CHAPTER 02 30 MIN READ BEGINNER

Routing, Switching & VLANs

The previous chapter covered addressing in theory: how IP addresses, subnets, and the OSI layers are supposed to fit together on paper. This chapter is about what actually moves a frame off one device's network card and onto another's. Switches and routers make thousands of forwarding decisions a second, and every one of those decisions is a place where traffic can be seen, redirected, or manipulated. Understanding how a switch learns a MAC address, how a router picks a next hop, and how VLANs carve up a single physical network is what turns "the attacker pivoted laterally" from a vague phrase into something you can actually picture happening on the wire.

routing switching VLANs

How Switches Forward Frames

A switch operates at Layer 2 and makes every forwarding decision based on MAC addresses, not IP addresses. At the center of that decision is the MAC address table, sometimes called a CAM (Content Addressable Memory) table, which maps MAC addresses to the physical switch port they were last seen on. When a switch first powers on, this table is empty. It builds the table dynamically by watching traffic, not by being configured with it.

How a Switch Learns MAC Addresses

The learning process is simple and constant, and it repeats for every frame the switch sees.

  1. A frame arrives on a port. The switch reads the source MAC address in the frame header.
  2. It records the mapping. If host A on port 3 sends a frame, the switch stores "MAC address of host A lives on port 3" in the table, along with a timestamp, and uses that entry for any future frame addressed to host A.
  3. The entry ages out if unused. Entries that go unused typically age out after a few minutes, which is why a switch relearns a MAC's location if a device moves to a different port or a different device is plugged in with the same address.

Forwarding: Known vs Unknown Destinations

Forwarding is the other half of the job, and it depends on whether the destination MAC is already known. If the switch has an entry for the destination MAC, it forwards the frame out that single port only, a behavior called unicast forwarding. If the destination MAC is not in the table yet, the switch does not know where to send it, so it floods the frame out every port except the one it arrived on.

Every connected device evaluates the flooded frame, and whichever one owns that MAC address responds, which lets the switch learn the mapping for next time. Broadcast frames (destination FF:FF:FF:FF:FF:FF) and multicast frames are always flooded by design, regardless of whether the switch has learned anything.

Switches vs Hubs

This flooding behavior is also what separates a switch from a hub in the way that actually matters for security. A hub has no MAC table at all; it repeats every incoming signal out every other port, all the time, which means any device on a hub can passively see all traffic on the segment. A switch, once it has learned where hosts live, sends unicast traffic only to the port that host is on.

Each switch port is its own collision domain, so two hosts on different ports of the same switch can transmit at the same time without their signals colliding, something that was a real constraint on shared hub segments. This is also why plugging a packet sniffer into a switch port does not automatically show you everyone else's traffic the way it would on a hub. Getting that visibility back is exactly what techniques like ARP spoofing and port mirroring are for, and both come up later in this chapter and this module.

ARP: Mapping IP to MAC

IP addresses get a packet to the right network, but a switch has no idea what an IP address is; it only understands MAC addresses. Something has to translate between the two, and on IPv4 networks that something is the Address Resolution Protocol (ARP). Whenever a host needs to send a frame to another device on the same local network and does not already know that device's MAC address, it runs an ARP exchange first.

The ARP Exchange, Step by Step

  1. The sending host broadcasts an ARP request. It asks the entire local network segment, effectively "who has IP address 10.0.0.15, tell 10.0.0.10," sent to FF:FF:FF:FF:FF:FF so every device on the segment receives it.
  2. Only the owner responds. The device that actually holds 10.0.0.15 sends back a unicast ARP reply directly to the requester, containing its MAC address.
  3. The requester uses the answer. The original host now has what it needs to build a proper Ethernet frame and starts talking directly to that MAC address.

Why the ARP Cache Exists

Running a fresh ARP exchange for every single packet would be wasteful, so operating systems cache the results in an ARP table (viewable on most systems with arp -a). Entries stay cached for a short window, commonly somewhere between a couple of minutes and a few hours depending on the OS, and get refreshed or expired as needed. This cache is what makes normal traffic fast, and it is also exactly what an attacker targets to intercept traffic.

The Trust Gap: No Authentication

ARP has no built-in authentication. Any device on the local segment can send an ARP reply, whether or not it was actually asked, and most operating systems will accept an unsolicited reply and update their cache with it.

That gap is the entire basis for ARP spoofing, also called ARP poisoning: an attacker sends forged ARP replies telling a victim that the attacker's own MAC address corresponds to, say, the default gateway's IP. The victim updates its ARP cache and starts sending its gateway-bound traffic straight to the attacker, who can then read it, alter it, or just forward it along so the victim never notices anything changed. This is the foundational Layer 2 man-in-the-middle technique, and later chapters in this module build directly on it when covering traffic interception and detection.

Why this matters: ARP trusts whatever answer arrives first and never verifies it against anything. That single design gap is why ARP spoofing has remained effective for decades on any network that has not deployed specific countermeasures like dynamic ARP inspection.

How Routers Forward Packets

A router operates at Layer 3 and forwards packets between different networks based on IP addresses, using a routing table to decide where each packet should go next. The routing table lists known destination networks, each paired with the next hop to reach them and the exit interface to use. Unlike a switch's MAC table, which maps individual devices, a routing table maps entire networks or subnets, which is what lets a single table entry cover thousands of possible destination addresses.

The Default Gateway

Every host on a network is configured with a default gateway, which is simply the IP address of the router that handles traffic destined for anything outside the local subnet. When a host wants to reach an address it determines is not on its own network, it does not try to ARP for that remote address directly; it ARPs for the default gateway's MAC address instead, and sends the packet there. The router receives it and takes over from that point.

The Forwarding Decision, Hop by Hop

Once a packet lands on a router, the forwarding decision is a lookup, not a full path calculation.

  1. Examine the destination IP. The router reads the destination address on the incoming packet.
  2. Match against the routing table. It compares that address against the entries in its routing table and picks the most specific matching route, a principle known as longest prefix match.
  3. Rewrite and forward. It rewrites the Layer 2 header and forwards the packet out the appropriate interface toward the next hop. Its job for that packet is done.

The next router in the chain repeats the exact same process independently: examine the destination, check its own table, forward one hop closer. No single router needs to know the entire end-to-end path; the packet gets there through a sequence of independent, local decisions, one hop at a time.

Static vs Dynamic Routing

Routing tables get built in one of two ways.

MethodHow Routes Get AddedTradeoff
Static routingAn administrator manually enters specific routesPredictable and easy to audit, but does not adapt if a link goes down
Dynamic routingRouters exchange information about known networks via a routing protocol and recalculate automaticallyAdapts when the topology changes, but depends on trusting what other routers advertise

OSPF (Open Shortest Path First) is a common choice inside a single organization's network, while BGP (Border Gateway Protocol) is what routes traffic between organizations and is the protocol that effectively holds the internet together. Neither protocol needs a deep dive here; what matters for now is that "the routing table" is not always hand-built, and misconfigured or maliciously injected dynamic routes are their own category of attack.

VLAN Segmentation

A VLAN, or Virtual LAN, is a way of splitting one physical switch into multiple logically separate networks. Ports on the same physical switch can be assigned to different VLANs, and traffic on one VLAN is invisible to devices on another VLAN even though they share the exact same hardware. To the devices involved, each VLAN behaves like its own independent Ethernet segment, with its own broadcast traffic and its own address space, despite the underlying cabling and switch chassis being shared infrastructure.

Quick glossary, keep these four straight:
  • VLAN: a logically separate network carved out of one physical switch.
  • Trunk link: a link between switches that carries traffic for many VLANs at once.
  • 802.1Q tag: the field inserted into a frame header that records which VLAN it belongs to.
  • Access port: a port connected to an end device, where tagging is added and removed transparently.

Trunking and 802.1Q Tagging

VLAN separation matters most when traffic needs to cross between switches while staying separate. A single trunk link connecting two switches needs to carry traffic for many VLANs at once, and the 802.1Q standard makes that possible.

  1. The sending switch tags the frame. It inserts a small VLAN tag into the Ethernet frame header, recording which VLAN the frame belongs to.
  2. The tagged frame crosses the trunk. The trunk link carries frames for every VLAN configured on it, each marked with its own tag.
  3. The receiving switch reads and strips the tag. It delivers the frame only to ports that belong to that same VLAN.

Ports connected to end devices are normally configured as access ports, which do not see the tag at all; the switch adds and removes it transparently on their behalf.

Why VLANs Matter for Security

The practical effect of VLANs is that they create separate broadcast domains on shared hardware. Without VLANs, every device plugged into a switch (or a chain of switches) sits in one broadcast domain, meaning ARP requests, DHCP discovery packets, and other broadcast traffic reach every single device on that switch fabric. That is both a performance problem at scale and, more importantly for this module, a visibility and access problem.

Put a workstation VLAN, a server VLAN, and a guest wifi VLAN on the same physical switches but keep them as separate VLANs, and a broadcast on the guest network never reaches the server VLAN at all. Communication between VLANs has to go through a router or a Layer 3 switch, which means it can be filtered, logged, and controlled the same way traffic between two entirely separate networks would be.

Flat Networks and Lateral Movement

A flat network is one where most or all devices sit in a single broadcast domain with little or no segmentation between them: workstations, servers, printers, IoT devices, and guest laptops all reachable from each other with no router or firewall in between. Flat networks are common in smaller organizations and in older infrastructure that grew organically without a segmentation plan. They are one of the single biggest force multipliers available to an attacker who lands on one host.

How an Attacker Exploits One

Once an attacker has code execution on any device inside a flat network, whether through phishing, an exposed service, or a compromised credential, that device can reach every other device on the same broadcast domain by design, with nothing to stop it. The attacker can ARP-scan the subnet to enumerate live hosts in seconds, connect directly to file shares, RDP, SSH, or database ports on any of them, and pivot from a low-value workstation straight to a domain controller or a database server if that server happens to sit on the same segment.

None of this requires exploiting anything sophisticated; a flat network simply never made the attacker work for that access in the first place. Internal reconnaissance that would normally take days of careful probing against segmented, filtered networks can take minutes.

VLANs and ACLs as the Defense

VLAN segmentation combined with access control lists (ACLs) is the concrete, well understood defense against this. Splitting hosts into VLANs by function and by trust level (user workstations, servers, management interfaces, guest access, IoT devices) forces all inter-segment traffic through a router or Layer 3 switch instead of allowing direct Layer 2 reachability.

ACLs applied at that routing boundary then decide exactly which traffic is allowed to cross between segments: a workstation VLAN might be allowed to reach a specific application server on its listening port and nothing else, with everything else dropped and logged. An attacker who compromises a workstation in that scenario is contained to what the workstation itself was ever allowed to reach, which is a very different outcome than free rein over the entire network.

Concrete example: A finance workstation and a domain controller sitting in the same flat VLAN means a single phishing click on the workstation can be followed, minutes later, by a direct SMB connection to the domain controller. Put the workstation in a user VLAN and the domain controller in a locked-down server VLAN with an ACL permitting only specific, necessary ports between them, and that same phishing click gets the attacker one workstation, not a path to the domain.

Common Attacks at This Layer

VLAN Hopping

VLAN hopping is an attempt to send traffic into a VLAN the attacker's port was never assigned to. The double tagging variant relies on a misconfigured trunk: the attacker crafts a frame with two 802.1Q tags stacked on top of each other, and a switch that strips only the outer tag before forwarding ends up delivering the frame into the VLAN named in the inner tag. It works reliably only when an attacker's access port happens to sit on the same VLAN as the trunk's native VLAN, which is exactly why leaving devices on the default native VLAN is a well known misconfiguration to avoid.

Switch spoofing is a second VLAN hopping technique where an attacker's device negotiates a trunk link with the switch by mimicking trunking protocols like DTP (Dynamic Trunking Protocol), turning what should be a restricted access port into a trunk that carries every VLAN.

ARP Spoofing

ARP spoofing, introduced earlier in this chapter, is the practical workhorse man-in-the-middle technique at this layer. An attacker on the local segment continuously sends forged ARP replies to poison the cache of a target and often the default gateway as well, positioning themselves to intercept, inspect, or modify traffic between the two without either side noticing a change in behavior. It requires the attacker to already have a foothold on the local broadcast domain, which is one more reason flat networks are so much more exposed than segmented ones.

Rogue DHCP Servers

A rogue DHCP server is an unauthorized device that answers DHCP discovery broadcasts on the network, racing the legitimate DHCP server to respond first. Whichever DHCP offer a client accepts determines its IP address, subnet mask, DNS servers, and default gateway, so a rogue server that wins that race can hand out its own IP as the default gateway or DNS server, silently routing a victim's traffic through attacker-controlled infrastructure for interception. It requires no credentials and no exploit, only presence on the segment and a faster reply than the real server.

AttackMechanismTypical Detection Signal
VLAN hopping (double tagging)Stacked 802.1Q tags exploit native VLAN trunk handlingFrames with unexpected nested VLAN tags; traffic appearing on a VLAN with no legitimate source
VLAN hopping (switch spoofing)Attacker negotiates a trunk via DTP on an access portUnexpected DTP negotiation attempts; trunk forming on a port configured for a single host
ARP spoofing / poisoningForged, unsolicited ARP replies redirect traffic through the attackerDuplicate or conflicting MAC-to-IP mappings; gratuitous ARP floods; ARP inspection alerts
Rogue DHCP serverUnauthorized device wins the DHCP offer race and controls handed-out configMultiple DHCP servers answering the same discovery broadcast; clients receiving unexpected gateway/DNS values

Key Takeaways

  • Switches forward frames using a dynamically learned MAC address table, flooding out every port only when a destination is not yet known.
  • ARP maps IP addresses to MAC addresses through a broadcast request and unicast reply, but it has no authentication, which is what makes ARP spoofing possible.
  • Routers forward packets hop by hop using longest prefix match against a routing table, built either statically or dynamically through protocols like OSPF and BGP.
  • VLANs split one physical switch into separate broadcast domains, with 802.1Q trunk tagging keeping VLAN traffic distinct as it crosses between switches.
  • Flat networks let a single compromised host reach everything else on the same broadcast domain; VLAN segmentation plus ACLs contain that blast radius by design.
  • VLAN hopping, ARP spoofing, and rogue DHCP servers are the core Layer 2 and Layer 3 boundary attacks, and each leaves a distinct, detectable signal on the network.

Knowledge Check

Click an answer to reveal the explanation.

A switch receives a frame destined for a MAC address that is not currently in its MAC address table. What does the switch do?

When a destination MAC is not yet learned, the switch floods the frame out every other port so that whichever device owns that address receives it and can respond. That response lets the switch learn the correct port and add it to the MAC address table for future frames, at which point forwarding switches to unicast delivery on that single port.

An analyst notices that two different devices are both responding as the owner of the same IP address on ARP requests, and the MAC address bound to the default gateway's IP keeps flipping between two values. What is the most likely explanation?

A MAC address bound to a given IP flip-flopping between a legitimate value and an unexpected one is a textbook sign of ARP spoofing: the attacker is repeatedly sending forged ARP replies claiming ownership of the gateway's IP, racing against the real gateway's own traffic and periodically winning that race. Cable faults and DHCP renewal do not produce conflicting ARP ownership claims, and this behavior has nothing to do with VLAN tagging.

A small company runs all of its workstations, servers, and a domain controller on one switch with no VLANs configured. From a security standpoint, what is the most significant consequence of this design?

With everything in one broadcast domain and no router or ACL sitting between hosts, a single compromised workstation has unrestricted Layer 2 reachability to every other device on the switch, including high-value targets like the domain controller. Segmenting those devices into separate VLANs with ACLs at the routing boundary would force that traffic through a filtering point instead of allowing it by default.