LTLnetworker | IT hálózatok, biztonság, Cisco

               IT networks, security, Cisco

Archive for October, 2014

Why is this huge traffic appearing here? Unknown unicast flood

Posted by LTLnetworker on October 5, 2014


Switches usually forward unicast frames to the necessary direction only. Selecting the egress port depends on the MAC address table that is populated by MAC learning. The switch has a chance to learn an address and keep it in the table only if frames are sent from that address regularly. Cisco switches’ default aging time is 300 s, a MAC address is dropped from the table if no frames arrive for 5 minutes.

Unknown unicast flood occurs if traffic is sent to a MAC address which was
a) never learned
b) already aged out
from the MAC address table. In this case, the frame is flooded out on all ports belonging to the VLAN just like a broadcast.
Read the rest of this entry »

Posted in Cisco, switch | Tagged: , | Leave a Comment »