The Protocol Header Field in IP Packet

IPv4 Protocol field tells the receiver what kind of protocol message is inside the IP datagram’s payload.

So, no—ICMP, IGMP, OSPF, TCP, and UDP are not flags inside the payload. The IPv4 header contains a small numeric field called Protocol, and that number identifies how to interpret the payload.

For example:

IPv4 Datagram
+------------------------+
| IPv4 Header            |
| Protocol = 1           |  ← says "payload is ICMP"
+------------------------+
| ICMP message           |  ← actual payload
+------------------------+

If the Protocol field is 6:

IPv4 Header
Protocol = 6
      ↓
Payload = TCP segment

If it is 17:

Protocol = 17
      ↓
Payload = UDP datagram

And similarly:

IPv4 Protocol valuePayload contains
1ICMP message
2IGMP message
6TCP segment
17UDP datagram
89OSPF packet

So the picture means:

An IP packet can carry different kinds of higher-level or IP-related protocol data inside its payload.

What does ICMP do there?

If:

Protocol = 1

then the IP payload is an ICMP message.

For example:

IP Header
Protocol = 1
+
ICMP Echo Request

That is what ping uses.

Or:

IP Header
Protocol = 1
+
ICMP Destination Unreachable

ICMP is used for control, error reporting, diagnostics, etc.

What about OSPF?

If:

Protocol = 89

the IP payload contains an OSPF packet.

For example:

IP Header
Protocol = 89
+
OSPF Hello packet

Routers use OSPF packets to exchange routing information.

OSPF does not normally sit inside TCP or UDP.

It goes directly inside IP:

IP
└── OSPF

not:

IP
└── UDP
    └── OSPF

ICMP is similar

ICMP also goes directly inside IP:

IP
└── ICMP

TCP and UDP are:

IP
└── TCP
    └── Application data

or:

IP
└── UDP
    └── Application data

That is a very important difference.

So what is the red dot in the diagram?

The red dot represents the idea of multiplexing/demultiplexing.

At the sender, IP may receive data from:

TCP
UDP
ICMP
IGMP
OSPF
...

and encapsulate whichever one is being sent into the IP payload.

Then the IPv4 Protocol field identifies which one it is.

At the receiver:

IPv4 Protocol field
        ↓
   Is it 1?
        ↓
      ICMP

   Is it 6?
        ↓
      TCP

   Is it 17?
        ↓
      UDP

   Is it 89?
        ↓
      OSPF

So it is essentially saying:

“What kind of data is inside my payload?”

One small issue with the diagram

The diagram visually places ICMP, IGMP, and OSPF around the Network layer, which is reasonable. TCP and UDP belong to the Transport layer.

So a cleaner conceptual picture would be:

             TCP       UDP
              \         /
               \       /
                \     /
                 IP
              /  |   \
           ICMP IGMP OSPF

But all five can be carried directly in an IPv4 payload, and the IPv4 Protocol field tells the receiver which one is present.

The key point is:

Protocol field = identifier

Payload = actual TCP, UDP, ICMP, IGMP, or OSPF message

It is not that the payload contains all of them at once. Each individual IP packet normally carries one indicated next protocol.

From AI Tools as is.

Do routers in the Internet Core Use MAC address?

Yes — if the link between two routers is Ethernet, the packet is carried from one router to the next inside an Ethernet frame that uses MAC addresses for that particular hop.

But the important distinction is:

Routers decide where to send the packet using Layer 3 information such as the IP destination (or sometimes an MPLS label), not by using the final destination’s MAC address.

For example:

Host A → Router 1 → Router 2 → Router 3 → Host B

Suppose all links are Ethernet.

Hop 1: Host A → Router 1

IP packet:
Source IP = Host A
Destination IP = Host B

Ethernet frame:
Source MAC = Host A MAC
Destination MAC = Router 1 MAC

Hop 2: Router 1 → Router 2

Router 1 removes the old Ethernet frame, examines the IP packet, chooses Router 2 as the next hop, and creates a new frame:

IP packet:
Source IP = Host A
Destination IP = Host B

New Ethernet frame:
Source MAC = Router 1's outgoing-interface MAC
Destination MAC = Router 2's MAC

Hop 3: Router 2 → Router 3

Again:

Source MAC = Router 2
Destination MAC = Router 3

The MAC addresses change at every Ethernet hop.

So:

IP addresses:  mostly end-to-end
MAC addresses: hop-to-hop

A useful diagram is:

Host A          R1             R2             R3          Host B
 IP A                                                   IP B

MAC A → MAC R1
                 MAC R1 → MAC R2
                                  MAC R2 → MAC R3
                                                  MAC R3 → MAC B

IP A --------------------------------------------------> IP B

But not every Internet-core link has to use MAC addresses

This is the important qualification.

A router-to-router link could use:

  • Ethernet → MAC addresses are used
  • PPP → no Ethernet MAC addressing
  • MPLS → labels may be used for forwarding through the provider network
  • other Layer-2 technologies → their own framing/addressing rules

Today, Ethernet is very common even between routers, so MAC addresses are often involved. But it is more accurate to say:

Each router forwards the IP packet to the next hop using the Layer-2 mechanism of that particular link. If the link is Ethernet, that mechanism includes source and destination MAC addresses.

So I would not say:

“The Internet core routes packets using MAC addresses.”

I would say:

The Internet core routes packets using Layer 3 routing, while each individual Ethernet hop uses MAC addresses to deliver the frame to the next router.

From AI Tools as is

Electrical Signal vs. Electromagnetic Signal

An electrical signal is a changing electrical quantity, usually voltage or current, in a wire, cable, or electronic circuit.

Examples include:

  • signals traveling through copper Ethernet cables,
  • audio signals inside electronic circuits,
  • voltage pulses inside digital electronics.

A simple way to think about it is:

Electrical signal = changing voltage and/or current

For example:

Voltage
  ↑
  |      /‾\      /‾\
  |     /   \    /   \
  |____/     \__/     \____ → Time

The graph shows how the voltage changes over time.

An electromagnetic signal is a changing combination of electric and magnetic fields that propagates through space or through a medium.

Examples include:

  • Wi-Fi signals,
  • cellular signals,
  • radio broadcasts,
  • satellite communication,
  • microwave communication.

A simple way to think about it is:

Electromagnetic signal = changing electric and magnetic fields traveling as a wave

For Wi-Fi, the process is approximately:

Digital data
    ↓
Electrical signal inside the device
    ↓
Antenna
    ↓
Electromagnetic radio signal
    ↓
Air

The antenna converts the high-frequency electrical signal in the circuit into an electromagnetic wave that travels through the air.

Main Difference

Electrical SignalElectromagnetic Signal
Usually described in terms of voltage and currentDescribed in terms of electric and magnetic fields
Commonly travels through conductors or circuitsCan travel through air or space
Example: copper Ethernet cableExample: Wi-Fi
Often measured as voltage versus timeOften discussed as radio waves, frequency, field strength, or wavelength

The two ideas are related.

A changing electrical current can create changing electric and magnetic fields. This is how an antenna produces a radio signal.

Similarly, when an electromagnetic radio wave reaches a receiving antenna, it causes a small electrical signal in the antenna and receiver circuitry.

So the relationship can be shown as:

Electrical signal
      ↓
    Antenna
      ↓
Electromagnetic signal
      ↓
    Antenna
      ↓
Electrical signal

For networking, a simple distinction is:

  • Copper cable → electrical signal
  • Fibre-optic cable → optical/light signal
  • Wi-Fi → electromagnetic/radio signal

One subtle point is that electrical signals in real cables also involve electromagnetic fields physically. However, in normal engineering and networking terminology, a signal carried through a copper conductor is usually called an electrical signal, while a wireless signal traveling through the air is usually called an electromagnetic or radio signal.

From AI Tools as is.

Signal and Electrical Signal

A signal is a physical quantity that changes over time or space.

Examples include changes in sound pressure, light, temperature, voltage, or current.

An electrical signal is a changing electrical quantity, usually voltage or current.

In electrical and electronics textbooks, signals are often shown as graphs:

Voltage
  ↑
  |      /‾\      /‾\
  |     /   \    /   \
  |____/     \__/     \____ → Time

In this graph:

  • the horizontal axis represents time,
  • the vertical axis represents the signal value, often voltage,
  • the curve shows how that value changes over time.

So, in simple terms:

Signal: a physical quantity that changes.
Electrical signal: a voltage or current that changes over time.

From AI Tools as is.

From AI Tools as is.

Electrical Signals: What Is Really Traveling Through a Wire?

Electrical Signals: What Is Really Traveling Through a Wire?

When people hear the phrase electrical signal, it is easy to imagine electricity as something flowing through a wire like water through a pipe. That picture is useful in some situations, but it does not fully describe what is happening in communication systems.

An electrical signal is better understood as a controlled change in electrical quantities, especially voltage and current, over time. In cables and transmission lines, these changes are associated with electromagnetic fields that propagate along the conductors.

What Is an Electrical Signal?

At a simple level:

An electrical signal is a changing voltage and/or current that can represent information.

For example, a communication system might use different electrical conditions to represent digital data:

Data:        1       0       1       1

Voltage:    High     Low     High    High

The actual encoding used in modern networks can be much more sophisticated, but the basic idea is the same: information is represented by controlled electrical changes.

Is an Electrical Signal Voltage or Current?

It can involve both.

Voltage and current are closely related in an electrical circuit or transmission line.

  • Voltage is the electrical potential difference between two points.
  • Current is the movement of electric charge.
  • An electrical signal generally involves time-varying voltage and corresponding current.

For introductory explanations, electrical signals are often shown as voltage changing over time, because voltage is easy to visualize on a graph.

For example:

Voltage

5 V     ────────          ────────
               │          │
0 V            └──────────┘
          time →

But this graph is only one representation of the physical signal.

What Is Actually Happening in the Wire?

A real electrical communication signal is more than voltage values appearing at different moments.

In a cable:

  • voltage changes,
  • current changes,
  • an electric field exists between conductors,
  • a magnetic field exists around the conductors,
  • electromagnetic energy propagates along the cable.

A more complete description is:

A real electrical signal is an electromagnetic disturbance guided by the conductors, represented electrically by changing voltage and current.

This becomes especially important when dealing with high-speed communication systems such as Ethernet.

What Is a Conductor?

A conductor is a material that allows electric charge to move relatively easily.

Common conducting materials include:

  • copper,
  • aluminum,
  • silver.

In networking cables, copper is very common.

For example, a simple pair of conductors might look like:

Copper conductor A  ─────────────────────

Copper conductor B  ─────────────────────

The electrical signal is related to the voltage difference between these conductors and the current flowing through them.

Twisted-Pair Ethernet

Ethernet cables commonly use twisted pairs of copper wires.

A simplified pair looks like:

Wire 1   ~~~~~~~\
                 } Twisted pair
Wire 2   ~~~~~~~/

The two wires are twisted around each other.

Ethernet commonly uses differential signaling, which means that the receiver is interested mainly in the voltage difference between the two wires rather than simply the voltage on one wire relative to ground.

Conceptually:

Wire A voltage:    rises
Wire B voltage:    falls

Receiver examines:
Voltage A - Voltage B

This approach helps the communication system resist electrical noise.

Does Electricity Travel Through the Wire?

This question needs careful wording.

Electric charge does move in conductors, but the electrons themselves do not race from the transmitter to the receiver at the speed of the communication signal.

Individual electrons usually have a relatively slow average drift.

The electromagnetic disturbance, however, propagates along the cable much faster—typically a significant fraction of the speed of light.

So when data is sent through an Ethernet cable:

The same individual electrons are not carrying the data all the way from one computer to another.

Instead, changes in the electromagnetic field propagate through the transmission line.

A useful analogy is a long row of closely spaced objects. Movement at one end can produce an effect that travels along the row even though each individual object moves only a small distance.

The Signal Is Not Just Inside the Copper

Another important idea is that the electromagnetic energy associated with the signal is not confined entirely inside the metal conductor.

Electric and magnetic fields exist around and between the conductors.

The conductors help establish and guide these fields.

Therefore, a more accurate statement than:

“The electricity travels inside the wire”

is:

The conductors guide an electromagnetic signal along the cable.

For everyday explanations, saying that an electrical signal travels through a wire is still perfectly reasonable. The electromagnetic description simply explains the physical process more accurately.

Electrical Signals and Digital Data

Suppose a computer needs to transmit:

10110100

Those 0s and 1s are data.

They are abstract symbols. Literal 0s and 1s do not travel through the copper cable.

The network interface converts the digital information into electrical signal patterns.

Conceptually:

Digital data
     ↓
Electrical encoding
     ↓
Changing voltage/current
     ↓
Cable
     ↓
Receiver detects signal
     ↓
Digital data reconstructed

This is the connection between data and signals.

Data is the representation of information.
The electrical signal is the physical mechanism used to carry that data.

Does a Digital Signal Have to Be a Square Wave?

No.

Diagrams often show digital signals as simple high and low voltage levels:

      ┌───────┐       ┌───────┐
──────┘       └───────┘       └────

This is useful for explaining basic digital concepts, but real high-speed signals usually do not look like perfect square waves.

Real systems are affected by:

  • resistance,
  • capacitance,
  • inductance,
  • bandwidth limitations,
  • attenuation,
  • reflections,
  • interference,
  • noise.

Modern communication systems also use sophisticated signaling and coding methods.

Therefore:

Digital data does not mean that the real physical signal must look like perfect rectangular pulses.

Signal Versus Power

Electrical signals also relate to electrical power.

For a basic DC situation:\[ P = V \times I \]

where:

  • \(P\) = power in watts,
  • \(V\) = voltage in volts,
  • \(I\) = current in amperes.

For example:\[ 10\text{ V} \times 2\text{ A} = 20\text{ W} \]

So the device is using or transferring power at a rate of:\[ 20\text{ watts} \]

Power Is Not Energy

Power and energy are related, but they are not the same thing.

Power tells us how quickly energy is being transferred or used.

Energy includes time:\[ E = P \times t \]

Since:\[ P = V \times I \]

we can write:\[ E = V \times I \times t \]

If a device uses 20 W for one hour:\[ 20\text{ W} \times 1\text{ h} = 20\text{ Wh} \]

So:

Voltage × Current = Power

while:

Voltage × Current × Time = Energy

This is also why electricity bills commonly use kilowatt-hours:\[ 1\text{ kWh} = 1000\text{ Wh} \]

Signals and Power Are Related but Different Concepts

An electrical communication signal contains energy, but its main purpose is often to represent information, not simply to deliver useful electrical power.

Compare two systems:

Electrical power cable

The main goal is to transfer energy.

Power source
    ↓
Electrical energy
    ↓
Appliance

Communication cable

The main goal is to communicate information.

Data
 ↓
Electrical signal
 ↓
Cable
 ↓
Signal detected
 ↓
Data recovered

Both involve voltage, current, energy, and electromagnetic fields, but their primary purposes are different.

A Useful Mental Model

At different levels of detail, electrical signals can be described in different ways.

At the simplest level:

An electrical signal is voltage changing over time.

A more complete description is:

An electrical signal involves changing voltage and current.

At the physical level:

An electrical communication signal is an electromagnetic wave or disturbance guided by conductors, represented by changing voltage and current.

All three statements can be useful. The difference is simply the level of detail.

Putting Everything Together

A communication system using copper can be summarized as:

Information
     ↓
Data
     ↓
Electrical encoding
     ↓
Changing voltage and current
     ↓
Electromagnetic signal
     ↓
Copper conductors guide the signal
     ↓
Receiver detects the electrical changes
     ↓
Data reconstructed
     ↓
Information recovered

The key idea is that an electrical signal is not simply “electrons carrying bits through a wire.”

It is a physical electromagnetic phenomenon involving voltage, current, electric fields, and magnetic fields, used in a controlled way to carry information from one location to another.

From AI Tools as Is:

Data and Signals: A Simple Way to Understand How Communication Works

Most digital communication can be understood with one simple idea:

Data and Signals: A Simple Way to Understand How Communication Works

Data is the information represented in a form that a system can use. A signal is the physical way that data is carried from one place to another.

This distinction sounds technical at first, but it becomes much easier when connected to everyday examples such as phone calls, Wi-Fi, music streaming, text messages, and fibre-optic Internet.

Information, Data, Signal, and Medium

These four ideas are related, but they are not the same.

Information is the meaning that someone wants to communicate.

For example:

“The meeting starts at 9:00.”

That sentence has meaning. That meaning is the information.

Data is the representation of that information.

A computer may represent text using numbers, and ultimately using bits such as:

01001000 01100101 01101100 01101100 01101111

These bits are data.

However, written 0s and 1s do not physically travel through a cable or through the air. Something physical must represent them.

That is where the signal comes in.

A signal is a physical quantity that changes in a controlled way so that it can represent data. Depending on the communication system, the signal may involve:

  • electrical changes in copper,
  • light in optical fibre,
  • radio waves through the air.

The medium is the path through which that signal travels.

So the overall idea is:

Information → Data → Signal → Medium → Signal → Data → Information

A Simple Phone Example

Imagine saying:

“Hello.”

The meaning of “Hello” is the information.

A modern phone converts the sound of the voice into digital data. That data is then represented by signals and transmitted through the communication network.

The path might look conceptually like this:

Voice
  ↓
Digital data
  ↓
Signal
  ↓
Communication network
  ↓
Signal
  ↓
Digital data
  ↓
Sound

The receiver does not receive the original sound travelling all the way from one mouth to another. The communication system converts, represents, transmits, reconstructs, and plays the information.

What Does a Sound Wave Represent?

Sound is a useful example because it shows the difference between information and a physical signal.

A sound wave in air is created by variations in air pressure.

As sound travels, regions of higher and lower pressure move through the air.

These are commonly described as:

Compression — a region of relatively higher air pressure.

Rarefaction — a region of relatively lower air pressure.

A graph of a sound wave may look like this:

Pressure / amplitude
        ↑
        |      /‾\      /‾\
        |     /   \    /   \
--------|----/-----\--/-----\----→ Time
        |   /       \/       \
        |

The wavy line does not mean that air molecules literally fly through the air in a curved path like that.

The graph simply shows how pressure changes over time.

The air molecules mainly vibrate back and forth around their normal positions while the pressure disturbance travels.

What Does a Signal Graph Mean?

A signal graph can be understood as a picture of:

How some physical quantity changes over time.

The horizontal direction normally represents time.

The vertical direction represents some measurable property, such as:

  • voltage,
  • signal strength,
  • air pressure,
  • light intensity.

For example:

Signal strength
      ↑
      |       /\        /\
      |      /  \      /  \
      |_____/    \____/    \_____ → Time

This picture simply says that the signal becomes stronger and weaker as time passes.

Once that basic idea is clear, several common terms become easier to understand.

Amplitude describes how large or strong the signal variation is.

Frequency describes how often the pattern repeats.

Period describes how long one complete repetition takes.

Wavelength describes the physical distance covered by one complete repeating cycle of a wave.

Data Is Abstract; Signals Are Physical

One of the most useful ways to remember the distinction is:

Data is abstract. Signals are physical.

For example:

10110010

is data.

A physical communication system may represent that data using changing voltage levels, light patterns, or radio waves.

A very simplified electrical representation might look like:

Data:     1   0   1   1   0

Signal:  HIGH LOW HIGH HIGH LOW

Real communication systems can use much more sophisticated encoding, but the basic principle remains the same:

Physical signals represent data.

Text Messages Do Not Literally Fly Through the Air

Suppose a phone sends:

“Hi”

over Wi-Fi.

The letters H and i do not physically fly through the room.

The phone converts the text into digital data.

That digital data is processed by networking hardware and represented in a radio signal.

The radio signal travels through the air.

A receiving device detects the radio signal and reconstructs the data.

So the process is closer to:

"Hi"
 ↓
Digital representation
 ↓
Bits
 ↓
Radio signal
 ↓
Air
 ↓
Radio signal received
 ↓
Bits reconstructed
 ↓
"Hi"

This is one of the clearest examples of the difference between data and signal.

What Happens in Copper, Fibre, and Wireless?

The same data can be carried using very different physical signals.

Communication mediumTypical physical signal
Copper cableElectrical changes
Optical fibreLight
Wi-FiRadio waves
Cellular networkRadio waves
Satellite communicationRadio/microwave signals

The data may remain logically the same even though the physical way of carrying it changes.

For example, an Internet packet may travel:

Laptop
  ↓
Wi-Fi radio
  ↓
Access point
  ↓
Electrical Ethernet signal
  ↓
Router
  ↓
Optical fibre signal
  ↓
Service-provider network

The same communication may pass through several different signal types before reaching its destination.

Analog and Digital

Another common distinction is between analog and digital.

An analog quantity changes continuously.

Natural sound is a good example. Air pressure varies continuously as someone speaks.

A digital representation uses discrete values.

Computers commonly represent data using binary values:

0 and 1

A microphone and digital audio system may therefore perform a process conceptually like:

Continuous sound
      ↓
Measurements / samples
      ↓
Numbers
      ↓
Digital data

The reverse happens during playback:

Digital data
      ↓
Audio reconstruction
      ↓
Speaker movement
      ↓
Sound waves

Digital Data Does Not Mean Square Waves Everywhere

A common misunderstanding is to imagine that digital communication always means perfect square-shaped electrical pulses.

Digital data may be represented by many kinds of physical signals.

For example, radio communication may encode digital information by changing properties such as:

  • amplitude,
  • frequency,
  • phase,
  • combinations of these.

Therefore:

Digital describes the data representation, not necessarily the shape of the physical signal.

A Music Streaming Example

Consider listening to music over Wi-Fi.

The music is the information.

The audio file contains digital data.

The networking system processes that data.

Wi-Fi converts networking data into radio signals.

The signal travels through the air.

The receiving device reconstructs the data.

The audio system converts the digital audio into electrical signals that drive a speaker.

The speaker produces sound waves.

So one communication chain may look like:

Music
 ↓
Digital audio data
 ↓
Network data
 ↓
Wi-Fi radio signal
 ↓
Air
 ↓
Wi-Fi receiver
 ↓
Network data
 ↓
Digital audio
 ↓
Speaker
 ↓
Sound

This shows that communication frequently involves several kinds of representation and several kinds of signals.

Why This Distinction Matters

Understanding data and signals makes many networking concepts easier.

It helps explain:

  • why computers use bits,
  • why networks need physical media,
  • why Wi-Fi uses radio,
  • why fibre uses light,
  • why copper carries electrical signals,
  • why the same data can travel through different media,
  • why signal quality affects communication,
  • why data can remain unchanged even when the physical transmission technology changes.

It also helps separate two questions that are often mixed together:

What information are we sending?

and

How are we physically carrying it?

The first is mainly about information and data.

The second is mainly about signals and transmission media.

The Simplest Mental Model

The entire subject can be summarized with four ideas:

Information is what we mean.
Data is how we represent it.
Signal is how we physically carry it.
Medium is where the signal travels.

Or, in one line:

Information → Data → Signal → Medium → Signal → Data → Information

That simple chain explains a surprisingly large part of modern communication—from voice calls and Wi-Fi to fibre optics, mobile networks, satellite systems, and the Internet.

From AI Tools as is.

What does sound wave represent

From AI as is:

A sound wave represents changes in pressure in a medium—usually air—as the sound travels.

In air, molecules vibrate back and forth, creating alternating regions of:

  • Compression — higher pressure
  • Rarefaction — lower pressure

So when you see a sound-wave graph, the vertical axis usually represents pressure variation or signal amplitude, while the horizontal axis represents time or distance.

A simple sinusoidal sound wave:

Amplitude / Pressure
      ↑
      |      /‾\      /‾\
      |     /   \    /   \
------|----/-----\--/-----\----→ Time
      |   /       \/       \
      |  /

Important points:

  • Amplitude → relates to sound intensity/loudness
  • Frequency → relates to pitch
  • Wavelength → distance between repeating points such as two compressions
  • Period → time for one complete cycle

One important clarification: the wavy line does not mean air molecules themselves travel in a sine-wave path. The molecules mainly move back and forth around their normal positions while the pressure disturbance travels forward.

The Hidden Firewall: How Public Wi-Fi Keeps Your Devices Apart

The Hidden Firewall: How Public Wi-Fi Keeps Your Devices Apart : From AI tools as is

Have you ever sat in a crowded coffee shop, connected to the free Wi-Fi, and wondered: If dozens of us are on the exact same network, why can’t I see anyone else’s computer?

It’s a valid question. When you connect to a local area network (LAN)—like the one in your home—your devices generally talk to each other without issue. Your phone can cast a video to your TV, your laptop can send a file to your printer, and you can share folders across computers.

So why doesn’t that happen when you connect to a public hotspot?

Let’s break down how public Wi-Fi networks manage dozens of simultaneous connections, how they stop strangers from peering into your laptop, and what options you have when you actually do need to share data with someone sitting right next to you.

1. The Basics: Does Everyone Get an IP Address?

Yes. The moment your phone or laptop connects to a public hotspot, the router assigns it a unique private IP address.

This happens through a protocol called DHCP (Dynamic Host Configuration Protocol). The network’s router acts as a traffic controller:

  • It hands out private IP addresses (typically starting with 192.168.x.x or 10.x.x.x) to every single connected device.
  • It uses these unique IP addresses to manage incoming and outgoing data, making sure that the web page you requested ends up on your screen and not on the laptop of the person sitting two tables over.

From a networking standpoint, every device connected to that hotspot forms a single Wireless Local Area Network (WLAN).

2. The Security Barrier: Why Devices Can’t See Each Other

If everyone is on the same local network, shouldn’t you be able to “ping” or browse the device next to you?

On an unmanaged or default home network, yes. But public networks implement a fundamental security feature known as AP Isolation (Access Point Isolation), also referred to as Client Isolation.

     [ Public Wi-Fi Router ]
         /          \
        /            \
       v              v
  [ Your Laptop ]  x  [ Stranger's Laptop ]
                 (Blocked by AP Isolation)

How AP Isolation Works

When AP Isolation is enabled on a router:

  1. Vertical Traffic is Allowed:Your computer can send data up to the router to access the wider internet, and the router can send data back down to your computer.
  2. Horizontal Traffic is Dropped:The router is configured to block direct frame forwarding between wireless clients connected to the same network. If your laptop sends a packet aimed at another laptop’s local IP address, the router simply drops it.

Without AP Isolation, public Wi-Fi would be a free-for-all. A malicious user on the network could easily scan the local IP range, discover exposed network shares, attempt ARP spoofing attacks, or probe open ports on vulnerable devices.AP Isolation ensures that every connected device sits in its own digital quarantine.

3. Can You Bypass AP Isolation?

A common question among networking students and tech enthusiasts is whether an end-user can override this setting to access other devices on the network.

The short answer is no.

Because AP Isolation is enforced at Layer 2 (the data link layer) directly inside the router’s hardware/firmware, you cannot bypass it via software tweaks or terminal commands on your own device. The router is the central gatekeeper; if its rulebook says “do not forward packets between client A and client B,” your traffic goes nowhere.

Only the network administrator with direct access to the router’s management panel can enable or disable Client Isolation.

4. How to Connect Devices on Public Wi-Fi

If AP Isolation blocks local communication, how can you share a file or play a local multiplayer game with a friend sitting next to you at a coffee shop?

You have to route around the router’s local restrictions using one of these four methods:

MethodHow It WorksBest Used For
Cloud / Internet RoutingData travels vertically up to the internet (e.g., via Google Drive, Dropbox, or email) and back down to the destination device.Basic file sharing and document collaboration.
Peer-to-Peer WirelessProtocols like Apple AirDrop, Google Quick Share, or Wi-Fi Direct bypass the router entirely. Devices negotiate a direct radio link between their Wi-Fi cards.Fast, local transfers without using mobile data.
Virtual Private Networks (Mesh VPNs)Tools like Tailscale or ZeroTier build an encrypted overlay network over the internet. Both devices see each other as if they were on a private LAN.Remote access, SSH, and local development testing.
Personal HotspotOne device shares its cellular connection, creating an entirely new, unisolated Wi-Fi LAN for both users.Local gaming, wireless debugging, or private file servers.

Summary

Public Wi-Fi networks give everyone an IP address, but AP Isolation keeps those devices completely isolated from one another.It’s one of the simplest and most effective layers of protection in public network design—ensuring you can enjoy your coffee and surf the web without worrying about who else is sharing the airwaves.

One Physical Switch, Multiple VLANs: How VLANs Work, How to Configure Them, and Where IP Subnets Fit In

One Physical Switch, Multiple VLANs: How VLANs Work, How to Configure Them, and Where IP Subnets Fit In

From AI tools as IS.

A single managed Ethernet switch can behave as though it were several independent switches.

This is the basic idea behind a VLAN — Virtual Local Area Network.

Suppose an organization has one 24-port switch. Without VLANs, all 24 ports could belong to the same Layer 2 network. Broadcast traffic generated by one device could potentially reach devices connected to all of the other ports.

With VLANs, the same physical switch can be divided logically:

                 One Physical Switch
        ┌──────────────────────────────┐
        │ Ports 1–8   → VLAN 10       │
        │ Ports 9–16  → VLAN 20       │
        │ Ports 17–23 → VLAN 30       │
        │ Port 24     → Trunk         │
        └──────────────────────────────┘

The result is similar to having three separate logical switches inside one physical device.

VLAN 10        VLAN 20        VLAN 30
Staff          Accounting     Guests
   │               │             │
   └──────── One Physical Switch ┘

The important question is: what actually creates the separation?

It is not the VLAN name. It is not the IP address. It is the VLAN ID and the switch configuration.


What Actually Separates One VLAN From Another?

Each VLAN has a numerical identifier.

For example:

VLAN 10
VLAN 20
VLAN 30

Names can optionally be attached:

VLAN 10 = STAFF
VLAN 20 = ACCOUNTING
VLAN 30 = GUESTS

But the names are only for administrators.

The actual distinction is:

VLAN ID 10 ≠ VLAN ID 20 ≠ VLAN ID 30

The switch maintains separate Layer 2 forwarding environments for the different VLANs.

If Port 1 belongs to VLAN 10 and Port 10 belongs to VLAN 20, traffic does not simply flow between those ports merely because they are on the same physical switch.

A broadcast arriving in VLAN 10 remains in VLAN 10.

PC-A
 │
 │ VLAN 10 broadcast
 ▼
Switch
 ├── VLAN 10 devices receive it
 └── VLAN 20 devices do NOT receive it

This is why each VLAN is normally described as a separate Layer 2 broadcast domain.


How Does a Switch Know Which VLAN a Device Belongs To?

For an ordinary user device, the administrator typically assigns the physical switch port to a VLAN.

For example:

Port 1 → VLAN 10
Port 2 → VLAN 10
Port 3 → VLAN 10

Port 4 → VLAN 20
Port 5 → VLAN 20

These ports are commonly called access ports.

A computer connected to an access port normally does not need to know anything about VLAN tagging.

The computer sends a normal Ethernet frame.

The switch already knows:

Frame entered Port 1
Port 1 belongs to VLAN 10
Therefore this frame belongs to VLAN 10

The VLAN membership is being enforced by the switch.


How Are VLANs Created?

On a managed switch, VLANs are normally created through one of several management mechanisms:

  • command-line interface;
  • web interface;
  • centralized network controller;
  • cloud management platform;
  • network-management API.

For example, on a Cisco-style command-line interface:

vlan 10
 name STAFF

vlan 20
 name ACCOUNTING

vlan 30
 name GUESTS

Then ports can be assigned to the VLANs.

For example:

interface GigabitEthernet0/1
 switchport mode access
 switchport access vlan 10

Another port could be placed into VLAN 20:

interface GigabitEthernet0/2
 switchport mode access
 switchport access vlan 20

The exact commands vary by manufacturer, but the concept is essentially the same.

The administrator:

creates a VLAN ID → assigns ports → optionally assigns a name → optionally configures Layer 3 addressing.


Does Creating a VLAN Require an IP Address?

No.

This is one of the most important facts about VLANs:

A VLAN can exist without any IP address.

VLANs operate primarily at Layer 2.

Ethernet switches can forward Ethernet frames based on MAC addresses without IPv4 or IPv6 being present.

For example:

PC-A ─ Port 1 ─┐
               │ VLAN 10
PC-B ─ Port 2 ─┘

PC-A and PC-B could exchange Layer 2 Ethernet frames even if neither has an IP address.

The VLAN still exists.

The switch still keeps its traffic separate from VLAN 20.


Does the Switch Need an IP Address?

A basic Layer 2 switch does not need an IP address to switch frames.

It can perform:

MAC learning
        ↓
MAC table lookup
        ↓
Ethernet frame forwarding

without an IP address assigned to the switch itself.

However, a managed switch normally has a management IP address so an administrator can remotely access it using technologies such as:

SSH
HTTPS
SNMP
Network controller

That IP address is for managing the switch.

It is not what makes Layer 2 switching possible.

A switch could even be configured through a local console connection without having an IP address at all.


Does a VLAN Require IP Subnetting?

No.

Creating VLANs and creating IP subnets are two separate operations.

A VLAN belongs to Layer 2:

VLAN 10

An IP subnet belongs to Layer 3:

192.168.10.0/24

Therefore:

Subnetting does not create VLANs, and VLAN creation does not automatically create IP subnets.

They are separate concepts.

But in ordinary modern IP networks, they are normally used together.


The Normal Design: One VLAN, One IP Subnet

A common design is:

VLAN 10 → 192.168.10.0/24
VLAN 20 → 192.168.20.0/24
VLAN 30 → 192.168.30.0/24

This means:

          Layer 2                 Layer 3

VLAN 10 ───────────────→ 192.168.10.0/24

VLAN 20 ───────────────→ 192.168.20.0/24

VLAN 30 ───────────────→ 192.168.30.0/24

This is normally the best and cleanest design.

It gives each Layer 2 broadcast domain its own Layer 3 network.


VLAN and Subnet Are Not the Same Thing

They are often paired so closely that it is tempting to think they are identical.

They are not.

VLANIP Subnet
Layer 2 conceptLayer 3 concept
Divides Ethernet networksDivides IP address space
Uses VLAN IDsUses network prefixes
Example: VLAN 10Example: 192.168.10.0/24
Determines broadcast domainDetermines which IP addresses are on-link
Enforced mainly by switchesUsed by hosts and routers

A useful way to remember it is:

VLAN tells Ethernet which Layer 2 network a device belongs to.

Subnet tells IP which Layer 3 network an address belongs to.


Can a VLAN Work Without IP?

Absolutely.

For example:

VLAN 50

may contain equipment communicating through some Layer 2 protocol without using IPv4 or IPv6.

Ethernet itself does not require IP.

A VLAN can also exist simply because an administrator has created it, even if no devices are currently connected.

So this is perfectly possible:

VLAN 10
Ports 1–4
No IP addresses

The Layer 2 separation still exists.


What Changes Once IP Is Introduced?

Suppose VLAN 10 contains:

PC-A
IP: 192.168.10.10/24

PC-B
IP: 192.168.10.20/24

Both belong to:

VLAN 10
Subnet 192.168.10.0/24

Communication is straightforward.

PC-A sees that 192.168.10.20 belongs to its own subnet.

It uses ARP to discover PC-B’s MAC address.

Conceptually:

PC-A:

Who has 192.168.10.20?

The ARP request is an Ethernet broadcast.

Because PC-B is in the same VLAN, it receives the request.

PC-B responds with its MAC address.

PC-A can then send:

Ethernet:
Destination MAC = PC-B

IP:
Destination IP = 192.168.10.20

The Layer 2 switch forwards the frame based primarily on the destination MAC address.

No router is needed.


What If Two VLANs Use Different IP Networks?

This is the normal design.

For example:

VLAN 10
192.168.10.0/24

and:

VLAN 20
192.168.20.0/24

Suppose:

PC-A = 192.168.10.10

needs to communicate with:

PC-B = 192.168.20.20

PC-A realizes:

192.168.20.20 is NOT in my subnet

Therefore, it sends the packet to its default gateway.

That gateway might be:

192.168.10.1

located on a router or Layer 3 switch.

The path becomes:

PC-A
VLAN 10
192.168.10.10
       │
       ▼
Layer 3 Switch / Router
       │
       ▼
PC-B
VLAN 20
192.168.20.20

This is called inter-VLAN routing.


What If Two Separate VLANs Use the Same IP Subnet?

This is where problems begin.

Suppose:

VLAN 10
PC-A = 192.168.1.10/24

and:

VLAN 20
PC-B = 192.168.1.20/24

Both devices believe they belong to:

192.168.1.0/24

PC-A wants to reach:

192.168.1.20

It checks its subnet mask and concludes:

“That device is on my local network. I don’t need my router.”

So PC-A sends an ARP broadcast:

Who has 192.168.1.20?

But that broadcast exists in:

VLAN 10

PC-B is in:

VLAN 20

VLAN boundaries prevent the broadcast from crossing.

PC-B therefore never receives the ARP request.

PC-A cannot learn PC-B’s MAC address.

Communication normally fails.


Why Doesn’t the Router Fix It?

Because PC-A does not initially send the packet to the router.

PC-A believes:

192.168.1.20 = local address

So it tries direct Layer 2 delivery.

That is exactly what the subnet mask tells a host to do.

The host effectively thinks:

Same subnet
    ↓
Find destination MAC
    ↓
Send directly

But VLAN separation prevents the necessary Layer 2 discovery.

This creates a mismatch:

IP says:       SAME NETWORK

VLAN says:     DIFFERENT LAYER 2 NETWORK

That is why spreading the same ordinary IP subnet across separate, non-bridged VLANs is normally a bad design.


Could Special Technologies Make It Work?

Yes.

There are specialized techniques involving:

  • proxy ARP;
  • Layer 2 bridging;
  • overlays;
  • stretched VLANs;
  • certain data-centre architectures;
  • specialized gateways.

But those are exceptions.

They do not change the fundamental design recommendation:

Separate VLANs should normally use separate IP subnets.


What If One VLAN Contains Multiple IP Subnets?

Interestingly, the reverse is technically possible.

Suppose one VLAN contains devices from:

192.168.10.0/24

and:

192.168.20.0/24

Both groups exist inside the same Layer 2 broadcast domain.

This can be made to work.

For example, a router or Layer 3 switch could have gateway addresses for both subnets.

But it is usually undesirable.

Why?

Because the Layer 2 and Layer 3 boundaries no longer match.

You might have:

           ONE VLAN
              │
      ┌───────┴───────┐
      │               │
192.168.10.0/24   192.168.20.0/24

Both groups share the same Ethernet broadcasts, even though they are logically separate IP networks.

This can make:

  • troubleshooting harder;
  • DHCP design more complicated;
  • security policies less intuitive;
  • network documentation confusing;
  • broadcast domains unnecessarily large.

So although it can work:

Multiple subnets inside one VLAN are normally avoided unless there is a specific operational reason.


The Cleanest Design

The most predictable architecture is:

VLAN 10
      │
      └── 192.168.10.0/24

VLAN 20
      │
      └── 192.168.20.0/24

VLAN 30
      │
      └── 192.168.30.0/24

This creates matching boundaries:

Layer 2 boundary
       =
Layer 3 boundary

Operationally, that is much easier to understand.


Where Does a Layer 3 Switch Fit In?

A Layer 2 switch can create VLANs and switch frames within them.

But it cannot normally route traffic between different IP subnets.

A Layer 3 switch can do both.

For example:

        Layer 3 Switch
       /       |       \
      /        |        \
 VLAN 10    VLAN 20    VLAN 30
    │           │          │
192.168.10   192.168.20   192.168.30
 .0/24        .0/24        .0/24

The Layer 3 switch can create a logical Layer 3 interface for each VLAN.

These are commonly called SVIs — Switched Virtual Interfaces.

For example:

VLAN 10 gateway = 192.168.10.1
VLAN 20 gateway = 192.168.20.1
VLAN 30 gateway = 192.168.30.1

Then the switch can perform routing between the VLANs.


One Switch Can Therefore Perform Two Different Jobs

A Layer 3 switch might handle traffic in two different ways.

When two devices are in the same VLAN:

PC-A → Layer 2 switching → PC-B

The switch primarily uses MAC addresses.

When devices are in different VLANs/subnets:

PC-A
   ↓
Layer 3 routing
   ↓
PC-C

the switch examines IP addresses and performs routing.

So the same physical device can perform:

Layer 2 switching
+
Layer 3 routing

What About VLANs Across Multiple Switches?

VLANs are not limited to one physical switch.

Suppose:

Switch A                  Switch B
---------                 ---------
VLAN 10                   VLAN 10
VLAN 20                   VLAN 20
VLAN 30                   VLAN 30

One physical connection between the switches can carry traffic from several VLANs.

This is normally done using a trunk.

Switch A
   │
   │  VLAN 10
   │  VLAN 20
   │  VLAN 30
   │
   │  Trunk
   │
Switch B

Ethernet frames travelling across a trunk commonly contain an IEEE 802.1Q VLAN tag.

Conceptually:

Ethernet Frame

Destination MAC
Source MAC
VLAN ID = 20
Payload

The VLAN ID tells the receiving switch which logical network the frame belongs to.

Multiple VLANs can therefore share the same physical cable while remaining logically separated.


Access Port vs. Trunk Port

These two terms are fundamental.

An access port normally carries traffic for one VLAN and connects to an ordinary end device:

PC
 │
 │ Access port
 │ VLAN 10
 ▼
Switch

A trunk port normally carries multiple VLANs:

Switch
   │
   │ VLAN 10
   │ VLAN 20
   │ VLAN 30
   │
   ▼
Switch

Trunks are commonly used between:

  • switches;
  • switches and routers;
  • switches and servers;
  • switches and virtualization hosts;
  • switches and wireless infrastructure.

Why Use Multiple VLANs on One Switch?

Consider an office with employees, servers, security cameras, and guests.

Without VLANs:

Employees
Servers
Guests
Cameras
      │
      ▼
One large Layer 2 network

With VLANs:

VLAN 10 → Employees
VLAN 20 → Servers
VLAN 30 → Guests
VLAN 40 → Cameras

The organization gains logical separation without purchasing four completely separate sets of switches.

It can also apply different:

  • security policies;
  • firewall rules;
  • routing policies;
  • DHCP configurations;
  • access controls.

For example:

Employees → Servers       ALLOW

Guests → Internet         ALLOW

Guests → Servers          BLOCK

Cameras → Camera Server   ALLOW

Cameras → Employee PCs    BLOCK

VLANs provide the Layer 2 separation, while routers, Layer 3 switches, and firewalls provide controlled communication between the resulting networks.


Could We Simply Avoid IP Completely?

Yes, technically.

You could have:

VLAN 10
VLAN 20
VLAN 30

with no IPv4 or IPv6 configured.

The Ethernet segmentation would still exist.

But most modern corporate applications depend on IP.

Without IP, devices generally cannot participate normally in:

  • web applications;
  • Internet access;
  • DNS;
  • email;
  • cloud applications;
  • most client/server applications.

So although VLANs do not technically require IP, practical modern enterprise VLANs are normally paired with IPv4 and/or IPv6 subnets.


Which Design Is Best?

For an ordinary modern IP network, the preferred design is generally:

ONE VLAN
   ↓
ONE IP SUBNET
   ↓
ONE LAYER 3 GATEWAY

For example:

VLAN 10
192.168.10.0/24
Gateway 192.168.10.1
VLAN 20
192.168.20.0/24
Gateway 192.168.20.1
VLAN 30
192.168.30.0/24
Gateway 192.168.30.1

This aligns:

Layer 2 segmentation

with:

Layer 3 addressing

and makes routing predictable.


Which Alternatives Create Problems?

The four basic possibilities can be summarized this way:

DesignPossible?Usually recommended?
VLAN with no IP subnetYesYes for special Layer 2 purposes
One VLAN + one subnetYesBest normal design
One VLAN + multiple subnetsYesUsually no
Multiple isolated VLANs + same subnetNormally problematicAvoid

The problematic case is particularly important:

VLAN 10 ─┐
         ├── 192.168.1.0/24   ← BAD NORMAL DESIGN
VLAN 20 ─┘

because IP believes the devices are local to one another while Ethernet has separated their broadcasts.

The cleaner design is:

VLAN 10 → 192.168.10.0/24

VLAN 20 → 192.168.20.0/24

Now Layer 2 and Layer 3 agree.


Does Using the Same IP Subnet Across VLANs Cause “Chaos”?

“Chaos” may be an informal word, but it captures the practical problem reasonably well.

Several confusing symptoms can result:

ARP failures. Devices believe another address is local but cannot reach its Layer 2 broadcast domain.

IPv6 Neighbor Discovery failures. IPv6 has a similar local-neighbour discovery requirement.

Intermittent connectivity. Depending on gateways and special configurations, some communication may appear to work while other communication fails.

DHCP confusion. Separate VLANs typically require appropriate DHCP scopes and relay configuration.

Duplicate addresses. Administrators may accidentally reuse addresses because the VLANs appear isolated.

Difficult troubleshooting. IP addressing suggests one topology while the actual Layer 2 topology says something different.

Good network architecture tries to make different layers reinforce rather than contradict each other.


The Three Boundaries to Keep Separate

A useful mental model is:

Physical boundary

Which cable or switch port is being used?

Physical switch port

Layer 2 boundary

Which VLAN does the frame belong to?

VLAN ID

Layer 3 boundary

Which IP subnet does the address belong to?

IP network prefix

These are three different questions.

For example:

Physical Port 5
       ↓
VLAN 20
       ↓
192.168.20.0/24

They are related by configuration, but they are not inherently the same thing.


A Complete Example

Suppose one physical switch serves three departments.

              ONE PHYSICAL SWITCH

       ┌──────────────────────────┐
       │                          │
       │ VLAN 10                  │
       │ Staff                    │
       │ 192.168.10.0/24          │
       │                          │
       │ VLAN 20                  │
       │ Accounting               │
       │ 192.168.20.0/24          │
       │                          │
       │ VLAN 30                  │
       │ Guests                   │
       │ 192.168.30.0/24          │
       │                          │
       └────────────┬─────────────┘
                    │
               Layer 3
               Routing
                    │
                Firewall
                    │
                 Internet

Ports might be configured as:

Ports 1–8   → VLAN 10
Ports 9–16  → VLAN 20
Ports 17–23 → VLAN 30
Port 24     → uplink/trunk

IP addressing could be:

VLAN 10
192.168.10.0/24
Gateway: 192.168.10.1
VLAN 20
192.168.20.0/24
Gateway: 192.168.20.1
VLAN 30
192.168.30.0/24
Gateway: 192.168.30.1

Within each VLAN:

Layer 2 switching and MAC addresses handle local Ethernet delivery.

Between VLANs:

Layer 3 routing and IP addresses handle communication.

Toward external networks:

routers/firewalls provide connectivity and security.


Final Thought

A single managed Ethernet switch can support many VLANs because a VLAN is a logical Layer 2 boundary rather than a separate physical switch.

The separation is created through:

VLAN IDs + switch-port assignments + VLAN tags where required.

It does not depend on the VLAN name.

It does not depend on IP addressing.

And it does not require subnetting simply to exist.

However, once ordinary IP communication is introduced, the cleanest architecture is normally:

One VLAN → one IP subnet → one Layer 3 gateway.

A VLAN can exist without IP.

A subnet can exist without a VLAN.

One VLAN can technically contain multiple subnets.

Special technologies can even stretch addressing in unusual ways.

But for ordinary networks, matching one subnet to one VLAN avoids unnecessary complexity.

The key is to keep the layers conceptually separate:

VLAN controls Layer 2 membership and broadcasts.

Subnet controls Layer 3 IP addressing.

Switches forward Ethernet frames within VLANs.

Routers or Layer 3 switches route IP packets between subnets.

When those boundaries are designed to match each other, the network becomes much easier to understand, operate, secure, and troubleshoot.

Network Devices, VLANs, Subnets, Layer 2 and Layer 3 Switches, and Routers

Network Devices, VLANs, Subnets, Layer 2 and Layer 3 Switches, and Routers

From AI tools as IS.

Modern computer networks are built from several different kinds of devices and several different kinds of logical boundaries. This can become confusing because terms such as switch, router, VLAN, subnet, LAN, Layer 2, and Layer 3 are closely related but do not mean the same thing.

A particularly common source of confusion is the relationship between a VLAN and an IP subnet. In a typical corporate network, one VLAN is normally paired with one IP subnet, making them look almost interchangeable. Technically, however, they operate at different layers and solve different problems.

Similarly, a modern Layer 3 switch can perform routing, which makes it look very much like a router. Yet Layer 3 switches and routers are normally designed for somewhat different jobs.

The easiest way to understand all of this is to start with how devices communicate on a simple Ethernet network and gradually build up from there.


The Main Types of Network Devices

A modern network can include many kinds of devices.

Some of the most important are:

  • end devices or hosts;
  • servers;
  • Ethernet switches;
  • wireless access points;
  • routers;
  • firewalls;
  • gateways;
  • modems and optical network terminals.

End Devices or Hosts

An end device, often called a host, is a device that produces or consumes network communication.

Examples include:

  • desktop computers;
  • laptops;
  • smartphones;
  • tablets;
  • printers;
  • IP phones;
  • security cameras;
  • smart TVs;
  • servers;
  • IoT devices.

A laptop opening a website is an end device.

A smartphone making a VoIP call is an end device.

A printer receiving a print job is an end device.


Servers

A server is also a host, but it normally provides services to other devices.

Examples include:

  • web servers;
  • database servers;
  • email servers;
  • file servers;
  • DNS servers;
  • DHCP servers;
  • authentication servers;
  • application servers.

The distinction between a client and a server is therefore mainly about the role of the device or application, not necessarily different hardware.


What Does a Layer 2 Switch Do?

An Ethernet switch primarily works at Layer 2, the Data Link layer.

Its basic job is to move Ethernet frames between devices.

A Layer 2 switch primarily makes forwarding decisions based on:

MAC addresses

Suppose four computers are connected to one switch:

PC-A ─┐
PC-B ─┤
      Switch
PC-C ─┤
PC-D ─┘

Each Ethernet network interface has a MAC address.

For example:

PC-A = AA:AA:AA:AA:AA:AA
PC-B = BB:BB:BB:BB:BB:BB

When frames arrive, the switch learns which MAC addresses are reachable through which ports.

Its MAC address table might eventually look like:

MAC addressSwitch port
AA:AA:AA:AA:AA:AAPort 1
BB:BB:BB:BB:BB:BBPort 2
CC:CC:CC:CC:CC:CCPort 3

If a frame destined for PC-B arrives on Port 1, the switch sees:

Destination MAC = BB:BB:BB:BB:BB:BB

checks its MAC address table and forwards the frame through Port 2.

This process does not require the switch to examine the destination IP address.

Ubiquiti’s current networking documentation describes the same basic process: Layer 2 switches learn source MAC addresses, build forwarding tables, and use those tables to decide where Ethernet frames should be sent.


Does a Layer 2 Switch Need an IP Address?

Interestingly:

A basic Layer 2 switch does not need an IP address to switch Ethernet frames.

It can learn MAC addresses and forward frames without having an IP address of its own.

For example:

PC-A ─ Switch ─ PC-B

PC-A and PC-B can exchange Ethernet traffic through the switch even if the switch itself has no management IP address.

Managed switches are usually assigned an IP address so administrators can:

  • connect using SSH;
  • access a web interface;
  • use SNMP;
  • collect telemetry;
  • perform configuration and monitoring.

That IP address is for management.

It is not what allows ordinary Layer 2 frame forwarding to happen.


Is a MAC Address Required?

For normal Ethernet communication, MAC addresses are fundamental.

An Ethernet frame contains source and destination MAC addresses.

For example:

Destination MAC
Source MAC
EtherType
Payload
Frame Check Sequence

So Ethernet devices generally require MAC addressing to deliver frames.

However:

IP networking itself does not universally require MAC addresses.

MAC addresses belong to technologies such as Ethernet.

IP can also operate over other Layer 2 technologies that do not use Ethernet MAC addressing in the same way.

Examples include certain:

  • point-to-point links;
  • tunnels;
  • PPP links;
  • virtual interfaces.

Therefore:

Ethernet → normally requires MAC addressing

but:

IP → does not inherently require Ethernet MAC addresses


Can MAC Communication Exist Without IP?

Yes.

Ethernet is not dependent on IP.

Two devices can exchange Layer 2 Ethernet frames using MAC addresses without running IPv4 or IPv6.

Various Layer 2 control protocols also operate without depending on ordinary IP forwarding.

Examples include protocols associated with:

  • spanning tree;
  • link discovery;
  • link aggregation.

So:

MAC addressing can exist without IP addressing.


Can IP Exist Without Ethernet?

Yes.

IP is a Layer 3 protocol and is not limited to Ethernet.

An IP packet can be transported over:

  • Ethernet;
  • Wi-Fi;
  • cellular systems;
  • point-to-point links;
  • tunnels;
  • many other underlying technologies.

This is one of the great strengths of IP.

The Layer 3 packet does not need to know whether one particular segment of its journey uses copper Ethernet, fiber, Wi-Fi, or another technology.


What Is a VLAN?

VLAN means:

Virtual Local Area Network

A VLAN logically separates one physical switched Ethernet infrastructure into multiple Layer 2 networks.

Suppose a company owns one switch:

Port 1 → Employee PC
Port 2 → Employee PC
Port 3 → Accounting PC
Port 4 → Accounting PC
Port 5 → Guest device
Port 6 → Guest device

Instead of putting everyone into the same Layer 2 network, the administrator could configure:

VLAN 10 → Employees
VLAN 20 → Accounting
VLAN 30 → Guests

The physical switch is one device, but logically there are three separate Ethernet networks.


A VLAN Is a Broadcast Domain

One important property of a VLAN is that each VLAN normally forms a separate Layer 2 broadcast domain.

Suppose a computer in VLAN 10 sends an Ethernet broadcast.

The switch forwards that broadcast to other appropriate ports in:

VLAN 10

but not normally to:

VLAN 20
VLAN 30

Therefore:

A VLAN creates Layer 2 separation.

Devices connected to the same physical switch can behave as though they were connected to separate switches.


One Physical Switch, Several Logical LANs

Conceptually:

               Physical Switch
        ┌──────────────────────────┐
        │ VLAN 10     VLAN 20      │
        │ Staff       Accounting   │
        │                          │
        │ VLAN 30                  │
        │ Guests                   │
        └──────────────────────────┘

This is why VLANs are so useful.

Organizations do not need a completely separate physical switch for every department or network.


What Is an IP Subnet?

A subnet is a Layer 3 concept.

It defines a group of IP addresses belonging to the same logical IP network.

For example:

192.168.10.0/24

is an IPv4 subnet.

Addresses might include:

192.168.10.1
192.168.10.2
192.168.10.3
...

Another subnet could be:

192.168.20.0/24

These are different IP networks.

A router or Layer 3 device is normally required to forward packets between them.


VLAN and Subnet: Are They the Same Thing?

No.

They frequently correspond to each other, but they are different concepts.

VLANSubnet
Layer 2Layer 3
Ethernet conceptIP concept
Creates a broadcast domainDefines an IP network
Identified by VLAN IDIdentified by network prefix
Example: VLAN 10Example: 192.168.10.0/24
Switches enforce separationRouters route between subnets
Uses MAC-based forwardingUses IP-based forwarding

A good way to remember the distinction is:

A VLAN groups and separates Ethernet devices.

while:

A subnet groups and separates IP addresses.


Why Do VLANs and Subnets Seem Like the Same Thing?

Because normal network design commonly maps them one-to-one.

For example:

VLAN 10 → 192.168.10.0/24
VLAN 20 → 192.168.20.0/24
VLAN 30 → 192.168.30.0/24

This is a very clean design.

Each VLAN represents:

  • one Layer 2 broadcast domain;
  • normally one IP subnet.

Cisco documentation describes this common design explicitly: individual IP subnetworks are commonly mapped to individual VLANs, while routing is required to communicate between VLANs.

So in practice:

One VLAN = one subnet

is a very useful design rule.

But it is not a definition saying VLAN and subnet are technically identical.


Does Subnetting Create VLANs?

No.

Subnetting creates IP networks.

It does not automatically create Layer 2 VLANs.

Consider a router:

                 Router
                /      \
192.168.10.0/24          192.168.20.0/24

Each router interface could connect to a separate physical Ethernet network.

There might be no VLAN configuration anywhere.

Yet there are clearly two IP subnets.

Therefore:

A subnet can exist without a VLAN.


Can a VLAN Exist Without a Subnet?

Yes.

A VLAN can exist entirely at Layer 2 without any IP subnet being assigned to it.

For example:

VLAN 100

may be configured on a switch and contain Ethernet devices that use some non-IP protocol.

Or an administrator may create a VLAN before any devices or IP addresses have been assigned.

Therefore:

A VLAN does not technically require an IP subnet.

However, if hosts in that VLAN are going to use normal IPv4 or IPv6 communication, the VLAN will ordinarily be associated with an IP subnet.


Can a Network Exist Without IP?

Yes.

A computer network does not have to use Internet Protocol.

Ethernet itself is a networking technology and can carry protocols other than IPv4 or IPv6.

Historically, many networks used protocols such as:

  • IPX;
  • AppleTalk;
  • various proprietary networking protocols.

Specialized industrial environments can also use communication mechanisms that are not ordinary IP networks.

Today, however, IP dominates general-purpose computer networking.


Can Multiple VLANs Use One IP Subnet?

Under normal network design:

They should not.

Suppose:

VLAN 10
PC-A = 192.168.1.10/24

and:

VLAN 20
PC-B = 192.168.1.20/24

Both hosts believe they are on:

192.168.1.0/24

PC-A examines:

192.168.1.20

and concludes:

“That address belongs to my local subnet.”

So PC-A tries to discover PC-B’s MAC address using ARP.

It broadcasts:

Who has 192.168.1.20?

But the broadcast remains within VLAN 10.

PC-B is in VLAN 20 and never receives it.

Communication therefore fails under normal circumstances.

This is why the normal design is:

VLAN 10 → Subnet A
VLAN 20 → Subnet B

rather than putting the same subnet into two isolated VLANs.

Specialized techniques can change this behavior, but they are exceptions rather than the normal design.


Can One VLAN Contain Multiple IP Subnets?

Technically, yes.

For example, devices in one VLAN could be configured using:

192.168.10.0/24

and:

192.168.20.0/24

on the same Layer 2 broadcast domain.

But this is generally not the preferred design.

It complicates:

  • addressing;
  • gateway configuration;
  • troubleshooting;
  • security;
  • broadcast-domain design.

The normal design remains:

One VLAN mapped to one IP subnet.


What Happens When Two Computers Are in the Same VLAN and Subnet?

Suppose:

PC-A
IP: 192.168.10.10
MAC: AA-AA-AA-AA-AA-AA

and:

PC-B
IP: 192.168.10.20
MAC: BB-BB-BB-BB-BB-BB

Both belong to:

VLAN 10
Subnet: 192.168.10.0/24

and are connected through a Layer 2 switch.

The communication process is roughly as follows.

Step 1: PC-A examines the destination IP

PC-A sees:

192.168.10.20

Its subnet mask tells it that the destination is on the same subnet.

Therefore, PC-A does not send the packet to its router.


Step 2: PC-A Needs the Destination MAC Address

Ethernet delivers frames using MAC addresses.

PC-A therefore needs to determine which MAC address corresponds to:

192.168.10.20

It uses ARP for IPv4.

Conceptually:

Who has 192.168.10.20?

This is transmitted as an Ethernet broadcast.


Step 3: The Switch Floods the Broadcast

Because it is a broadcast, the switch sends it to the other ports belonging to VLAN 10.

PC-B receives the request.


Step 4: PC-B Replies

PC-B responds:

192.168.10.20 is at BB-BB-BB-BB-BB-BB

PC-A now knows PC-B’s MAC address.


Step 5: PC-A Builds an Ethernet Frame

The frame contains approximately:

Destination MAC: BB-BB-BB-BB-BB-BB
Source MAC:      AA-AA-AA-AA-AA-AA

Inside the frame:
Source IP:       192.168.10.10
Destination IP:  192.168.10.20

Step 6: The Layer 2 Switch Forwards the Frame

The switch looks at:

Destination MAC

checks its MAC address table, and sends the frame toward PC-B.

The router is not involved.

This is Layer 2 switching.


What If Two Physical LAN Segments Are Connected by a Layer 2 Switch?

Suppose:

LAN Segment A ─── Layer 2 Switch ─── LAN Segment B

If both sides belong to the same VLAN, the switch can bridge Ethernet frames between them.

Conceptually, the switch has turned those physical segments into one larger Layer 2 network.

For example:

Segment A:
PC-A
PC-B

        Layer 2 Switch

Segment B:
PC-C
PC-D

If all are in VLAN 10, they can belong to the same Layer 2 broadcast domain.

Calling them “LAN A” and “LAN B” is therefore somewhat ambiguous.

Physically, they may be separate Ethernet segments.

Logically, after bridging them through the switch, they can be one LAN.


What If They Are Truly Separate LANs?

If “LAN 1” and “LAN 2” means:

LAN 1 = VLAN 10 / 192.168.10.0/24

LAN 2 = VLAN 20 / 192.168.20.0/24

then a Layer 2 switch cannot by itself provide communication between them.

A Layer 3 device is required.

That could be:

  • a router;
  • a Layer 3 switch;
  • a firewall capable of routing.

What Is a Layer 3 Switch?

A Layer 3 switch combines traditional Ethernet switching with IP routing capabilities.

It can perform:

Layer 2 switching

MAC address → switch port

and:

Layer 3 routing

Destination IP network → next hop/interface

Modern Layer 3 switches commonly perform routing directly in switching hardware, making inter-VLAN communication extremely fast.

Ubiquiti, for example, describes current Layer 3 switches as providing hardware-accelerated inter-VLAN routing.


What Is an SVI?

One common way for a Layer 3 switch to route between VLANs is through Switched Virtual Interfaces, usually abbreviated SVIs.

Suppose:

VLAN 10 → 192.168.10.0/24
VLAN 20 → 192.168.20.0/24

The Layer 3 switch could have:

interface VLAN 10
IP address 192.168.10.1

and:

interface VLAN 20
IP address 192.168.20.1

The hosts use those addresses as their default gateways.

Conceptually:

VLAN 10
192.168.10.0/24
       │
       │ 192.168.10.1
       │
   Layer 3 Switch
       │
       │ 192.168.20.1
       │
VLAN 20
192.168.20.0/24

How Does a Layer 3 Switch Move Data Between VLANs?

Suppose:

PC-A
192.168.10.10/24
VLAN 10

needs to contact:

PC-B
192.168.20.20/24
VLAN 20

PC-A examines the destination.

It sees that:

192.168.20.20

is outside its local subnet.

Therefore, rather than trying to find PC-B’s MAC address, PC-A sends the packet to its default gateway:

192.168.10.1

which belongs to the Layer 3 switch.


The First Ethernet Frame

PC-A transmits approximately:

Ethernet:
Destination MAC = MAC of VLAN 10 gateway
Source MAC      = MAC of PC-A

IP:
Source IP       = 192.168.10.10
Destination IP  = 192.168.20.20

Notice something very important:

The destination MAC address is the gateway’s MAC address, but the destination IP address remains PC-B’s IP address.


The Layer 3 Switch Routes the Packet

The Layer 3 switch:

  1. receives the Ethernet frame;
  2. removes the Layer 2 Ethernet header;
  3. examines the destination IP address;
  4. checks its routing table;
  5. determines that 192.168.20.0/24 is reachable through VLAN 20;
  6. discovers PC-B’s MAC address if necessary;
  7. constructs a new Ethernet frame;
  8. sends the packet into VLAN 20.

The new frame might contain:

Destination MAC = PC-B's MAC
Source MAC      = Layer 3 switch VLAN 20 MAC

Source IP       = 192.168.10.10
Destination IP  = 192.168.20.20

The Ethernet addresses changed.

The source and destination IP addresses normally did not.

This illustrates a fundamental principle:

MAC addresses normally change as packets cross routed Layer 3 boundaries, while end-to-end IP addresses normally remain the same unless something such as NAT changes them.


Layer 2 Switch vs. Layer 3 Switch

CapabilityLayer 2 SwitchLayer 3 Switch
Ethernet switchingYesYes
MAC address tableYesYes
VLANsYesYes
Layer 2 broadcast separationYesYes
IP routingNormally noYes
Routing tableNormally no forwarding roleYes
Inter-VLAN routingNoYes
SVI/default gatewayManagement only or limitedYes
Static/dynamic routesNo or very limitedUsually supported to varying degrees
Typical useAccess switchingDistribution/core + access in some designs

Cisco’s training material similarly contrasts a Layer 2 Catalyst 2960 with a Layer 3-capable switch and notes that enabling IP routing allows the Layer 3 switch to perform routing functions.


What Is a Router?

A router is fundamentally a Layer 3 device.

Its main job is:

to connect different IP networks and forward packets between them based on destination IP addresses and routing information.

For example:

LAN A
192.168.10.0/24
      │
    Router
      │
LAN B
192.168.20.0/24

or:

Corporate LAN
      │
    Router
      │
     ISP
      │
   Internet

Routers maintain routing tables showing how different networks can be reached.


A Router Is Not Defined as “LAN to WAN”

It is common to think:

Switch = LAN
Router = LAN to Internet

That is an oversimplification.

A router can connect:

  • LAN to LAN;
  • subnet to subnet;
  • VLAN to VLAN;
  • LAN to WAN;
  • WAN to WAN;
  • branch office to headquarters;
  • enterprise network to ISP;
  • one ISP to another ISP.

For example, two subnets inside the same building may communicate through a router.

No WAN is necessary.


If a Layer 3 Switch Routes, Why Do We Need Routers?

This is an important question.

A modern Layer 3 switch and a router overlap substantially.

Both can:

  • maintain routing tables;
  • forward IP packets;
  • support static routes;
  • support routing protocols;
  • route between networks.

The difference is increasingly about design, interfaces, features, scale, and intended role rather than a rigid Layer 2-versus-Layer 3 distinction.


Layer 3 Switch: Optimized for High-Speed LAN Routing

Layer 3 switches are commonly optimized for:

  • many Ethernet ports;
  • very high switching throughput;
  • VLANs;
  • inter-VLAN routing;
  • campus networks;
  • data centres;
  • access/distribution/core switching.

For example:

Employees VLAN
          \
Servers VLAN ─ Layer 3 Switch ─ Campus Core
          /
Guest VLAN

The device can switch and route enormous volumes of traffic locally.


Router: Optimized for Connecting Networks and WANs

Routers are typically designed for broader Layer 3 connectivity.

Depending on the router, features may include:

  • sophisticated routing protocols;
  • BGP;
  • MPLS;
  • WAN interfaces;
  • VPN;
  • SD-WAN;
  • NAT;
  • QoS;
  • tunneling;
  • traffic engineering;
  • carrier-scale routing tables;
  • Internet peering;
  • cellular WAN connections.

A branch router, for example, may connect:

Office LAN
    │
Branch Router
    ├── Fiber ISP
    ├── Secondary ISP
    └── 5G Backup

That role is different from simply switching thousands of local Ethernet devices.


Layer 3 Switch vs. Router

A useful practical comparison is:

Layer 3 SwitchRouter
Primarily optimized for LAN/campus/data-centre EthernetPrimarily optimized for inter-network/WAN/edge routing
Usually many Ethernet switch portsOften fewer but more flexible routed interfaces
Extremely fast inter-VLAN routingRich WAN and routing capabilities
Common in campus distribution/coreCommon at network boundaries and WAN edges
Heavy emphasis on VLANsHeavy emphasis on routing
Often ASIC-based local forwardingAlso hardware accelerated on modern enterprise/provider routers
Usually does not perform Internet NAT/firewall duties as its primary roleMay provide NAT, VPN, WAN, SD-WAN and related services

But these are tendencies—not absolute laws.

Modern high-end networking hardware increasingly blurs the distinction.


Can a Layer 3 Switch Replace a Router?

Sometimes.

Consider an office containing several VLANs:

Staff VLAN
Finance VLAN
Server VLAN
Guest VLAN

A Layer 3 switch can route among these networks efficiently.

There may be no reason to send every internal packet through a separate external router.

For example:

              Layer 3 Switch
              /     |      \
          Staff   Servers   Finance

This is one of the most common uses of Layer 3 switching.

But when traffic needs to leave the organization:

Layer 3 Switch
      │
Firewall / Edge Router
      │
ISP
      │
Internet

a dedicated edge router, firewall, or integrated security gateway is often used.


Can a Router Perform Layer 2 Switching?

Some routers can.

Modern network appliances frequently combine many functions.

One physical box might contain:

  • router;
  • Ethernet switch;
  • firewall;
  • VPN gateway;
  • Wi-Fi access point;
  • DHCP server.

A typical home “wireless router” is a good example.

Internally, it often contains:

Router
+
Ethernet switch
+
Wi-Fi access point
+
Firewall/NAT
+
DHCP server

So the product name does not necessarily reveal every internal function.


What Is an Access Switch?

An access switch connects end devices to the network.

Examples include:

  • desktop computers;
  • printers;
  • IP phones;
  • Wi-Fi access points;
  • security cameras.

A typical corporate access layer looks like:

PC ─┐
IP Phone ─┤
Printer ──┤ Access Switch
Wi-Fi AP ─┤
Camera ───┘

Access switches often provide Power over Ethernet (PoE) so the Ethernet cable can provide both data and electrical power to:

  • IP phones;
  • access points;
  • cameras.

Distribution and Core Switches

Larger networks often use hierarchical designs.

A simplified traditional campus architecture is:

End Devices
     │
Access Switches
     │
Distribution Switches
     │
Core
     │
WAN/Internet

Distribution and core switches are often Layer 3 switches.

They can route between many VLANs and aggregate traffic from many access switches.

Current Cisco campus families illustrate this separation. Cisco positions Catalyst 9200 and 9300 systems for access and branch/campus use, while Catalyst 9400, 9500, and 9600 families serve increasingly large distribution and core roles.


A Small-Business Network

A small office might have only:

Internet
   │
Router/Firewall
   │
Managed Switch
 ┌─┼────┬─────┐
PC AP Printer Phone

The router/firewall might perform:

  • Internet routing;
  • NAT;
  • DHCP;
  • VPN;
  • firewalling.

The switch provides:

  • Ethernet connectivity;
  • VLANs;
  • PoE;
  • perhaps some Layer 3 functionality.

Current examples aimed at smaller environments include Cisco Catalyst 1300 switches, which Cisco describes as designed for small and medium-sized businesses.

Cloud-managed platforms are also common in this market. Cisco Meraki, for example, offers smaller security/SD-WAN appliances for branches ranging from tens to hundreds of users.

Ubiquiti UniFi is another commonly encountered architecture in small and medium environments, offering Layer 2 and Layer 3 switching along with gateway and Wi-Fi systems.


A Medium-Sized Corporate Network

A medium-sized organization might have:

                   Internet
                      │
              Firewall/Edge Router
                      │
               Layer 3 Core
                /           \
       Access Switch     Access Switch
       /   |    \          /   |    \
     PCs  APs  Phones    PCs  APs  Cameras

There may be several VLANs:

VLAN 10 → Corporate users
VLAN 20 → Voice
VLAN 30 → Servers
VLAN 40 → Wi-Fi
VLAN 50 → Guests
VLAN 60 → Cameras

A Layer 3 switch may route among these networks.

A firewall may control which VLANs are permitted to communicate.

The edge router or firewall handles connectivity toward:

  • Internet providers;
  • branch offices;
  • cloud services;
  • VPNs.

Representative current enterprise switching platforms include Cisco Catalyst 9200 and 9300 systems. Cisco describes the 9200 family as enterprise access switching for branches and midsize campuses and the 9300 family as campus access systems with greater scale and capabilities.

For branch/WAN routing, Cisco’s current Catalyst 8300 platform is designed for SD-WAN, SASE, 5G and cloud-edge applications.


A Large Corporate Campus

A large corporation may have thousands or tens of thousands of devices.

A simplified architecture could be:

                    Internet / WAN
                         │
                   Edge Routers
                         │
                     Firewalls
                         │
                 Core L3 Switches
                  /             \
         Distribution       Distribution
          /       \           /       \
       Access    Access    Access    Access
        │          │        │          │
     Users/APs  Phones    Servers    Cameras

At this scale, redundancy becomes essential.

Organizations may use:

  • redundant core switches;
  • redundant routers;
  • multiple ISPs;
  • dynamic routing protocols;
  • high-speed fiber links;
  • link aggregation;
  • hundreds or thousands of VLANs;
  • large routing tables.

Cisco currently positions Catalyst 9500 and 9600 systems for midsize-to-large campus core roles.


What Happens in a Data Centre?

Data-centre networks can be much larger and faster.

Instead of the traditional access/distribution/core hierarchy, many data centres use leaf-spine architectures.

A simplified model is:

       Spine     Spine
        /|\       /|\
       / | \     / | \
    Leaf Leaf  Leaf Leaf
     │    │     │    │
   Servers     Servers

These devices often perform both sophisticated Layer 2 and Layer 3 functions.

Cisco’s Nexus 9000 family, for example, is designed for data-centre switching and currently supports interfaces reaching 800 Gb/s on some platforms.

At this scale, the old idea that:

“switch = simple Layer 2 device”

becomes increasingly inadequate.

Modern data-centre switches often perform extensive Layer 3 routing as well.


What Devices Make Up the Internet?

The Internet is fundamentally a network of networks.

A simplified path might be:

Home/Office
    │
Access Router
    │
ISP Edge Router
    │
ISP Core
    │
Internet Peering Router
    │
Another ISP
    │
Data Centre
    │
Server

Internet-scale routers must manage enormous quantities of traffic and very large routing tables.

They commonly use:

  • BGP;
  • MPLS;
  • segment routing;
  • high-speed optical Ethernet;
  • 100G;
  • 400G;
  • increasingly 800G links.

Representative service-provider platforms include Cisco’s 8000 Series and Juniper’s MX and PTX families.

Cisco positions its 8000 systems for carrier core, aggregation and Internet peering applications.

Juniper’s MX family is used for service-provider edge, broadband, peering and related applications, while the PTX family is designed for high-capacity core and WAN environments. Current PTX platforms support 400G and 800G architectures.


Are There Switches Inside the Internet?

Certainly.

The Internet is not built only from routers.

Switches are heavily used inside:

  • data centres;
  • ISP facilities;
  • Internet exchanges;
  • carrier Ethernet networks;
  • aggregation networks.

The distinction depends on what function is being performed at that point.

For communication between IP networks or autonomous systems, routing is central.

Within a data-centre fabric or local Layer 2 domain, switching may be central.

Modern hardware can perform both.


Common Equipment in Networking Labs

Networking laboratories often use either real hardware or network simulators/emulators.

Historically and still in many training environments, Cisco devices such as:

  • Catalyst 2960 Layer 2 switches;
  • Catalyst 3560/3650 Layer 3 switches;
  • Cisco 1941/2900-series routers

are frequently encountered.

These should be understood as training and legacy platforms, not necessarily recommendations for new corporate deployments in 2026.

Cisco’s own networking lab material has used Catalyst 2960 switches and Cisco ISR routers in hands-on exercises, while Layer 2-versus-Layer 3 comparison material uses the 2960 alongside Layer 3-capable Catalyst platforms.

Today, many labs are also virtual.

Common approaches include:

  • Cisco Packet Tracer;
  • GNS3;
  • EVE-NG;
  • vendor virtual router images;
  • cloud networking labs.

Virtual labs make it possible to construct networks containing many routers and switches without owning large amounts of physical hardware.


Representative Devices by Environment

The following is not a strict purchasing guide; it illustrates the kinds of equipment encountered at different scales.

EnvironmentTypical switchingTypical routing/gateway role
HomeIntegrated Ethernet switchConsumer gateway/router
Small businessManaged L2/L3 switchFirewall/router appliance
Medium enterpriseEnterprise access switchesBranch router/firewall
Large campusAccess + L3 distribution/coreEnterprise WAN edge routers
Data centreHigh-speed L2/L3 leaf-spine switchesEdge/peering routers
ISPCarrier Ethernet/aggregation switchesEdge/core/peering routers
Internet backboneVery high-capacity switching fabricsCarrier-class BGP/core routers

Representative current families include:

  • Small/medium switching: Cisco Catalyst 1300, Catalyst 9200, UniFi switching;
  • Enterprise campus: Cisco Catalyst 9300, 9400, 9500, 9600;
  • Branch/WAN: Cisco Catalyst 8300 and comparable platforms;
  • Data centre: Cisco Nexus 9000, Juniper QFX and comparable systems;
  • Service-provider edge/core: Cisco 8000, Juniper MX and PTX.

Cisco’s current Catalyst portfolio explicitly divides its families among access, distribution, and core roles, while Juniper positions its MX/PTX families for edge, peering, WAN and core routing.


Putting VLAN, Subnet, Switch and Router Together

Consider a corporate network with three departments.

Employees
VLAN 10
192.168.10.0/24
       \
        \
         Layer 3 Switch
        /       |       \
Accounting      |       Servers
VLAN 20         |       VLAN 30
192.168.20.0/24 |       192.168.30.0/24
                |
             Firewall
                |
             Router
                |
              ISP
                |
             Internet

This architecture demonstrates all of the concepts.

Inside VLAN 10

Frames are switched using MAC addresses.

Between VLAN 10 and VLAN 20

Packets are routed using IP addresses.

Between the company and the Internet

A router/firewall forwards traffic toward the ISP.

VLAN

Defines the Layer 2 logical network.

Subnet

Defines the Layer 3 IP network.

Layer 2 switch

Moves frames within VLANs.

Layer 3 switch

Moves frames within VLANs and routes packets between IP subnets.

Router

Connects IP networks and is commonly used at WAN and Internet boundaries.


What Addresses Are Actually Used During Communication?

A useful summary is:

Inside one Ethernet LAN

Both are used:

IP address → identifies the Layer 3 endpoint

MAC address → identifies the local Ethernet destination

Suppose:

192.168.10.10

sends something to:

192.168.10.20

The IP addresses identify the endpoints.

The MAC addresses allow the Ethernet frame to cross the local LAN.


Across a Router

Suppose:

192.168.10.10

communicates with:

8.8.8.8

The destination is not local.

The computer creates a frame whose:

Destination IP  = 8.8.8.8
Destination MAC = MAC address of local gateway

The router receives it.

At the next Ethernet link, a different pair of MAC addresses is normally used.

Therefore:

IP addresses identify Layer 3 source/destination communication, while MAC addresses generally identify the next Ethernet hop.

That is why MAC addresses normally change at routed boundaries while IP addresses can remain end-to-end.


Does Every Router Need a MAC Address?

Not inherently.

A router performing IP routing over Ethernet has MAC addresses on its Ethernet interfaces because Ethernet requires them.

But a router could also have a non-Ethernet point-to-point interface where Ethernet MAC addressing is irrelevant.

So:

Routing requires Layer 3 addressing, but Ethernet MAC addressing is only required when the relevant link technology is Ethernet or uses comparable MAC mechanisms.


Does Every Switch Need an IP Address?

No.

A Layer 2 switch can forward frames with no IP address configured.

A managed switch normally receives an IP address so administrators can manage it.

A Layer 3 switch, however, needs Layer 3 addresses on interfaces or SVIs when it is actually performing IP routing.


The Most Important Relationships

These concepts can be summarized as:

Layer 2
    │
    ├── Ethernet
    ├── MAC addresses
    ├── Switch
    └── VLAN
              │
              │ commonly mapped 1:1
              ▼
Layer 3
    │
    ├── IPv4 / IPv6
    ├── IP addresses
    ├── Subnet
    ├── Layer 3 switch
    └── Router

This one-to-one VLAN-to-subnet relationship is a design convention, not a statement that VLAN and subnet are identical.


Common Misconceptions

Several statements sound reasonable but are technically incorrect.

“A VLAN is a subnet.”

Not exactly.

A VLAN is Layer 2.

A subnet is Layer 3.

They are normally paired.


“Subnetting creates VLANs.”

No.

Subnetting creates IP subnets.

VLANs are configured separately at Layer 2.


“A VLAN requires IP.”

No.

A VLAN can exist without IP.


“IP requires Ethernet MAC addresses.”

No.

IP can operate over technologies other than Ethernet.


“A Layer 2 switch requires an IP address.”

No.

It requires no IP address for ordinary frame forwarding.


“A switch connects devices while a router connects LANs.”

Too simplistic.

A Layer 3 switch can route between networks, and a router can connect networks within the same building.


“Routers are only for LAN-to-WAN communication.”

No.

A router can connect any appropriate different Layer 3 networks.


“Different VLANs can normally use the same subnet.”

No.

Separate VLANs isolate Layer 2 broadcasts such as ARP, so one IP subnet spread across independently isolated VLANs normally will not function correctly without special mechanisms.


A Useful Mental Model

The simplest way to keep everything straight is to ask three different questions.

Question 1: What Layer 2 network am I in?

Think:

VLAN

and:

MAC address

and:

switch


Question 2: What Layer 3 network am I in?

Think:

subnet

and:

IP address


Question 3: How do I reach another Layer 3 network?

Think:

router

or:

Layer 3 switch

and:

default gateway

and:

routing table


Final Thought

The boundaries between switches and routers have become less rigid as networking hardware has evolved.

A traditional Layer 2 switch primarily forwards:

Ethernet frames based on MAC addresses.

A router primarily forwards:

IP packets between networks based on IP addresses and routing tables.

A Layer 3 switch combines both capabilities:

Layer 2 switching + Layer 3 routing.

Likewise, a VLAN and a subnet often appear together but represent different things:

VLAN = Layer 2 logical separation

Subnet = Layer 3 logical addressing

The normal modern design is:

One VLAN
   ↓
One IP subnet
   ↓
Layer 3 gateway
   ↓
Other VLANs/subnets

Within the VLAN, switches use MAC addresses.

Between subnets, routers or Layer 3 switches use IP addresses.

At the edge of the organization, routers, firewalls, or integrated gateways connect the internal network to WANs, service providers, cloud networks, and ultimately the Internet.

Once these layers are separated conceptually, much of networking becomes easier to understand:

MAC addresses and VLANs organize local Layer 2 communication. IP addresses and subnets organize Layer 3 communication. Switches move frames locally. Routers and Layer 3 switches move packets between networks.

Modern networking equipment may combine these functions in one physical device, but the underlying concepts remain distinct.

References and Further Reading

  1. Cisco — Catalyst 9000 Switching Family. Current enterprise access, distribution, and core switching families, including Catalyst 9200, 9300, 9400, 9500, and 9600.
  2. Cisco — Campus LAN Core and Distribution Switches. Current positioning of enterprise Layer 3 switching platforms for small, midsize, and large campus networks.
  3. Cisco — Catalyst 8300 Series Edge Platforms. Current enterprise branch, SD-WAN, WAN edge, security, and 5G-capable routing platform.
  4. Cisco — Nexus 9000 Series. Modern high-performance data-centre switching platforms supporting high-speed Ethernet up to 800G on current systems.
  5. Cisco — Cisco 8000 Series. Carrier-class routing platforms designed for core, aggregation, peering, ISP and cloud-scale applications.
  6. Cisco Networking Academy — Comparing Layer 2 and Layer 3 Devices. Discussion of Layer 2 switches, Layer 3 switches and routers, including inter-VLAN routing concepts.
  7. Cisco — VLAN and IP Routing Configuration. Documentation explaining that hosts within the same VLAN can communicate through switching while communication between different VLANs requires Layer 3 routing.
  8. Juniper Networks — MX Series Universal Routing Platforms. Service-provider and enterprise routing systems for broadband edge, peering, mobile backhaul and data-centre edge roles.
  9. Juniper Networks — PTX Series Routers. High-capacity WAN/core and peering platforms supporting current 100G, 400G and 800G architectures.
  10. Ubiquiti — Switching, Routing and STP. Modern explanation of Layer 2 MAC learning and Layer 3 routing concepts.
  11. Ubiquiti — Layer 3 Routing. Documentation showing practical inter-VLAN routing using Layer 3 switches.
  12. Cisco — Catalyst 1300 Series. Managed switching family aimed at small and medium-sized business networks.