skip to content

In campus network design, what is a collapsed core, and when should a campus keep a separate core layer instead?

level: middleimportance: should knowfreq 30%

answer

  1. two layers instead of three
  2. one redundant pair does two jobs
  3. single building, few access blocks
  4. mesh grows as n(n-1)/2
  5. core as pure transport

basics

~20 s

A collapsed core merges the distribution and core layers into one redundant pair that every access switch uplinks to. It fits a single building; a campus with several distribution blocks keeps a core so blocks avoid a full mesh.

solid answer

~40 s

A **collapsed core** is a two-tier campus: access switches uplink to one redundant pair of switches that does both the distribution job (gateways for the access VLANs, policy, the Layer 2/Layer 3 boundary) and the core job (routing between blocks and toward the WAN, internet and data centre). It saves a layer of switches, optics and cabling, and suits a single building or a small campus. A **separate core** earns its cost once you have several distribution blocks: without it each block must connect to every other, which grows as n(n-1)/2 (fifteen connections for six blocks), while with a core each block connects once. The core also stays simple, fast transport, so a change or failure inside one block stays inside it.

go deeper

for a junior

Recall the three roles, access, distribution and core, and that a collapsed core is one redundant pair doing the distribution and core jobs together.

for a middle

Explain where the gateways and the Layer 2/Layer 3 boundary sit, and why connecting blocks without a core grows as n(n-1)/2 while a core grows linearly.

for a senior

Decide from block count, change rate and where the WAN and data centre attach, and keep each block's Layer 2 failure domain from spreading across the campus.

for a principal

Treat the core as a cost you buy for isolation and growth, and judge when a site's expected number of buildings justifies it.

## The three roles first A campus network serves people and devices in offices, not racks of servers. The classic hierarchical campus has three roles: - **Access** — switches in wiring closets that users, phones, printers and access points plug into, usually one or more VLANs per closet. - **Distribution** — a redundant pair per building or block that terminates the access uplinks, holds the default gateways for the access VLANs (made redundant with a first-hop redundancy protocol such as VRRP), applies policy and marks the boundary between switching and routing. - **Core** — a redundant pair (or more) that interconnects the distribution blocks and connects the campus to the WAN, the internet edge and any on-site data centre. It is meant to forward fast and change rarely. A **collapsed core** keeps the access layer and merges the other two roles into one pair of switches. ## What a collapsed core looks like In a collapsed-core campus: 1. every access switch has uplinks to both switches of the collapsed pair; 2. the pair holds the gateways for all access VLANs and routes between them; 3. the WAN routers, the internet firewall and any server room attach to the same pair. Nothing is lost in redundancy: the core is still two switches, and each access switch still has two uplinks. What disappears is one layer of devices, optics and links, and one more hop for traffic leaving the building. ## When a separate core earns its place The case for a core is mostly about how distribution blocks connect to each other. | Distribution blocks | Block-to-block connections without a core: n(n-1)/2 | Block-to-core connections with a core: n | |---|---|---| | 2 | 1 | 2 | | 4 | 6 | 4 | | 6 | 15 | 6 | | 8 | 28 | 8 | Each connection here is itself several physical links, because each block is a redundant pair. The mesh grows quadratically while the core grows linearly, so beyond a handful of blocks the full mesh becomes cabling, optics and routing adjacency you cannot justify. Other reasons to keep a separate core: - **Isolation of change.** A block's distribution pair carries policy and VLAN-facing configuration that changes often. A core that only routes between blocks can be left alone, so a mistake in one building does not ripple through the others. - **A clean place for shared services.** The WAN edge, internet edge and data centre attach to the core once instead of to one building's distribution pair. - **Growth.** Adding a building means adding one block and connecting it to the core, without re-cabling every existing block. ## When a collapsed core is the right call A collapsed core is the sensible default when: - the campus is one building, or a few small buildings close together; - there are few enough access switches that one pair can terminate all their uplinks; - the traffic mostly goes north-south, from users to the WAN, internet or data centre, rather than between blocks. Many small and medium sites never need more. A collapsed core also leaves a clean growth path: when a second large building arrives, the existing pair can keep its distribution role for the first building, a new pair takes the same role in the second, and a separate core pair is added above both. Planning uplink ports and fibre routes for that day costs little when the collapsed core is first built. The design question to ask is not "is three-tier better?" but "how many distribution blocks will there be, and how often will one of them change?" ## Failure domains in a campus Whichever shape you choose, keep Layer 2 inside each access-distribution block. A VLAN that spans buildings turns a loop or a broadcast storm in one closet into an outage across the campus. Loop prevention inside the block is spanning tree's job; the design job is to route between blocks so that the failure domain of one block's Layer 2 stops at its distribution pair. Some campuses push routing down to the access switches (routed access), which shrinks the Layer 2 domain to a single closet at the cost of losing VLANs that span closets.

  • Where does the Layer 2/Layer 3 boundary sit in a collapsed-core campus?
    Usually on the collapsed pair itself: access switches carry VLANs up on trunks, and the pair holds each VLAN's default gateway, made redundant with a first-hop redundancy protocol such as VRRP, and routes between them. A routed-access design moves the boundary down to the access switches instead, so each closet's uplinks are routed and no VLAN leaves the closet.
  • Is a collapsed core a single point of failure?
    Not if built as intended. The collapsed core is a pair, and every access switch uplinks to both, so losing one switch costs capacity and gateway failover time, not connectivity. What it does concentrate is change risk: the same pair carries every block's policy and the campus's exit, so maintenance on it touches the whole site.

saying these in an interview costs you the question

  • A collapsed core removes redundancy because there is only one core switch.
  • A separate core layer is needed as soon as a campus has more than one VLAN.
  • Per-user access policy belongs in the core because all traffic passes through it.
  • A collapsed core means routing has moved down to the access switches.