What a Switch Actually Learns from a MAC Address
A switch learns from source MAC addresses, not destination addresses. Watching the table populate makes unknown unicast, flooding and forwarding much easier to reason about.
A switch learns from source MAC addresses, not destination addresses. Watching the table populate makes unknown unicast, flooding and forwarding much easier to reason about.
Subnetting became much easier once I treated it as address boundaries and binary arithmetic instead of a collection of shortcut tables.
A two-PC switch lab is simple enough to expose the actual sequence behind a successful ping: addressing, ARP, MAC learning and frame forwarding.
STP made more sense after I created the failure it is designed to prevent: a Layer 2 loop with no TTL to save the network.
PAT stopped feeling like a magic Internet-sharing feature once I watched inside local addresses, public translations and transport ports change in the NAT table.
OSPF became useful when I compared it directly with the static routes I had been maintaining by hand and watched neighbors and learned routes change with the topology.
A VLAN is first a Layer 2 boundary. IP subnets often map to VLANs, but keeping those two concepts separate makes switching and routing much easier to reason about.
Most beginner lab failures were not exotic protocol bugs. They were wrong masks, wrong VLANs, missing routes, stale assumptions and tests that did not isolate the failing layer.
My first memorable ACL mistake was technically correct: it blocked exactly what I told it to block, including the management traffic I still needed.
A trunk can be up while one VLAN is still broken. That lab pushed me to verify allowed VLANs and operational state instead of assuming the link was simply good or bad.
A useful home lab does not need enterprise hardware. A spare PC, a small switch and a few isolated network experiments are enough to learn a lot about real interfaces, routes and services.
A three-router topology is enough to show the most important routing lesson: reachability is directional, and the return path matters just as much as the forward path.
One router interface, an 802.1Q trunk and a few subinterfaces were enough to connect separate VLANs without hiding what was happening at Layer 2 and Layer 3.
DHCP is easier to troubleshoot when treated as a timed client-server exchange that delivers an address plus the parameters a host needs to participate in the network.
A trunk does not merge VLANs. It preserves multiple Layer 2 domains across one physical link by carrying VLAN identity with the frame.