The Link Layer & Local Networks

September 24, 2026 • 10 min read

The Link Layer & Local Networks
Table of contents

Part of the series:Networks Explained

The physical layer post ended at the bottom: bits, and nothing that knows what they mean. This post adds the first thing that does. Layer one moves bits to the neighbor. Layer two gives those bits an address, a frame around them, and a device smart enough to deliver them to exactly one machine out of everyone plugged into the same cable. This is the layer that turns loose signals into a local network, and it is the first place the addressing idea appears.

The OSI post summarized the job in one sentence: deliver bytes to the neighbor. That is worth unpacking, because the neighbor is the whole point.

A router connecting two networks receives a packet and forwards it to a different cable. It never looks inside for a local machine. The link layer is what happens on a single cable, between machines sharing that cable, and it answers three questions:

  • Who is this for? There may be a dozen machines on this wire.
  • Where does it start and end? The physical layer delivers a soup of bits. Somebody must mark the message boundaries.
  • Did it survive the trip? Signals get damaged, and someone should detect that before passing garbage upward.

Note what the link layer does not do. It knows nothing about hosts across the world, nothing about programs, and nothing about whether a message will be answered. It moves frames one hop, on this wire, to this machine.

MAC addresses: identity on the wire

The link layer’s address is the MAC address1: 48 bits, usually written as six hex bytes, and permanently burned into the network interface at the factory.

a4:83:e7:2f:19:0b

first 3 bytes (a4:83:e7)  who made the card (the OUI vendor prefix)
last 3 bytes (2f:19:0b)    which card (assigned by the manufacturer)

The structure matters because it is the one place where the internet’s “everything is flat” idea is broken. IP addresses are allocated top-down and therefore tell you where a machine is roughly. MAC addresses are assigned by hardware makers and tell you nothing about geography at all: the card in your laptop and the card in a server in Seoul share only a vendor prefix.

Real example: your laptop and your neighbor’s laptop, on the same café Wi-Fi, can have MAC addresses from the same manufacturer batch. There is no “where” in a MAC address.

A note on modern hardware: many interfaces now use a locally administered address, with a bit flipped to signal “this is a random number, not the vendor’s”, because tracking devices by permanent hardware identity turned into a privacy problem. The format stayed the same; the promise of global uniqueness got weaker on purpose.

The Ethernet frame

Layer two does not send bare bytes. It sends a frame2: the payload from above, wrapped in a header and a trailer that only nearby machines care about.

┌────────┬────────┬──────┬──────────────┬─────┬─────────┐
│ dest   │ source │ type │   payload    │ pad │  FCS    │
│ MAC    │ MAC    │      │  46-1500 B   │     │  4 B    │
│ 6 B    │ 6 B    │ 2 B  │              │     │         │
└────────┴────────┴──────┴──────────────┴─────┴─────────┘
    └ header ─────────────┘                  └ trailer ──┘

Field by field:

  • Destination and source MAC: who this frame is for, and who sent it. These two fields are the entire local addressing system.
  • Type: what is inside, meaning an IP packet, an ARP message, or something else. This is the EtherType pointer that lets a machine hand the frame to the right layer.
  • Payload: up to 1500 bytes of layer 3 data. A 1500-byte payload is the MTU3, the maximum transmission unit, the standard ceiling for a frame on ordinary Ethernet.
  • FCS: a frame check sequence4, a checksum over the whole frame.

Two details in there surprise people. First, the minimum: a frame must be at least 64 bytes, so tiny payloads get padded. Second, the trailer: the frame does not end when the payload does, which means a receiver knows to keep reading after a short message instead of mistaking the gap for the end.

Real example: when your machine sends 20 bytes of a DNS query, the Ethernet frame is still 64 bytes minimum, padded to 60 with zeros. Small packets on a real link are mostly padding and headers, which is one reason protocols prefer fewer, larger messages.

The FCS is the link layer’s only reliability claim, and it is modest: it detects errors, and a corrupt frame is silently dropped. Detection is not recovery. Layer two never retransmits, because it has no idea whether the frame was lost in transit or arrived while the receiver was busy, and re-sending blindly would flood a busy link with duplicates. The transport layer is where retransmission actually happens.

Switches: the box that learned who is where

Now the hardware. A hub is the old answer: an electrical box that repeats every signal to every port. Every machine hears everything, and only one may speak at a time, or the signals collide into noise. A hub is one big collision domain5: everybody shares one conversation slot.

A switch6 is the modern answer. It forwards each frame only out the port where the destination actually is, and it learns that mapping by watching:

laptop sends frame  ──▶  switch notes: A4:83:E7:2F:19:0B is on port 3
                        and stores it (the CAM table)

later, a frame for A4:83:E7:2F:19:0B arrives
   ├─ destination known  → forward out port 3 only
   └─ destination unknown → flood out every other port
                            (the first sighting must find someone)

This learning is the whole trick, and it has a name that sounds corporate and is simple: source learning. Every frame that arrives tells the switch whose machine is on which port. The switch never asks.

hub:    port1 ─┐
        port2 ─┼─ repeat everything everywhere
        port3 ─┘      one collision domain

switch: port1 ─┐   each port is its own collision domain;
        port2 ─┼─ frames go only where they need to go
        port3 ─┘   full duplex: send and receive simultaneously

That last property matters more than it sounds. Because a switch gives every machine its own private wire, a machine can send and receive at the same time. Hubs could not: they were half duplex, and the whole network took turns. Moving from hubs to switches is the single change that made office networks feel ten times faster, without any cable being replaced.

Real example: when you run a speed test on Wi-Fi and get half the advertised speed, one common reason is that the wireless medium is shared, unlike the wired network. Full-duplex switches are why a gigabit cable port really does reach close to a gigabit.

ARP: bridging the two address worlds

Here is a gap in the story. Layer 3 identifies machines with IP addresses7, which are what applications use and what routing depends on. Layer 2 delivers frames using MAC addresses. To send anything, a host needs to know which MAC belongs to which IP.

Inside your own network, that question is answered by broadcast, because broadcasting is cheap there. The Address Resolution Protocol8 asks it directly:

host A wants to send to 192.168.1.50, and does not know the MAC

A ──▶ everyone on the LAN: "who has 192.168.1.50? tell a4:83:e7:11:22:33"
50 ──▶ A: "that's me"
A   records the answer in its ARP cache, and sends the frame

The result is cached, so the question is asked once per address rather than once per packet. That cache is the reason ARP is invisible in normal use and briefly visible when you open a terminal and run arp -a.

Two things worth knowing about this design. If the destination is not on your own network, A does not resolve the destination at all: it resolves the default gateway9, the machine that forwards traffic off the local network, which is why the first ARP request after you open a browser is always about your router. And because ARP replies are unauthenticated, a machine on the same network can answer for anyone, forging MACs. This is one of the oldest tricks on the internet, and it is one reason the security post exists.

IPv6 does not use ARP. Neighbors are discovered with a protocol built on multicast, so a machine can ask only the machines that could plausibly be the answer, and nobody on the network has to see the question.

Everything above applies to wireless, with one structural difference that explains everyday Wi-Fi behavior: there is no cable, so there is no dedicated wire per machine and no switch. Every device on a Wi-Fi network shares one radio channel10.

Sharing a medium means collisions, and collisions cannot be detected by listening while transmitting, because a radio cannot hear itself clearly. So Wi-Fi cannot use the wired approach of detecting a collision after the fact. It avoids them instead, using carrier sense multiple access with collision avoidance: listen before speaking, wait a randomized amount, transmit, and if you did not hear an acknowledgement, assume it collided and back off exponentially. Acknowledging every single frame is the price of a shared, invisible medium.

A wired switch gives each machine a private lane. A Wi-Fi access point gives everyone the same lane, so the protocol has to behave politely.

VLANs: networks inside the network

A single physical switch can host several logical networks. VLANs11 tag frames with a small identifier so the switch keeps the groups apart, so a port for accounting machines and a port for guest Wi-Fi can sit in the same switch and never talk.

one physical switch
   ├── VLAN 10: employees
   ├── VLAN 20: servers
   └── VLAN 30: guest Wi-Fi      (isolated by tag, not by cable)

This is the “virtual” in virtual local area network. It also previews the next post’s world: once you can carve a switch into logical networks, you start wanting a layer that does the same across an entire globe, and the machine that does that is a router.

The big picture

Layer two delivers frames to the neighbor, and only the neighbor. It addresses machines with flat, meaningless 48-bit MAC addresses, wraps the payload in a frame with type, padding, and a checksum that detects errors without ever repairing them, and moves frames with a switch that learns which port belongs to which machine from the frames it already sees, giving each machine its own collision domain and full duplex. ARP bridges the IP world to the MAC world by asking the whole local network and caching the answer. Wi-Fi runs the same layer over a shared radio, which is why it avoids collisions instead of detecting them.

layer 3: "192.168.1.50"          the address that means something
   ↓ ARP: who owns that IP?      the local question
layer 2: "a4:83:e7:11:22:33"     the address on this wire
   ↓ switch forwards, physical signals
destination machine

One hop, one address, one wire. The next post takes the packet that link layer carries and asks the hard question: how does it get from that machine to one on another continent?

Footnotes

  1. MAC address - Wikipedia

  2. Ethernet frame - Wikipedia

  3. Maximum transmission unit - Wikipedia

  4. Frame check sequence - Wikipedia

  5. Collision domain - Wikipedia

  6. Network switch - Wikipedia

  7. IP address - Wikipedia

  8. Address Resolution Protocol - Wikipedia

  9. Default gateway - Wikipedia

  10. Wireless network - Wikipedia

  11. Virtual LAN - Wikipedia