CCNA Switching Fundamentals

Switching is where every CCNA journey starts: the models that describe networks, how switches forward frames, and the media and protocols underneath it all. These CCNA switching fundamentals notes cover the OSI and TCP/IP models, frame forwarding, Ethernet media, TCP vs UDP, well-known port numbers, and topologies and virtualisation. Then put it to the test with our free CCNA mock test.

The OSI and TCP/IP Models

The OSI model is a seven-layer framework for describing how data moves across a network: 7 Application, 6 Presentation, 5 Session, 4 Transport, 3 Network, 2 Data Link, 1 Physical. Memorise it both ways — top-down and bottom-up. A handy mnemonic is "All People Seem To Need Data Processing" (top-down) or "Please Do Not Throw Sausage Pizza Away" (bottom-up).

The TCP/IP model is what the real world actually uses, and it compresses OSI's seven layers into four: the top three OSI layers become one Application layer, Transport stays, Network becomes Internet, and the bottom two merge into Network Access. The exam tests whether you can map a protocol or device to the right layer — a router is a Layer 3 device, a switch is Layer 2, a hub is Layer 1, and a firewall typically operates at Layers 3–4 (sometimes up to 7).

Learn encapsulation as a process, not just a word. As data moves down the stack on the sender, each layer adds its own header: the Transport layer creates a segment (TCP) or datagram (UDP), the Network layer wraps it in a packet with source and destination IP addresses, and the Data Link layer wraps that in a frame with source and destination MAC addresses. The receiver strips each header going back up — this is de-encapsulation. The unit names (segment, packet, frame, bits) are classic exam fodder.

Key exam points

  • OSI layers 7→1: Application, Presentation, Session, Transport, Network, Data Link, Physical.
  • TCP/IP model: Application (OSI 5–7), Transport (4), Internet (3), Network Access (1–2).
  • Data units: segment (L4), packet (L3), frame (L2), bits (L1).
  • Routers work at Layer 3, switches at Layer 2, hubs and repeaters at Layer 1.

How Switches Forward Frames

A switch learns by watching. When a frame arrives, the switch records the source MAC address and the port it arrived on in its CAM table (also called the MAC address table). When it needs to forward a frame, it looks up the destination MAC: if found, the frame goes out of only that port (known unicast); if not found, the switch floods the frame out of every port except the one it arrived on. Broadcasts and multicasts are always flooded. CAM entries age out after a period of inactivity (default 300 seconds on Cisco switches).

Switches forward frames in three ways. Store-and-forward receives the entire frame, checks the FCS for errors, then forwards — highest latency but error-free forwarding. Cut-through starts forwarding as soon as it has read the destination MAC — lowest latency but it can forward damaged frames. Fragment-free is the compromise: it reads the first 64 bytes (enough to catch collision fragments) before forwarding. The exam loves asking which method checks for errors: only store-and-forward.

Keep the domain boundaries straight. Every switch port is its own collision domain (full-duplex links have no collisions at all), but all ports in a VLAN share one broadcast domain. Routers break up broadcast domains; switches break up collision domains. Useful checks: show mac address-table and show interfaces status.

Key exam points

  • Switches learn source MACs into the CAM table; unknown unicasts, broadcasts and multicasts are flooded.
  • Only store-and-forward checks the FCS; cut-through forwards after the destination MAC; fragment-free checks 64 bytes.
  • Each switch port is a collision domain; each VLAN is a broadcast domain. Routers separate broadcast domains.
  • CAM entries age out (default 300 s). Verify with show mac address-table.

Copper, Fibre and Ethernet Media

For copper, know the twisted-pair categories and what they carry: Cat5e handles Gigabit Ethernet (1000BASE-T) to 100 m, Cat6 also does Gigabit to 100 m (and 10 Gbps to 55 m), and Cat6a carries 10GBASE-T the full 100 m. A straight-through cable (T568B on both ends) connects unlike devices — PC to switch; a crossover cable (pairs 1↔3 and 2↔6 swapped) connects like devices — PC to PC or switch to switch. In practice Auto-MDIX on modern ports detects the cable type automatically, so the exam's crossover questions are mostly about recognising the concept rather than real-world pain.

Fibre comes in two flavours. Single-mode (OS1/OS2, 9/125 µm core, usually yellow jacket) uses one light path and travels kilometres — 1000BASE-LX reaches about 10 km. Multimode (OM3/OM4, 50/125 µm, usually aqua) is cheaper but shorter — 1000BASE-SX reaches about 550 m. The exam expects you to match the transceiver to the fibre: SX/SR = multimode short reach, LX/LR = single-mode long reach.

Speed and duplex mismatches are a favourite troubleshooting topic. A duplex mismatch (one side full, the other half) produces late collisions, CRC errors and painfully slow throughput — always check show interfaces for collisions, input errors and CRCs. Autonegotiation usually gets it right, but a hard-coded side talking to an auto side is the classic failure: the auto side falls back to half duplex. Console access uses a rollover cable (light blue) at 9600 baud.

Key exam points

  • Straight-through: unlike devices (PC→switch). Crossover: like devices (switch→switch). Auto-MDIX makes this mostly automatic.
  • Cat5e/6 = Gigabit to 100 m; Cat6a = 10 Gbps to 100 m. Fibre: single-mode = long distance, multimode = short.
  • Duplex mismatch causes late collisions and CRC errors — check show interfaces counters.
  • Console: rollover cable, 9600 baud, 8-N-1.

TCP vs UDP

TCP is connection-oriented and reliable: it opens with a three-way handshake (SYN → SYN-ACK → ACK), numbers every segment, expects acknowledgements, retransmits what goes missing, and reassembles data in order. It also does flow control via the sliding window so a fast sender doesn't overwhelm a slow receiver. Use TCP when the data must arrive intact — web browsing, email, file transfer, SSH.

UDP is the opposite: connectionless, no handshake, no ACKs, no retransmission, no ordering — just fire and forget. What it loses in reliability it gains in speed and low overhead (an 8-byte header versus TCP's 20). Use UDP when timeliness beats perfection: DNS lookups, DHCP, SNMP, streaming media, voice and video calls, and routing-protocol hellos that are re-sent regularly anyway.

The exam tests two things here: which protocol an application uses, and the mechanics of the handshake. Know that a TCP header carries sequence and acknowledgement numbers, source/destination ports and window size, and that a session closes with FIN exchanges. When you see "connection-oriented, guaranteed delivery" in a question stem, the answer is TCP; "low overhead, real-time" points to UDP.

Key exam points

  • TCP: 3-way handshake (SYN, SYN-ACK, ACK), sequencing, ACKs, retransmission, flow control — reliable but slower.
  • UDP: connectionless, no ACKs, 8-byte header — fast, used by DNS, DHCP, SNMP, voice/video.
  • TCP header fields to know: ports, sequence/ack numbers, window size.
  • Question cues: 'guaranteed delivery' = TCP; 'low overhead / real-time' = UDP.

Well-Known Port Numbers

Port numbers are how the Transport layer directs traffic to the right application, and the exam expects a solid set memorised cold. Focus on the table below — these appear constantly, both as direct recall and hidden inside scenario questions (for example, an ACL that must permit DNS needs UDP/TCP 53, not just "DNS").

PortProtocolService
20 / 21TCPFTP data / control
22TCPSSH
23TCPTelnet
25TCPSMTP
53TCP/UDPDNS
67 / 68UDPDHCP server / client
69UDPTFTP
80TCPHTTP
110TCPPOP3
143TCPIMAP
161 / 162UDPSNMP agent / traps
443TCPHTTPS
49TCPTACACS+
179TCPBGP
389 / 636TCPLDAP / LDAPS
500 / 4500UDPIKE / IPsec NAT-T
1812 / 1813UDPRADIUS auth / accounting

Learn the tricky pairs deliberately: 20 vs 21 (FTP data vs control), 67 vs 68 (server vs client), 161 vs 162 (polling vs traps), 1812 vs 1813 (RADIUS authentication vs accounting), and 500 vs 4500 (IKE vs NAT traversal). DNS is the odd one out that uses both TCP and UDP — UDP for normal queries, TCP for zone transfers and large responses.

Key exam points

  • Core set: 21 FTP, 22 SSH, 23 Telnet, 25 SMTP, 53 DNS, 67/68 DHCP, 69 TFTP, 80 HTTP, 443 HTTPS.
  • Email trio: 25 SMTP (send), 110 POP3, 143 IMAP (receive).
  • Management/security: 22 SSH, 161/162 SNMP, 49 TACACS+, 1812/1813 RADIUS, 179 BGP.
  • DNS uses UDP normally, TCP for zone transfers; 500/4500 are IKE/NAT-T for IPsec.

Network Topologies and Virtualisation

The classic enterprise design is the three-tier model: access layer (switches users plug into), distribution layer (policy, routing between VLANs, aggregation), and core layer (fast backbone transport, no fiddly policy). Smaller networks collapse distribution and core into one layer — the collapsed core (two-tier) design. The exam wants the purpose of each tier, not product names: access connects endpoints, distribution enforces policy, core moves traffic fast.

Topologies describe physical or logical layout: star (everything to a central switch — the LAN norm), mesh (every device to every other — resilient but expensive, seen in WAN cores and data centres), hub-and-spoke (branches to a central site), and point-to-point (two endpoints). WAN options include leased lines, MPLS, Metro Ethernet, DSL/cable, cellular and VPN tunnels over the internet.

Virtualisation separates logical resources from physical hardware. A hypervisor (Type 1 runs on bare metal, Type 2 runs on an OS) hosts multiple virtual machines, each with its own OS. Containers share the host OS kernel, so they're lighter and faster to start. On network gear, VRFs (Virtual Routing and Forwarding) give one physical router multiple independent routing tables — like VLANs, but for Layer 3. Verify with show ip vrf and show ip route vrf NAME.

Key exam points

  • Three-tier: access (endpoints) → distribution (policy/routing) → core (fast transport). Small sites use collapsed core.
  • WAN options: leased line, MPLS, Metro Ethernet, DSL/cable, cellular, internet VPN.
  • Type 1 hypervisor = bare metal; Type 2 = hosted on an OS. Containers share the host kernel.
  • VRFs = separate routing tables on one router (Layer 3 separation, like VLANs at Layer 2).

Related CCNA study guides

Frequently asked questions

What are the key CCNA exam points for The OSI and TCP/IP Models?

For the CCNA 200-301 exam, remember: OSI layers 7→1: Application, Presentation, Session, Transport, Network, Data Link, Physical. TCP/IP model: Application (OSI 5–7), Transport (4), Internet (3), Network Access (1–2). Data units: segment (L4), packet (L3), frame (L2), bits (L1). Routers work at Layer 3, switches at Layer 2, hubs and repeaters at Layer 1.

What are the key CCNA exam points for How Switches Forward Frames?

For the CCNA 200-301 exam, remember: Switches learn source MACs into the CAM table; unknown unicasts, broadcasts and multicasts are flooded. Only store-and-forward checks the FCS; cut-through forwards after the destination MAC; fragment-free checks 64 bytes. Each switch port is a collision domain; each VLAN is a broadcast domain. Routers separate broadcast domains. CAM entries age out (default 300 s). Verify with show mac address-table.

What are the key CCNA exam points for Copper, Fibre and Ethernet Media?

For the CCNA 200-301 exam, remember: Straight-through: unlike devices (PC→switch). Crossover: like devices (switch→switch). Auto-MDIX makes this mostly automatic. Cat5e/6 = Gigabit to 100 m; Cat6a = 10 Gbps to 100 m. Fibre: single-mode = long distance, multimode = short. Duplex mismatch causes late collisions and CRC errors — check show interfaces counters. Console: rollover cable, 9600 baud, 8-N-1.

What are the key CCNA exam points for TCP vs UDP?

For the CCNA 200-301 exam, remember: TCP: 3-way handshake (SYN, SYN-ACK, ACK), sequencing, ACKs, retransmission, flow control — reliable but slower. UDP: connectionless, no ACKs, 8-byte header — fast, used by DNS, DHCP, SNMP, voice/video. TCP header fields to know: ports, sequence/ack numbers, window size. Question cues: 'guaranteed delivery' = TCP; 'low overhead / real-time' = UDP.

What are the key CCNA exam points for Well-Known Port Numbers?

For the CCNA 200-301 exam, remember: Core set: 21 FTP, 22 SSH, 23 Telnet, 25 SMTP, 53 DNS, 67/68 DHCP, 69 TFTP, 80 HTTP, 443 HTTPS. Email trio: 25 SMTP (send), 110 POP3, 143 IMAP (receive). Management/security: 22 SSH, 161/162 SNMP, 49 TACACS+, 1812/1813 RADIUS, 179 BGP. DNS uses UDP normally, TCP for zone transfers; 500/4500 are IKE/NAT-T for IPsec.