In a TLS-based VPN, what changes between a routed (layer 3) tunnel interface and a bridged (layer 2) one, and when is bridging worth it?
answer
- packets versus frames
- which broadcast domain the client joins
- ARP and DHCP cross the bridge
- fourteen extra bytes per packet
basics
~20 sA routed tunnel carries IP packets into its own subnet; a bridged tunnel carries Ethernet frames and drops the client into the LAN's broadcast domain, so ARP, DHCP and non-IP traffic cross too. Bridge only when something truly needs layer 2.
solid answer
~50 sWith a **routed** (layer 3) interface the tunnel carries IP packets: the client gets an address in a tunnel subnet, the server routes between that subnet and the LAN, and only traffic that is routed to the client crosses. With a **bridged** (layer 2) interface the tunnel carries whole Ethernet frames and the server bridges it into the LAN, so the client sits in the LAN's **broadcast domain**: it can take its address from the LAN's own DHCP server, it answers ARP directly, and every broadcast and non-IP frame on the LAN is copied across the WAN to every bridged client. Each packet also carries a 14-byte Ethernet header. Bridging is worth it only when a protocol or application really needs layer 2 — a non-IP protocol or broadcast-based discovery; otherwise routed is cheaper, scales further and is easier to filter by subnet.
go deeper
Recall that a routed tunnel carries IP packets into its own subnet and a bridged one carries Ethernet frames into the LAN.
Explain what joins the broadcast domain with a bridged client — ARP, DHCP, discovery, non-IP frames — and compute the 14-byte header cost.
Judge when a requirement truly needs layer 2, and describe how bridging extends the LAN's failure domain to every remote client.
Decide the estate default: routed with filtered subnets, and bridging only as a scoped exception with its broadcast load and security exposure accounted for.
## Two kinds of virtual interface A **TLS-based VPN** delivers decrypted traffic into a virtual network interface on each end, and that interface comes in two flavours — the TUN-style and TAP-style interfaces most operating systems provide: - A **layer 3 (routed) interface** exchanges **IP packets**. It has no MAC address; the operating system routes packets into it like any other point-to-point link. - A **layer 2 (bridged) interface** exchanges **Ethernet frames**, MAC header included. It looks like a network card, and the VPN server can bridge it to the LAN's physical port. RFC 4026, the VPN terminology document, draws the same line for provider VPNs: a layer 3 VPN "interconnects sets of hosts and routers based on Layer 3 addresses", while its layer 2 VPN types carry layer 2 service, such as the Virtual Private LAN Service. ## Side by side | Aspect | Routed (layer 3) | Bridged (layer 2) | |---|---|---| | Unit carried | IP packet | Ethernet frame | | Client address | From a tunnel subnet the VPN assigns | Can come from the LAN's own DHCP server | | Broadcasts and ARP | Stay on each side | Cross the tunnel | | Non-IP protocols | Not carried | Carried | | Extra header per packet | None | 14 bytes untagged, 18 with an 802.1Q tag | | Filtering | By tunnel subnet at the server | Needs layer 2 filtering or none | | Scaling | Routing scales with clients | Every client joins one broadcast domain | ## What bridging drags across the tunnel Once the client is in the LAN's broadcast domain, it receives everything the LAN sends to everyone: - **ARP requests.** RFC 826 resolves an IPv4 address by broadcasting a request "to all stations on the Ethernet cable"; on a bridged VPN, "all stations" now includes every remote client. - **DHCP discovery.** A client "broadcasts a DHCPDISCOVER message on its local physical subnet" (RFC 2131) — across a bridge, the LAN's server can answer it. - **Multicast and service discovery** announcements from printers and file servers. - **Non-IP frames** of any legacy protocol on the LAN. Each of those frames is encrypted and sent separately to every bridged client, over links that are slower than the LAN. A broadcast storm on the office LAN becomes a storm in every tunnel. ## The per-packet cost An untagged Ethernet header is two 6-byte MAC addresses and a 2-byte EtherType: **14 bytes**, or 18 with a 4-byte 802.1Q tag. On a 1,400-byte packet that is 1% extra; on a 100-byte voice packet it is 14%. The tunnel's inner MTU drops by the same amount, so the bridged side must be sized for it. ## When bridging is worth it 1. A **non-IP protocol** must reach the LAN — routing cannot carry it at all. 2. An application **discovers peers by broadcast** or link-local multicast and cannot be pointed at an address instead. 3. The remote device must take its address, and the policy attached to it, from the **LAN's own DHCP server**. Outside those cases, routed is the default: no broadcast traffic on the WAN, a clean subnet to write firewall rules against, and no shared failure domain between the office LAN and every laptop on the road. ## A common confusion Bridging is not needed to reach hosts on the office LAN. A routed tunnel reaches them through ordinary routing — provided the LAN's router knows the tunnel subnet lies behind the VPN server, or the server translates client addresses.
- Why can a bridged client get its address from the office DHCP server, while a routed client cannot?A DHCP client starts by broadcasting a DHCPDISCOVER on its local subnet (RFC 2131). A bridge forwards that broadcast into the LAN, so the office server answers. A routed tunnel is its own subnet and routers do not forward broadcasts, so the VPN server assigns the tunnel address itself and pushes it over the control channel.
- What does bridging do to the office LAN's failure domain?It extends it to every bridged client. A broadcast storm, a flood from a misbehaving host or an ARP-heavy scan on the LAN is copied, encrypted, into every tunnel, consuming each client's uplink and the server's CPU; and a misbehaving client injects its frames straight into the LAN. A routed tunnel stops all of that at the server.
saying these in an interview costs you the question
- Bridged mode is faster because it skips routing altogether.
- A routed tunnel cannot reach any host on the office LAN.
- Bridging adds no overhead because the Ethernet header is stripped first.
- A bridged client still needs its own tunnel subnet and routes.
- Routed and bridged differ only in how addresses are handed out.