How does an Ethernet switch differ from a hub, and what are collision domains and broadcast domains?
answer
- repeat bits versus forward frames
- who shares the wire
- one collision domain per switch port
- only layer 3 stops broadcasts
basics
~20 sA hub repeats every bit out every port, so its hosts share one collision domain; a switch forwards whole frames by destination MAC, so each port is its own collision domain. Neither splits a VLAN's broadcast domain; a router does.
solid answer
~50 sA hub is a multi-port repeater: it regenerates the electrical signal from one port onto all the others without reading any address, so every attached host shares the medium, only one can transmit at a time, and simultaneous transmissions collide. That shared segment is one **collision domain**. A switch is a multi-port bridge: it receives each frame, reads the destination MAC address and sends it only out the port where that address lives, so every switch port is its own collision domain, and on a full-duplex link collisions cannot happen at all. A **broadcast domain** is the set of hosts that receive a frame sent to `ff:ff:ff:ff:ff:ff`. A switch floods broadcasts out every port, so all its ports (in one VLAN) stay one broadcast domain; only a router, which forwards IP packets rather than frames, ends it.
go deeper
Recall the one-line rule: a hub repeats bits to everyone, a switch forwards frames by destination MAC. Then define collision domain as who shares the medium and broadcast domain as who hears a broadcast.
Explain why each switch port is a collision domain (buffering, full duplex), why switches still flood broadcasts, and count domains correctly in a mixed hub, switch and router drawing.
Connect the definitions to symptoms: duplex mismatch errors, broadcast load growing with a flat network, and why a host on a switch normally cannot see its neighbours' unicast traffic.
Frame broadcast-domain size as a design and failure-radius choice: when splitting with routing or VLANs pays for itself in reduced broadcast load and blast radius versus the operational cost of more boundaries.
## Two boxes that look the same A hub and a switch both have a row of Ethernet ports and both connect hosts on one local network, which is why the question is asked: the difference is entirely in what happens to a frame once it arrives. - A **hub** is a **multi-port repeater**. It works on bits: whatever signal arrives on one port is regenerated and sent out every other port at once. It never reads a MAC address, never buffers a frame and never decides anything. - A **switch** is a **multi-port bridge**. It works on **frames**: it receives a frame, reads the **destination MAC address** in its header, looks that address up in its **MAC address table** (the forwarding database that maps each learned address to a port) and sends the frame only out the matching port. Frames to unknown addresses and to the broadcast address are **flooded** out every port except the one they came in on. ## Collision domains A **collision domain** is the set of devices that compete for the same shared medium, so that two of them transmitting at the same moment corrupt each other's signal. 1. On a hub, every attached host is in **one** collision domain. Classic shared Ethernet handled this with **CSMA/CD** (carrier sense multiple access with collision detection, IEEE 802.3's half-duplex access method): listen before sending, detect a collision, send a jam signal, back off for a random time and retry. As more hosts are added, more time is lost to collisions and back-off. 2. On a switch, **each port is its own collision domain**. The switch buffers frames, so two hosts sending at the same moment to the same destination are queued, not collided. 3. On a **full-duplex** link (the normal case between a host and a switch today) each direction has its own channel, so collisions **cannot occur** and CSMA/CD is switched off. The port is still counted as a separate collision domain in textbook exercises, but it never actually sees a collision. Collisions survive today only on half-duplex segments: a leftover hub, or a **duplex mismatch** where one end runs full duplex and the other half duplex, which shows up as late collisions on the half-duplex side and FCS errors on the full-duplex side. ## Broadcast domains A **broadcast domain** is the set of hosts that receive a frame sent to the broadcast address `ff:ff:ff:ff:ff:ff`. Protocols that must reach "everyone on the segment" depend on it: an IPv4 host resolving a neighbour's MAC address with ARP, or a client looking for a DHCP server, sends a broadcast. - A hub repeats broadcasts like everything else. - A switch **floods** broadcasts out every port in the same VLAN, because the broadcast address matches no single port. Chaining ten switches together still gives **one** broadcast domain. - A **router** ends a broadcast domain: it forwards IP packets between networks and does not forward a link-layer broadcast from one interface onto another. - A **VLAN** splits one physical switch into several broadcast domains; that tagging mechanism belongs to VLAN study, but the rule stays the same: one VLAN, one broadcast domain. ## Counting domains in a small network Picture a fresh switch with three ports in use: port 1 connects a hub with four hosts on it, port 2 connects a single host, port 3 connects a router interface. | Segment | Collision domains | Broadcast domain | |---|---|---| | Hub with four hosts, plus switch port 1 | 1 (shared) | same one | | Switch port 2 and its host | 1 | same one | | Switch port 3 and the router interface | 1 | same one; the router's other interfaces start new ones | | **Total** | **3** | **1** | The usual mistakes are counting one collision domain per host on the hub (they share the medium, so it is one) or counting one broadcast domain per switch port (the switch floods broadcasts, so it is one). ## Why the distinction still matters - **Capacity**: on a hub, all hosts share one link's bandwidth; on a switch, each port gets its own, and traffic between ports 1 and 2 does not consume port 3's. - **Privacy**: a host on a hub sees every frame on the segment; a host on a switch sees only frames addressed to it, broadcasts, multicasts it has not been filtered from, and flooded unknown-unicast frames. That is why attacks that make a switch flood exist. - **Scale**: a broadcast domain grows with every host in it, and every host must process every broadcast. Large flat networks are split with routers or VLANs, not with more switches.
- Does a full-duplex switch port still have collisions?No. On a full-duplex link each direction has its own channel, so both ends can transmit at once and CSMA/CD is switched off. The port is still described as its own collision domain, but nothing collides. Collisions appear only on half-duplex segments, such as a hub, or with a duplex mismatch, where the half-duplex end sees late collisions and the full-duplex end sees FCS errors.
- Why does a broadcast frame cross every switch in a flat network?The broadcast address `ff:ff:ff:ff:ff:ff` matches no single port in the MAC address table, so every switch floods it out all ports in that VLAN except the arrival port, and the next switch does the same. Only a device that forwards at the IP layer, a router, or a VLAN boundary stops it. ARP requests and DHCP discovery rely on exactly this reach.
saying these in an interview costs you the question
- A switch gives every port its own broadcast domain.
- A hub reads MAC addresses and sends each frame to the right port.
- Full-duplex switch ports still suffer collisions under heavy load.
- Adding more switches to a flat network shrinks how far broadcasts travel.
- Hosts on one hub each have their own collision domain.