1What a switch actually does
This is your copy to keep. The gold Going deeper boxes go past what the session covers, for anyone sitting the CompTIA Network+ exam or who wants the fuller picture.
A switch connects the devices inside one office and moves traffic between them. It
does that using the MAC address, short for media access control address. A MAC
address is the 48-bit hardware address set in every network interface at manufacture, written as six
pairs of hexadecimal digits, such as 00:1A:2B:3C:4D:5E. A switch never looks at IP
addresses. It only reads the hardware addresses on each frame, the name for a unit of
data as it crosses one local network.
It keeps a table pairing each hardware address with the port it was last heard on, called the MAC address table, and it builds that table by itself.
- A frame arrives on port 4. The switch reads the source address on it and writes down that this address lives on port 4. That is the only way a switch ever learns anything.
- The switch reads the destination address. If it is already in the table, the frame goes out that one port and no other port sees it.
- If the destination is not in the table, the switch sends the frame out every port except the one it arrived on. This is called flooding, and it is a guess that works: the right device answers, and the answer teaches the switch where that device is, so the next frame is not flooded.
Nothing configures this and nothing maintains it. Entries age out after a period of silence and are relearned when the device speaks again. That is why a machine that has been asleep is briefly flooded to when it wakes, and stops being flooded to as soon as the switch relearns its port.
2The broadcast domain
Some frames are addressed to every device at once. A broadcast is a frame sent to
the special destination FF:FF:FF:FF:FF:FF, and a switch always floods it out every port.
The set of devices that receive each other's broadcasts is called the broadcast
domain.
Broadcasts are not an edge case. They are how normal work gets done.
- A device that knows an IP address on its own network but not the matching hardware address broadcasts "who has 192.168.10.10" and the owner answers. That is ARP (Address Resolution Protocol), and it happens before nearly every conversation.
- A device with no address at all broadcasts to ask for one, because it has no address to send from and nowhere specific to send to.
- Printers, phones and media devices announce themselves by broadcast so other devices can find them without being told an address.
One switch with nothing configured is one broadcast domain, and every device on it hears every one of those. That is fine at ten devices. At two hundred it becomes traffic every machine has to process and discard, and it means the guest laptop in reception hears the same discovery traffic as the server. Splitting the broadcast domain is what the rest of this session is about.
3What a VLAN changes
A VLAN (virtual local area network) divides one physical switch into separate networks by configuration. Ports 1 to 12 can be the staff network and ports 13 to 24 the guest network, on the same switch, with no traffic crossing between them and nothing physical marking the difference.
What a VLAN actually does is narrow: it makes one broadcast domain into several. A broadcast sent by a device on the staff VLAN reaches only the ports on the staff VLAN. The switch treats the two groups as if they were two separate switches that happen to share a chassis.
Everything else follows from that one change. Two devices on different VLANs cannot find each other by ARP, so they cannot reach each other directly, so anything between them has to be carried by a router, which means a rule can be applied to it. That is the reason cameras, guest Wi-Fi and phones go on their own VLANs: separation is the point, and the router is the only door between them.
The way the switch keeps track is a tag, defined by the standard IEEE 802.1Q. The switch inserts four extra bytes into the frame, and twelve of those bits hold the VLAN number, which gives 4,094 usable VLAN numbers. A tagged frame is only tagged while it is travelling between network equipment. The tag is removed before the frame is handed to a workstation, which is why a device never knows or cares what VLAN it is on.
A VLAN is a layer 2 boundary: who hears whose broadcasts. A subnet is a layer 3 range of addresses. They are separate ideas and they always travel together, one subnet per VLAN, because a device can only reach its neighbors directly and the VLAN is what decides who its neighbors are. When documentation says "VLAN 20 is 192.168.20.0/24", it is naming both halves of the same network: the tag number and the address range.
4Access ports and trunk ports
Every switch port is configured one of two ways, and the difference is only about tags.
An access port
Carries one VLAN, untagged. A workstation, a printer or a camera plugs in, sends ordinary untagged frames, and the switch adds the port's VLAN internally. The device never sees a tag and needs no configuration.
Most ports in a building are access ports.
A trunk port
Carries several VLANs at once, tagged, so the equipment at the other end can tell them apart. It is used between a switch and another switch, between a switch and the gateway, and between a switch and an access point that broadcasts more than one wireless network.
Without trunk ports, a VLAN would stop at the edge of one switch.
In the UniFi console both are set on the same two fields on the port.
| Setting | Access port | Trunk port |
|---|---|---|
| Native VLAN / Network | The one VLAN the device is on. Frames leave untagged. | The VLAN used for untagged frames on that link, usually the management network. |
| Tagged VLAN Management | Block All. Only the native VLAN passes, so a device cannot reach any other VLAN by sending its own tags. | Allow All, or Custom to name the specific VLANs that may cross. |
Two practical points come out of those settings. Setting Block All on user ports is what stops a device from tagging its own frames and placing itself on a VLAN it was not given. And on a port feeding an access point, the native VLAN should not be the same as a network the access point is broadcasting, because the access point needs that network tagged in order to keep it separate.
5Power over Ethernet
PoE (Power over Ethernet) sends electrical power down the same cable as the data, so a phone, a camera or an access point needs no separate power supply. The switch is the power source, and how much it can deliver depends on which standard the port supports.
| Standard | Common name | Maximum at the switch port | Typically powers |
|---|---|---|---|
| IEEE 802.3af | PoE | 15.4 W | Desk phones, older access points |
| IEEE 802.3at | PoE+ | 30 W | Most access points, pan-tilt-zoom cameras |
| IEEE 802.3bt type 3 | PoE++ | 60 W | Larger access points, some displays |
| IEEE 802.3bt type 4 | PoE++ | 100 W | Powered devices at the top of the range |
What reaches the device is less than the figure at the port, because some is lost as heat in the cable. The longer the run, the more is lost, which is why a device can work on a short cable and fail on a long one with no fault anywhere.
A switch also has a total power budget across all its ports, and that budget is usually smaller than the sum of every port at its maximum. A switch at its budget stops powering further devices. The symptom is a device that will not come up on a port that tests fine, and the place to look is the switch's own power figure rather than the cable.
6Loops, and what stops them
Plug a cable from one switch port into another port on the same switch, or wire two switches to each other twice, and you have made a loop. A broadcast now goes round it forever, because a frame crossing a local network carries nothing that counts hops and nothing that expires. Each pass floods it again, the traffic doubles each time round, and within seconds the switch is saturated. This is a broadcast storm, and the symptom is the entire site failing at once with no configuration change to explain it.
What prevents it is spanning tree, a protocol the switches run between themselves that finds loops in the wiring and deliberately blocks one port in each loop until it is needed. The blocked port carries nothing while the main path is healthy and takes over if it fails. Spanning tree is on by default on managed switches, which is why loops are far more often survived than fatal.
Two things follow for the job. A port that shows as blocking is usually spanning tree doing its job rather than a fault. And an unmanaged desk switch a user brought from home does not run spanning tree, so a loop created through one is not caught, which is the most common way a site takes a storm.
7Diagnosing at layer 2
Layer 2 faults share a shape: the cable is fine, the device has power and a link light, and it still reaches nothing or reaches the wrong things. Four causes cover nearly all of them.
| Symptom | Likely cause | What to check |
|---|---|---|
| Link light on, no address, reaches nothing | Port on the wrong VLAN, or on a VLAN with no addressing service | The port's native VLAN in the console against the site's addressing scheme |
| Device reaches its own network but not the others it should | Tagged VLAN management blocking a VLAN the device needs | Whether the port is Allow All or Custom, and which VLANs the Custom list names |
| One access point broadcasts some networks and not others | The port feeding it is an access port, or its custom list is missing a VLAN | That the port is a trunk and that every broadcast network's VLAN is allowed on it |
| Whole site slow or down at once, nothing changed | A loop, often through equipment somebody plugged in | Switch port statistics for a port passing far more traffic than the rest, and any switch not in the documentation |
Reading the MAC address table
The table is the switch telling you where it believes each device is, and it settles questions nothing else can.
- A device that appears on the port you expect proves the cabling and the port are working, whatever the user is reporting.
- A device that appears on a different port than the documentation says means the documentation is wrong or somebody moved the cable.
- A device that does not appear at all has sent nothing the switch has heard, which puts the fault at the cable, the port, or the device itself rather than anywhere above.
- Many addresses on one port is normal and means another switch or an access point is there, not a fault.
One more fault belongs here because it looks like a wiring problem and is not. Two ends of a link have to agree on speed and on duplex, meaning whether they can send and receive at the same time. If one end is fixed and the other is negotiating, they can settle on different answers. The link comes up, small transfers work, and anything sustained collapses with errors counting up on the port. The fix is to have both ends negotiate, and the tell is the error counter on the port rather than anything the user can describe.
8Practice
- Open a site in the UniFi console and find its list of networks. Write down each VLAN number and the subnet that goes with it.
- Open a switch at that site and look at its ports. Find one access port and one trunk port, and say how you can tell which is which from the two settings named in section 4.
- Find the port feeding an access point. Confirm it is a trunk and that every VLAN the access point broadcasts is allowed on it.
- Find the switch's MAC address table and look up your own machine's hardware address in it. Confirm the port it names is the port you are actually plugged into.
- Find the switch's PoE figure: how much power it is delivering and what its budget is. Say how much headroom is left and how many more access points that would cover at 30 W each.
9Check for understanding
A switch receives a frame for a hardware address that is not in its table. What does it do, and what happens next that means it will not have to do the same thing again?
Explain in one sentence each what a VLAN changes and what it does not change.
A printer is moved to a port whose native VLAN is 30, the guest network, while the staff machines are on VLAN 10. The printer gets an address and its link light is on. Can staff print to it? Explain.
An access point broadcasts a staff network and a guest network. Staff connect fine and guest clients get no address at all. The access point shows as healthy. Where do you look first, and what are you looking for?
A camera works on a short patch lead at the rack and will not power on at its permanent position. The port tests fine and the switch shows plenty of power budget left. What is the likely cause?
A site goes down completely at 9:15 in the morning. No changes were made, and the switch is still reachable from the console. What do you suspect, what would confirm it, and why is the timing a clue rather than a coincidence?
10Before the next session
- Do the practice steps in section 8 on a real site, and bring the VLAN and subnet list you wrote down.
- Be able to state the two port settings and what each is set to for an access port and for a trunk port.
- Read the Network+ companion, chapter 3, the sections on networking devices and structured cabling.
Next session. 04 - Routing and Gateways. How traffic gets from one of these VLANs to another, and what the routing table is telling you.
11Glossary
- Switch
- The device connecting machines inside one local network, forwarding by hardware address.
- MAC address
- Media access control address. The 48-bit hardware address set in a network interface at manufacture, written as six pairs of hexadecimal digits.
- Frame
- A unit of data as it crosses one local network, carrying hardware addresses.
- MAC address table
- The switch's record of which hardware address was last heard on which port.
- Flooding
- Sending a frame out every port except the one it arrived on, because the destination is not yet in the table.
- Broadcast
- A frame addressed to every device on the local network at once.
- Broadcast domain
- The set of devices that receive each other's broadcasts.
- ARP
- Address Resolution Protocol. Finds the hardware address matching a known IP address on the local network, by broadcast.
- VLAN
- Virtual local area network. One physical switch divided into separate broadcast domains by configuration.
- Tag
- Four bytes added to a frame under IEEE 802.1Q, twelve bits of which hold the VLAN number.
- Access port
- A switch port carrying one VLAN, untagged, for an end device.
- Trunk port
- A switch port carrying several VLANs at once, tagged, between pieces of network equipment.
- Native VLAN
- The VLAN a port uses for untagged frames.
- PoE
- Power over Ethernet. Electrical power carried on the same cable as the data.
- Power budget
- The total power a switch can deliver across all its ports at once.
- Loop
- A wiring path that lets a frame return to where it started, so a broadcast circulates without end.
- Broadcast storm
- The saturation that follows a loop, as circulating broadcasts multiply.
- Spanning tree
- The protocol switches run between themselves to find loops and block a port in each one until it is needed.
- Duplex
- Whether a link can send and receive at the same time. Both ends must agree, or the link works for small transfers and fails for sustained ones.
12Sources
- IEEE, 802.1Q, Bridges and Bridged Networks, for VLAN tagging and the 12-bit VLAN identifier.
- IEEE, 802.1D and 802.1Q, for spanning tree.
- Ubiquiti, Intro to Networking, Power over Ethernet, for the power available at the switch port under each standard.
- Ubiquiti, Switch Port VLAN Assignment (Trunk and Access Ports), for the Native VLAN and Tagged VLAN Management settings and the access point note.
- Ubiquiti, Virtual Network (VLAN) Troubleshooting.
- Kodi A. Cochran, CompTIA Network+ (N10-009) Certification Companion (Apress, 2026), chapter 3, networking devices and structured cabling.