, C and D — including A's movable patch lead — with home view, focus-selected-part, toggleable full-enclosure view, exploded view, auto-rotate and expand controls, tappable numbered components with callouts, and labels matching a companion diagram. • Six live controls: source host (A/B/C/D), destination (A/B/C/D/broadcast), dynamic forwarding-entry aging time, Host A's connection (port 1, or port 4 sharing a segment with Host D), periodic test-traffic toggle and traffic interval. • Play/pause, single-step (0.1 s) and larger-step (1 s) time controls, plus a playback-speed selector (10x slow motion, real time, 10x faster, 1 minute per second). • Three trial actions: start trial, stop trial, send test traffic and clear dynamic MAC table, with a live "what is happening" sequence narrative, forwarding-table tokens (including "generated" and "unknown" states) and a scrollable forwarding-table readout. • Six live metrics: learned address-table entries, last egress port copies, frames injected, frames reaching the intended target, frames not reaching the target and total egress copies made. • A Curves & measurements tab with a learned-entries-over-time chart, a sent/copies chart, the full model equations and snapshot measurements. • An Experiments tab with four guided scenarios (first unknown unicast flooding three copies, broadcast to every non-ingress port, fast aging that expires a five-second-old entry, and a shared-segment same-port-filtering case), an automated model-verification bench of independent checks, and a timestamped event log with a copyable trial report. • A Learn & assess tab with four guided lessons, a two-question knowledge-check quiz and a written scope/reference statement.

How source learning and destination lookup stay separate

Every incoming frame teaches the switch one thing: it records the frame's source MAC address against the ingress port and the current time, updating the forwarding database (FDB) regardless of where the frame is ultimately sent. Separately, the switch looks up the destination MAC to decide where to forward — an unknown destination (never learned, including the very first frame from any host) or a broadcast destination floods out every port except the ingress port, generating one copy per remaining port.

Because learning and lookup are independent operations, a switch can flood a frame toward a destination it has not yet learned even while correctly learning the source at the same time — the "first unknown unicast" experiment shows exactly this: sending A to B before B has ever transmitted creates only A's table entry (not B's) and produces three flooded copies, since the destination is still unknown.

Aging, moves and the shared-segment edge case

The model equations state FDB[source] = (ingress port, last-seen time), that unknown or broadcast egress equals all ports minus the ingress port, that a known destination reached on its own ingress port is filtered (not forwarded back out the port it arrived on), and that an entry expires once elapsed time since it was last seen reaches the configured aging time. A host that physically moves to a different port does not update the switch's table until a frame actually arrives from that host on the new port — until then, or until the old entry ages out, traffic can be misdirected to the stale location.

The shared-segment experiment moves Host A onto port 4, the same physical port used by Host D, to demonstrate same-port filtering: once D is taught, a frame from A toward D on that shared ingress port is filtered rather than forwarded, since the destination is reachable on the same port the frame arrived on. This is a single, no-VLAN broadcast domain: there is no multicast snooping, VLAN tagging, link-negotiation modeling or frame serialization delay, and delivery to a target on the same segment that needs no switch forwarding is excluded from the delivered-frame count.

Frequently asked questions

Why does sending a frame from A to B only create one table entry, not two?

Source learning and destination lookup are separate steps. The switch learns only the source address of an incoming frame — sending from A teaches the switch where A is. It does not learn anything about B just because B is the destination; B's entry is only created once B itself transmits a frame that the switch receives.

Why does the switch flood a frame to every port instead of sending it directly?

Flooding happens whenever the destination address is not yet in the forwarding table (unknown unicast) or the destination is a broadcast address. In both cases the switch forwards a copy out every port except the one the frame arrived on, because it has no learned location to send it to directly.

What happens if a host moves to a different switch port?

The switch does not know a host has moved until it actually receives a frame sourced from that host on its new port. Until a new frame arrives — or the old table entry expires via aging — traffic destined for that host may still be forwarded to its previous, now-stale port location.

What does this MAC-learning model not simulate?

It models a single, no-VLAN broadcast domain on a four-port switch. It excludes multicast snooping, VLAN tagging, link-negotiation timing and frame serialization delay, and delivery counts exclude same-segment traffic that would never need switch forwarding in the first place. All traffic and addressing are simulated locally.

Related tools & guides