skip to content

In OSI terms, what does a hub, a switch and a router each read from incoming traffic, and what does each forward on?

level: juniorimportance: must knowfreq 78%

answer

  1. one layer deeper each
  2. bits, frames, packets
  3. MAC table versus routing table
  4. who stops a broadcast

basics

~20 s

A hub reads no addresses and repeats bits out of every other port (layer 1). A switch forwards frames on the destination MAC address (layer 2). A router forwards packets on the destination IP address (layer 3).

solid answer

~50 s

A **hub** is a layer 1 repeater: it regenerates the signal and sends every bit out of all other ports, so every attached host sees every frame and they share one collision domain. A **switch** works at layer 2: it reads the Ethernet header, forwards on the destination MAC and learns hosts from the source MAC, so once it knows where a destination is, unicast frames go only toward that port. Broadcasts still reach every port in the same broadcast domain. A **router** works at layer 3: it strips the frame, reads the destination IP address, looks it up in its routing table, decrements the IPv4 TTL or IPv6 `Hop Limit` and builds a new frame for the next hop. Because it forwards on IP, a router does not pass layer 2 broadcasts, so it bounds a broadcast domain.

go deeper

for a junior

Recall the ladder cleanly: hub repeats bits at layer 1, switch forwards on MAC at layer 2, router forwards on IP at layer 3. Add the unit each handles and one consequence, such as routers stopping broadcasts.

for a middle

Explain what each device does to the traffic: the hub touches nothing, the switch reads the frame header and learns from source addresses, the router rebuilds the frame and decrements TTL or Hop Limit. Tie each to its collision or broadcast domain.

for a senior

Use the ladder to diagnose: reaching hosts in your own subnet but nothing beyond usually points at the default gateway or the path past it, not the switch. Point out that real boxes stack functions, so ask which header a given forwarding or filtering decision reads.

for a principal

Treat the ladder as a design boundary: where layer 3 sits decides broadcast domain size, fault blast radius and where filtering can happen. Be explicit that device labels come from a teaching model, not a product guarantee.

## Three devices, three layers The OSI model gives a compact way to describe network devices: name the **header a device reads to make its forwarding decision**. On that test the three classic LAN and internetwork devices land on three consecutive layers: - a **hub** reads no header at all, so it is a **layer 1** (physical) device; - a **switch** reads the Ethernet frame header, so it is a **layer 2** (data link) device; - a **router** reads the IP packet header, so it is a **layer 3** (network) device. The protocol data unit each one handles follows from that: bits for the hub, frames for the switch, packets for the router. ## Hub: layer 1, reads nothing A **hub** is a multiport repeater. Whatever electrical signal arrives on one port it regenerates and sends out of every other port. It never interprets the bits as a frame, so it has no idea what a MAC address or an IP address is. Two consequences follow: - **Every host sees every frame.** Unicast traffic between two hosts reaches all the others on the hub, and any of them can read it. - **One shared collision domain.** Only one host can transmit at a time; simultaneous transmissions collide, so hub links run half duplex and share their capacity. Hubs are essentially obsolete in modern wired networks, but they remain the reference point for what "layer 1 only" means. ## Switch: layer 2, reads the frame header A **switch** reads the **Ethernet header**. It uses the **destination MAC address** to decide which port a frame leaves on, and the **source MAC address** to learn which port each host sits behind. (How that learning, forwarding and flooding works is its own subject, covered under Ethernet switching.) Once a switch has learned where a destination lives, it sends unicast frames only toward that port. Each port is its own link, usually full duplex, so hosts no longer contend with each other. What a switch does **not** do is stop **broadcasts**: a frame sent to the broadcast address still reaches every port in the same **broadcast domain** (the same VLAN). A plain layer 2 switch never reads the IP header to forward, so it cannot tell one IP subnet from another. ## Router: layer 3, reads the packet header A **router** strips the incoming frame, reads the **destination IP address**, looks it up in its **routing table** and picks a next hop. It then builds a fresh frame for the next link (the per-hop rewrite of the link addresses is covered under encapsulation) and decrements the IPv4 **TTL** or the IPv6 **Hop Limit**; RFC 8200 defines Hop Limit as decremented by 1 by each node that forwards the packet. Because a router forwards on IP addresses, it does **not** forward layer 2 broadcasts from one interface to another. Each router interface is therefore the edge of a broadcast domain, which is why two IP subnets need a router (or a layer 3 switch doing the routing) between them. RFC 1122 records the naming history: the Internet community calls these packet-switching computers "gateways" or "IP routers", while the OSI world calls them "Intermediate Systems". ## Side by side | Device | OSI layer | Reads | Forwards on | Broadcasts | |---|---|---|---|---| | Hub | 1 | nothing (raw signal) | every other port | repeated everywhere | | Switch | 2 | Ethernet header | destination MAC | flooded within the broadcast domain | | Router | 3 | IP header | destination IP via routing table | not forwarded between interfaces | A useful way to remember the table: each step up the ladder reads **one more header** and makes a **narrower** delivery decision. The hub delivers to everyone, the switch to the right port on the LAN, the router to the right next network. ## A shorthand, not a law The layer label describes the **forwarding decision**, not everything a box can do: 1. A managed switch has its own IP address for management, so it is also an IP host, yet it still forwards user frames on MAC addresses. 2. Many devices add **filters** that read deeper than their forwarding decision, such as a router access list that matches TCP ports. Filtering and forwarding are separate questions. 3. A home "wireless router" is several devices in one case: an access point, a small switch, a router and usually NAT. So in an interview, give the classic ladder, then show you know it describes which header each forwarding decision reads, and that real products stack several of these functions.

  • Why does replacing a hub with a switch improve a LAN even when every host is in one IP subnet?
    A hub sends every frame to every port, so all hosts share one half-duplex collision domain and each can read the others' unicast traffic. A switch gives each port its own link, usually full duplex, and once it has learned a destination MAC it sends unicast frames only toward that port. Capacity per host rises and most unicast traffic is no longer visible to other hosts, but broadcasts still reach everyone: it is still one broadcast domain.
  • Two hosts on the same layer 2 switch are in different IP subnets. Why can they not talk without a router?
    A host sends a packet for another subnet to its default gateway, addressing the frame to the gateway's MAC rather than the destination host's. A plain layer 2 switch never reads the IP header, so it cannot route between subnets; it only forwards frames inside the broadcast domain. Without a router, or a layer 3 switch doing the routing, there is no gateway to hand the packet to.
  • Where does a plain wireless access point sit on this ladder?
    At layer 2. It bridges frames between the radio side and the wired Ethernet side, forwarding on MAC addresses without routing on IP. The home wireless router is a different box: an access point, a small switch, a router and usually NAT in one case, so it works at several layers at once.

saying these in an interview costs you the question

  • A hub is a slower switch that forwards frames by MAC address.
  • A plain layer 2 switch reads IP addresses to choose the output port.
  • A router forwards layer 2 broadcast frames between its networks.
  • A switch sends every unicast frame to every port, just as a hub does.
  • Routers and switches do the same job; a router is only a bigger switch.