In OSI terms, how does a bridge differ from a switch, and how does a layer 3 switch differ from a router?
answer
- names versus layers
- multiport bridge
- routing inside the chassis
- Hop Limit still decremented
basics
~20 sA switch is a multiport bridge: both forward frames on MAC addresses at layer 2. A layer 3 switch also routes on IP, so for routed traffic it is a router; hardware and feature set differ, not the layer.
solid answer
~50 sA bridge and a switch make the same layer 2 decision: forward the frame on its destination MAC, learn from the source MAC and keep one broadcast domain. "Bridge" is the older name for boxes joining two or a few segments, often in software; a switch is the many-port, hardware-forwarding form. A **layer 3 switch** adds routing: between VLANs or subnets it reads the destination IP, looks up a route, decrements the IPv4 TTL or IPv6 `Hop Limit` and builds a new frame, which is what RFC 1122 calls a gateway or IP router. The differences from a traditional router are practical: layer 3 switches are built for port density and fast forwarding inside a site, routers typically for the site edge, varied links, larger routing tables and richer policy. Neither label changes which header the routing decision reads.
go deeper
Remember two equations: a switch is a multiport bridge, both at layer 2; a layer 3 switch is a switch that also routes on IP. Neither name changes the layer of the decision.
Walk through what a layer 3 switch does to a routed packet: reads the destination IP, looks up a route, decrements TTL or Hop Limit, rebuilds the frame. Then explain why hosts in different VLANs need that step.
Separate forwarding from filtering: a device routes on IP but its access lists may match ports. Compare layer 3 switches and routers by placement and features, and avoid claiming one runs at a different layer.
Discuss where routing belongs in a site design: routing inside the access or core layer with layer 3 switches versus concentrating it at edge routers, and what each does to broadcast domain size and fault isolation.
## Two naming questions, one layer question Interviewers ask about bridges and layer 3 switches to check whether a candidate describes devices by **what they read** or by **what they are called**. The answer to both halves is the same idea: the layer is fixed by the header the forwarding decision uses, and marketing names do not move it. - **Bridge versus switch**: same layer (2), same decision, different scale and history. - **Layer 3 switch versus router**: same layer (3) for routed traffic, same decision, different hardware and feature set. ## Bridge and switch: the same layer 2 decision A **bridge** joins LAN segments and forwards **Ethernet frames** between them based on the **destination MAC address**, learning host locations from the **source MAC address**. It keeps the joined segments in **one broadcast domain**: broadcasts cross it. (The learning and flooding algorithm itself belongs to Ethernet switching, a subject of its own.) A **switch** makes exactly that decision on many ports at once. The common one-line definition is correct: **a switch is a multiport bridge**. The two words survive for historical reasons: - early bridges joined two or a few segments, often forwarding in software; - switches arrived with many ports and forwarding in dedicated hardware, and gave every host its own port. Neither reads the IP header to forward, so neither can route between IP subnets. ## What makes a layer 3 switch a router A **layer 3 switch** is a switch that can also **route**. For traffic between two VLANs or subnets it: 1. accepts the frame addressed to its own MAC (it is the hosts' default gateway), 2. reads the **destination IP address** and looks it up in a routing table, 3. decrements the IPv4 **TTL** or IPv6 **Hop Limit** (RFC 8200: decremented by 1 by each node that forwards the packet), 4. builds a new frame toward the next hop or the destination host. That is the job RFC 1122 assigns to a **gateway**, the Internet community's older word for an IP router. So for routed traffic a layer 3 switch **is** a router, even though the packet may never leave the chassis. Traffic within one VLAN on the same box is still switched at layer 2. ## Router versus layer 3 switch The differences are practical, not architectural, and they vary by product, so hold them loosely: | Aspect | Layer 3 switch | Traditional router | |---|---|---| | Forwarding decision | destination IP | destination IP | | TTL / Hop Limit | decremented | decremented | | Typical placement | inside a site, between VLANs | site edge, between sites and providers | | Interfaces | many Ethernet ports | fewer ports, often varied link types | | Typical strengths | high forwarding rate, port density | larger routing tables, richer policy features | An interviewer who asks "is a layer 3 switch a router?" wants to hear "yes for the traffic it routes, and here is why", followed by the practical differences rather than a claim that one works at a different layer. ## VLANs: why routing is needed inside one switch A **VLAN** splits one physical switch into several **broadcast domains**. Each VLAN is usually its own IP subnet. A plain layer 2 switch forwards frames only within the VLAN they arrived on; flooding never crosses into another VLAN. Hosts in different VLANs therefore send their traffic to a **default gateway**, which must route it: - an external router connected to the switch, or - the switch's own layer 3 function. Either way a **routing hop** happens, with its TTL decrement, even if both hosts hang off the same box. ## When the labels mislead The OSI layers are a teaching model. RFC 3439, in its section titled "Layering Considered Harmful", notes that strict layering conflicts with efficient implementation, and real devices blur the lines: - a layer 3 switch often runs **access lists** that match TCP or UDP ports, reading layer 4 fields without forwarding on them; - a managed layer 2 switch has its own IP address for management, yet forwards user frames on MAC; - a single box may bridge some ports, route between others and filter everything. The reliable way to classify a device is to ask two separate questions: which header does its **forwarding** decision read, and which extra fields can its **filters** match? A bridge and a switch give the same answer to the first; so do a layer 3 switch and a router.
- Why does traffic between two VLANs on the same layer 2 switch still need a layer 3 device?Each VLAN is a separate broadcast domain, usually its own IP subnet, and a layer 2 switch forwards frames only within the VLAN they arrived on. A host therefore sends inter-VLAN traffic to its default gateway's MAC, and something must read the IP header and route it into the other VLAN: an attached router or the switch's own layer 3 function. The frames may never leave the chassis, but a routing hop still happens.
- A layer 3 switch can filter on TCP ports. Does that make it a layer 4 device?Not in the sense the layer label means. Its forwarding decision still reads the destination IP address; an access list that matches ports is a filter layered on top, reading deeper than forwarding needs. Describe a device by the header it forwards on, then list separately which fields its filters can match.
saying these in an interview costs you the question
- A bridge is a layer 1 device because it only joins two cable segments.
- A layer 3 switch forwards between subnets without decrementing the TTL.
- A layer 3 switch routes by looking up MAC addresses, which makes it faster.
- Hosts in two VLANs on one switch can talk without any layer 3 device.
- A switch and a bridge operate at different OSI layers.