Routelearn.net
Course menu

Unit 2: Network DevicesLesson 2.8 (8 of 8 in this unit)12 of 84 in the Network Fundamentals course

Comparing Network Devices

Hubs, switches, routers, modems, firewalls and access points can look alike from the outside, but each one does a different job at a different layer. This lesson puts them side by side, shows where each one sits in a real network and helps you choose the right device for a situation.

Beginner · 15 min read · Before this: Hubs, Switches, Routers, Modems, Firewalls, Wireless access points

Network devices are the hardware that connects end devices and moves traffic between them. Each type works mainly at one layer: hubs repeat bits (Layer 1), switches forward frames by MAC address (Layer 2), routers forward packets between networks by IP address (Layer 3), and firewalls filter traffic according to security rules.

In simple terms: Each device in a network has one main job: switches connect devices on the same network, routers connect different networks, and firewalls decide which traffic is allowed.

You have now met each network device on its own. This lesson compares them directly. The key idea to remember is this: each device is defined by the information it uses to make decisions. A hub uses none, a switch uses MAC addresses, a router uses IP addresses, and a firewall uses addresses, ports and sometimes the application itself.

💡 In simple terms: picture a postal service. The hub photocopies every letter for every flat. The switch knows which flat each person lives in. The router knows which town to send a letter to. The firewall is the security check that refuses suspicious parcels. The modem is the loading dock where the post van arrives, and the access point is the letterbox you can use from anywhere in the garden.

All devices at a glance

DeviceOSI layerDecides usingMain jobWhere you find it
NIC1–2Its own MAC addressConnects one device to the networkInside every device
Hub1Nothing (only signals)Repeats every signal out of every portObsolete; found in old LANs
Switch2MAC addressesDelivers frames to the right port within a LANAt the centre of every LAN
Router3IP addressesMoves packets between different networksBetween networks; the LAN's gateway
Modem1–2Line signalsConverts between Ethernet and the provider's line signalWhere the provider's line enters
Firewall3–4 (NGFW up to 7)IPs, protocols, ports, appsAllows or blocks traffic by rulesAt the edge and between zones
Access point1–2MAC addressesBridges Wi-Fi devices onto the wired LANOn ceilings and walls, cabled to a switch
Wireless router1–3 (+ NAT)MAC and IP addressesRouter + switch + AP + DHCP + NAT + firewall in oneHomes and very small offices
OSI layerHubModemAPSwitchRouterFirewall
L7 Application–––––some
L6 Presentation––––––
L5 Session––––––
L4 Transport––––some✓
L3 Network––––✓✓
L2 Data Link–✓✓✓✓✓
L1 Physical✓✓✓✓✓✓
The highest layer each device reads to make its decisions. “Some” on the router means NAT also uses Layer 4 port numbers; on the firewall, it means next-generation firewalls (NGFWs) also inspect applications (Layer 7).

If the layers are new to you, the next unit explains them in detail.

Learn more: The OSI Model

Every device in one network

A home network

Follow a laptop opening routelearn.net. The traffic passes through almost every device in this unit, and each device does its own small part.

Laptop192.168.1.20APin the routerSwitchLAN portsRouter + NAT192.168.1.1Firewallin the routerModemWAN 203.0.113.45Internetroutelearn.net
  1. 1. NIC + access point (Layers 1–2). The laptop's Wi-Fi NIC sends a frame by radio. The AP bridges it onto the wired side without changing the MAC addresses.
  2. 2. Router (Layer 3). The frame is addressed to the MAC address of the router, the default gateway. The router reads the destination IP address and chooses its route to the internet.
  3. 3. NAT and firewall (Layers 3–4). NAT replaces the private source IP address with the public one. The firewall records the connection so that the reply is allowed back in.
  4. 4. Modem (Layers 1–2). The modem converts the Ethernet frame into the provider's line signal.
  5. 5. The switch's role. Wired devices plug into the switch ports, and the switch delivers their frames to the router by MAC address.
In most homes, the AP, switch, router, NAT and firewall are all inside one box. They are drawn separately here so you can see each job.

An office network

In an office, each job usually has its own, larger device:

Laptop
Wi-Fi NIC
Access point
Wi-Fi ↔ Ethernet
Access switch
MAC forwarding
Core switch
joins floors
Router
IP routing
Firewall
rules + NAT
Modem / ONT
provider line
Internet
The path out of a typical office. The router and firewall are often the same device.

Hub vs. switch vs. router

These three devices are the classic comparison, because they can look alike and all have Ethernet ports.

HubSwitchRouter
OSI layer1 (Physical)2 (Data Link)3 (Network)
ReadsNothing: only signalsMAC addressesIP addresses
Keeps a table ofNothingMAC address → portNetworks → next hop (routing table)
Sends a unicastOut of every portOut of the one correct port (floods it if the MAC address is unknown)Out of the interface towards the destination network
Sends a broadcastOut of every portOut of every portNever forwards it
Collision domainsOne for all portsOne per portOne per interface
Broadcast domainsOneOne (without VLANs)One per interface
Changes the frame?NoNoYes: builds a new frame with new source and destination MACs
ConnectsDevices in one LANDevices in one LANDifferent networks

One broadcast, three devices

The clearest way to see the difference is to watch an ARP broadcast from PC A. The switch floods it to every device on its LAN, just as a hub would, but the router does not forward it.

192.168.1.0/24192.168.2.0/24PC A192.168.1.10PC B192.168.1.11SwitchRoutertwo networksSwitchPC C192.168.2.10
  1. 1. PC A broadcasts. The switch floods it out of every other port, so PC B and the router both receive it.
  2. 2. The router doesn't forward broadcasts. The broadcast stops here. PC C, on another network, never receives it.
  3. 3. A normal packet to PC C is routed. A unicast packet addressed to 192.168.2.10 is forwarded by the router onto the other network.
Switches extend a broadcast domain; routers end it.

Modem vs. router

ModemRouter
JobConnects to the provider's line (DSL, cable, fibre, cellular)Connects your network to other networks and shares the internet connection
OSI layer1–23
IP addressesDoesn't read or change themRoutes based on them; NAT changes them
Hands out addresses (DHCP)NoYes, on home routers
Without the otherOne computer online, with no router protecting itA working LAN, but no internet

Many ISP boxes contain both. If you add your own router, put the ISP box in bridge mode so that only one device does the routing and NAT.

Learn more: Modems

Router vs. firewall

RouterFirewall
Main question it asks"Where should this packet go?""Should this packet be allowed at all?"
Default behaviourForward anything it has a route forBlock anything not explicitly allowed
ReadsDestination IP addressSource and destination IP addresses, protocol and ports; NGFWs also identify the application
Remembers connectionsNo (except for NAT)Yes: tracks each connection (stateful)
Built forFast forwarding, many routes, routing protocolsInspection, rules, logging, threat protection
OverlapRouters can filter with access lists; most firewalls can route and do NAT. Small sites often use one box for both jobs.

Learn more: RoutersFirewalls

Access point vs. wireless router

Access pointWireless router
What it containsWi-Fi radios and an Ethernet uplinkRouter + switch + AP + DHCP + NAT + firewall
OSI layer1–2 (a bridge)1–3
Creates a new IP network?No: Wi-Fi clients join the existing subnetYes: its own LAN, for example 192.168.1.0/24
Gives out IP addressesNo (the network's DHCP server does)Yes
Connects to the internetOnly through a router somewhere elseDirectly, through its WAN port and a modem
Typical useOffices (many APs), extra coverage at homeHomes and very small offices

⚠️ If you use a second wireless router as an extra access point without switching it to AP mode, it creates a second network with its own DHCP and NAT. Devices on it may not be able to reach printers or other devices on the first network.

What each device does to a packet

Here is a good test of your understanding: as a packet travels from a laptop to a server on the internet, which addresses does each device change?

DeviceMAC addressesIP addressesPorts
HubUnchangedUnchangedUnchanged
SwitchUnchangedUnchangedUnchanged
Access pointUnchanged (the Wi-Fi frame is rebuilt as an Ethernet frame with the same source and destination)UnchangedUnchanged
RouterNew frame: its own MAC as the source, the next hop as the destinationUnchanged (but the TTL goes down by 1)Unchanged
Router or firewall doing NATNew framePrivate source address → publicSource port may change (PAT)
ModemCarried across the lineUnchangedUnchanged

Later lessons follow these changes step by step.

Learn more: Different-Subnet CommunicationWhat Happens When You Open a Website?

Which device do I need?

“I want my phones and laptops to use Wi-Fi at home, and I have broadband.”

→ A wireless router (the ISP's box is often already one, with the modem built in).

It combines the modem, routing, NAT, DHCP and Wi-Fi in one box.

“My home router has 4 LAN ports and I need 8 wired devices.”

→ An unmanaged switch.

Connect one switch port to a LAN port on the router. The switch adds more ports on the same network.

“Wi-Fi is weak at the far end of the house, and I can run a cable there.”

→ An access point, cabled to the router or a switch.

A cabled AP gives the best performance. Without a cable, a mesh system is the next best option.

“Wi-Fi is weak upstairs and I can't run cables.”

→ A mesh Wi-Fi system.

Mesh units connect to each other by radio and share one network name (SSID).

“My office has 30 desks, IP phones and 4 ceiling APs on one floor.”

→ A managed PoE switch, plus a router and firewall at the edge.

PoE (Power over Ethernet) powers the APs and phones through the cable; managed features add VLANs and monitoring.

“I have a new fibre line and want to use my own router.”

→ The provider's ONT (or the provider's box in bridge mode) plus your own router.

The ONT (optical network terminal) handles the fibre. Your router does the routing, NAT and Wi-Fi, so there is no double NAT.

“I host a public web server and must protect the internal network.”

→ A firewall with a DMZ zone.

People on the internet can reach only the server in the DMZ; the internal network stays behind the firewall.

“Guests should get internet but never reach my office PCs.”

→ A guest SSID on the APs, separated by a router or firewall.

The guest network is a separate network, and the firewall only allows guest traffic out to the internet.

“Two offices in different cities must share files.”

→ A router (usually a firewall) at each site, connected over a WAN or VPN.

Different networks always need routing between them.

Troubleshooting: which device is at fault?

When you know what each device does, you know where to look when something breaks:

SymptomPoints to
No link light on a wired PCThe cable, the switch port or the PC's NIC
Wi-Fi network name missingThe access point (or the wireless router's Wi-Fi)
169.254.x.x addressThe DHCP server, usually on the router, or the path to it
Local devices work, the internet doesn't, and the modem's online light is offThe modem or the provider
Local devices work, but other subnets can't be reachedThe router or the default gateway setting
Ping works, but one application doesn'tA firewall (network or host) blocking that port
The whole LAN suddenly slows to a crawl and the port lights flash constantlyA switching loop

Learn more: A Troubleshooting Method

Common mistakes

  • Calling every box with ports a “router” or a “hub”. Devices are defined by what they do, not by how they look, so name them by their job.
  • Thinking a switch connects you to the internet. A switch only connects devices within one network. Reaching the internet always needs a router.
  • Thinking switches stop broadcasts. Switches flood broadcasts out of every port. Routers (and VLANs) are what divide broadcast domains.
  • Thinking the modem is the router. They often share a box, but the jobs are different: the modem handles the line, the router handles IP.
  • Thinking a router is a firewall. A router decides where a packet goes; a firewall decides whether it may go at all.
  • Adding a second wireless router in router mode. It creates a separate network behind its own NAT, so devices on the two networks can't easily see each other. Use AP mode instead.
✅ Key takeaways
  • Hub = Layer 1 (repeats signals); switch = Layer 2 (MAC addresses); router = Layer 3 (IP addresses); firewall = Layers 3–4 and above.
  • Switches connect devices in one network; routers connect different networks and stop broadcasts.
  • Modems connect to the provider's line; routers share that connection with your LAN.
  • Routers decide where packets go; firewalls decide whether they are allowed at all.
  • An AP bridges Wi-Fi onto an existing network; a wireless router is a whole small network in one box.

Knowledge check

Predict · scenario 1

You need to connect two networks, 192.168.1.0/24 and 192.168.2.0/24, so that hosts can talk to each other but broadcasts stay inside each network. Which device do you need?

Predict · scenario 2

A PC sends a frame that crosses a switch and then a router on its way to another network. Which device puts a new source MAC address on it?

Predict · scenario 3

You replace an old 8-port hub with an 8-port switch. Eight PCs are connected. How do the collision domains change?

Predict · scenario 4

A small business has one provider line entering the building and wants Wi-Fi for staff and a firewall. Which list shows the minimum set of jobs needed?

Predict · scenario 5

Laptops on a new ceiling access point get 192.168.1.x addresses from the main router, the same as wired PCs. What does this tell you?

Where to go next

Every comparison in this lesson used OSI layers. The next unit explains them in detail, starting with The OSI model. To revisit a device, use the links below.

Learn more: Network Interface CardsHubsSwitchesRoutersModemsFirewallsWireless Access Points

FAQ

What is the main difference between a switch and a router?
A switch connects devices within one network and forwards frames using MAC addresses. A router connects different networks and forwards packets using IP addresses. You need a switch to build a LAN, and a router to reach any other network from that LAN, including the internet.
Is my home “router” really just a router?
No. A home router is usually a router, a small switch, a Wi-Fi access point, a DHCP server, a NAT device and a simple firewall in one case. The version your ISP supplies often has the modem built in too.
Why is a hub called a Layer 1 device if it has ports like a switch?
Because a device's layer depends on what it understands, not what it looks like. A hub only repeats electrical signals and never reads an address. A switch reads MAC addresses (Layer 2), and a router reads IP addresses (Layer 3).
Do I need a separate firewall at home?
Most homes don't. The home router's built-in firewall (helped by NAT) already blocks unsolicited traffic from the internet. Keep the router updated, avoid unnecessary port forwarding and keep each device's own firewall turned on.