You have now met each network device on its own. This lesson compares them directly. The key idea to remember is this: each device is defined by the information it uses to make decisions. A hub uses none, a switch uses MAC addresses, a router uses IP addresses, and a firewall uses addresses, ports and sometimes the application itself.
💡 In simple terms: picture a postal service. The hub photocopies every letter for every flat. The switch knows which flat each person lives in. The router knows which town to send a letter to. The firewall is the security check that refuses suspicious parcels. The modem is the loading dock where the post van arrives, and the access point is the letterbox you can use from anywhere in the garden.
All devices at a glance
| Device | OSI layer | Decides using | Main job | Where you find it |
|---|---|---|---|---|
| NIC | 1–2 | Its own MAC address | Connects one device to the network | Inside every device |
| Hub | 1 | Nothing (only signals) | Repeats every signal out of every port | Obsolete; found in old LANs |
| Switch | 2 | MAC addresses | Delivers frames to the right port within a LAN | At the centre of every LAN |
| Router | 3 | IP addresses | Moves packets between different networks | Between networks; the LAN's gateway |
| Modem | 1–2 | Line signals | Converts between Ethernet and the provider's line signal | Where the provider's line enters |
| Firewall | 3–4 (NGFW up to 7) | IPs, protocols, ports, apps | Allows or blocks traffic by rules | At the edge and between zones |
| Access point | 1–2 | MAC addresses | Bridges Wi-Fi devices onto the wired LAN | On ceilings and walls, cabled to a switch |
| Wireless router | 1–3 (+ NAT) | MAC and IP addresses | Router + switch + AP + DHCP + NAT + firewall in one | Homes and very small offices |
| OSI layer | Hub | Modem | AP | Switch | Router | Firewall |
|---|---|---|---|---|---|---|
| L7 ApplicationHTTP, DNS | – | – | – | – | – | some |
| L6 PresentationEncoding, encryption | – | – | – | – | – | – |
| L5 SessionSessions | – | – | – | – | – | – |
| L4 TransportTCP/UDP ports | – | – | – | – | some | ✓ |
| L3 NetworkIP addresses | – | – | – | – | ✓ | ✓ |
| L2 Data LinkFrames, MAC addresses | – | ✓ | ✓ | ✓ | ✓ | ✓ |
| L1 PhysicalBits on cable or radio | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
If the layers are new to you, the next unit explains them in detail.
Learn more: The OSI Model
Every device in one network
A home network
Follow a laptop opening routelearn.net. The traffic passes through almost every device in this unit, and each device does its own small part.
- 1. NIC + access point (Layers 1–2). The laptop's Wi-Fi NIC sends a frame by radio. The AP bridges it onto the wired side without changing the MAC addresses.
- 2. Router (Layer 3). The frame is addressed to the MAC address of the router, the default gateway. The router reads the destination IP address and chooses its route to the internet.
- 3. NAT and firewall (Layers 3–4). NAT replaces the private source IP address with the public one. The firewall records the connection so that the reply is allowed back in.
- 4. Modem (Layers 1–2). The modem converts the Ethernet frame into the provider's line signal.
- 5. The switch's role. Wired devices plug into the switch ports, and the switch delivers their frames to the router by MAC address.
An office network
In an office, each job usually has its own, larger device:
Hub vs. switch vs. router
These three devices are the classic comparison, because they can look alike and all have Ethernet ports.
| Hub | Switch | Router | |
|---|---|---|---|
| OSI layer | 1 (Physical) | 2 (Data Link) | 3 (Network) |
| Reads | Nothing: only signals | MAC addresses | IP addresses |
| Keeps a table of | Nothing | MAC address → port | Networks → next hop (routing table) |
| Sends a unicast | Out of every port | Out of the one correct port (floods it if the MAC address is unknown) | Out of the interface towards the destination network |
| Sends a broadcast | Out of every port | Out of every port | Never forwards it |
| Collision domains | One for all ports | One per port | One per interface |
| Broadcast domains | One | One (without VLANs) | One per interface |
| Changes the frame? | No | No | Yes: builds a new frame with new source and destination MACs |
| Connects | Devices in one LAN | Devices in one LAN | Different networks |
One broadcast, three devices
The clearest way to see the difference is to watch an ARP broadcast from PC A. The switch floods it to every device on its LAN, just as a hub would, but the router does not forward it.
- 1. PC A broadcasts. The switch floods it out of every other port, so PC B and the router both receive it.
- 2. The router doesn't forward broadcasts. The broadcast stops here. PC C, on another network, never receives it.
- 3. A normal packet to PC C is routed. A unicast packet addressed to 192.168.2.10 is forwarded by the router onto the other network.
Modem vs. router
| Modem | Router | |
|---|---|---|
| Job | Connects to the provider's line (DSL, cable, fibre, cellular) | Connects your network to other networks and shares the internet connection |
| OSI layer | 1–2 | 3 |
| IP addresses | Doesn't read or change them | Routes based on them; NAT changes them |
| Hands out addresses (DHCP) | No | Yes, on home routers |
| Without the other | One computer online, with no router protecting it | A working LAN, but no internet |
Many ISP boxes contain both. If you add your own router, put the ISP box in bridge mode so that only one device does the routing and NAT.
Learn more: Modems
Router vs. firewall
| Router | Firewall | |
|---|---|---|
| Main question it asks | "Where should this packet go?" | "Should this packet be allowed at all?" |
| Default behaviour | Forward anything it has a route for | Block anything not explicitly allowed |
| Reads | Destination IP address | Source and destination IP addresses, protocol and ports; NGFWs also identify the application |
| Remembers connections | No (except for NAT) | Yes: tracks each connection (stateful) |
| Built for | Fast forwarding, many routes, routing protocols | Inspection, rules, logging, threat protection |
| Overlap | Routers can filter with access lists; most firewalls can route and do NAT. Small sites often use one box for both jobs. | |
Access point vs. wireless router
| Access point | Wireless router | |
|---|---|---|
| What it contains | Wi-Fi radios and an Ethernet uplink | Router + switch + AP + DHCP + NAT + firewall |
| OSI layer | 1–2 (a bridge) | 1–3 |
| Creates a new IP network? | No: Wi-Fi clients join the existing subnet | Yes: its own LAN, for example 192.168.1.0/24 |
| Gives out IP addresses | No (the network's DHCP server does) | Yes |
| Connects to the internet | Only through a router somewhere else | Directly, through its WAN port and a modem |
| Typical use | Offices (many APs), extra coverage at home | Homes and very small offices |
⚠️ If you use a second wireless router as an extra access point without switching it to AP mode, it creates a second network with its own DHCP and NAT. Devices on it may not be able to reach printers or other devices on the first network.
What each device does to a packet
Here is a good test of your understanding: as a packet travels from a laptop to a server on the internet, which addresses does each device change?
| Device | MAC addresses | IP addresses | Ports |
|---|---|---|---|
| Hub | Unchanged | Unchanged | Unchanged |
| Switch | Unchanged | Unchanged | Unchanged |
| Access point | Unchanged (the Wi-Fi frame is rebuilt as an Ethernet frame with the same source and destination) | Unchanged | Unchanged |
| Router | New frame: its own MAC as the source, the next hop as the destination | Unchanged (but the TTL goes down by 1) | Unchanged |
| Router or firewall doing NAT | New frame | Private source address → public | Source port may change (PAT) |
| Modem | Carried across the line | Unchanged | Unchanged |
Later lessons follow these changes step by step.
Learn more: Different-Subnet CommunicationWhat Happens When You Open a Website?
Which device do I need?
“I want my phones and laptops to use Wi-Fi at home, and I have broadband.”
→ A wireless router (the ISP's box is often already one, with the modem built in).
It combines the modem, routing, NAT, DHCP and Wi-Fi in one box.
“My home router has 4 LAN ports and I need 8 wired devices.”
→ An unmanaged switch.
Connect one switch port to a LAN port on the router. The switch adds more ports on the same network.
“Wi-Fi is weak at the far end of the house, and I can run a cable there.”
→ An access point, cabled to the router or a switch.
A cabled AP gives the best performance. Without a cable, a mesh system is the next best option.
“Wi-Fi is weak upstairs and I can't run cables.”
→ A mesh Wi-Fi system.
Mesh units connect to each other by radio and share one network name (SSID).
“My office has 30 desks, IP phones and 4 ceiling APs on one floor.”
→ A managed PoE switch, plus a router and firewall at the edge.
PoE (Power over Ethernet) powers the APs and phones through the cable; managed features add VLANs and monitoring.
“I have a new fibre line and want to use my own router.”
→ The provider's ONT (or the provider's box in bridge mode) plus your own router.
The ONT (optical network terminal) handles the fibre. Your router does the routing, NAT and Wi-Fi, so there is no double NAT.
“I host a public web server and must protect the internal network.”
→ A firewall with a DMZ zone.
People on the internet can reach only the server in the DMZ; the internal network stays behind the firewall.
“Guests should get internet but never reach my office PCs.”
→ A guest SSID on the APs, separated by a router or firewall.
The guest network is a separate network, and the firewall only allows guest traffic out to the internet.
“Two offices in different cities must share files.”
→ A router (usually a firewall) at each site, connected over a WAN or VPN.
Different networks always need routing between them.
Troubleshooting: which device is at fault?
When you know what each device does, you know where to look when something breaks:
| Symptom | Points to |
|---|---|
| No link light on a wired PC | The cable, the switch port or the PC's NIC |
| Wi-Fi network name missing | The access point (or the wireless router's Wi-Fi) |
169.254.x.x address | The DHCP server, usually on the router, or the path to it |
| Local devices work, the internet doesn't, and the modem's online light is off | The modem or the provider |
| Local devices work, but other subnets can't be reached | The router or the default gateway setting |
| Ping works, but one application doesn't | A firewall (network or host) blocking that port |
| The whole LAN suddenly slows to a crawl and the port lights flash constantly | A switching loop |
Learn more: A Troubleshooting Method
Common mistakes
- Calling every box with ports a “router” or a “hub”. Devices are defined by what they do, not by how they look, so name them by their job.
- Thinking a switch connects you to the internet. A switch only connects devices within one network. Reaching the internet always needs a router.
- Thinking switches stop broadcasts. Switches flood broadcasts out of every port. Routers (and VLANs) are what divide broadcast domains.
- Thinking the modem is the router. They often share a box, but the jobs are different: the modem handles the line, the router handles IP.
- Thinking a router is a firewall. A router decides where a packet goes; a firewall decides whether it may go at all.
- Adding a second wireless router in router mode. It creates a separate network behind its own NAT, so devices on the two networks can't easily see each other. Use AP mode instead.
- Hub = Layer 1 (repeats signals); switch = Layer 2 (MAC addresses); router = Layer 3 (IP addresses); firewall = Layers 3–4 and above.
- Switches connect devices in one network; routers connect different networks and stop broadcasts.
- Modems connect to the provider's line; routers share that connection with your LAN.
- Routers decide where packets go; firewalls decide whether they are allowed at all.
- An AP bridges Wi-Fi onto an existing network; a wireless router is a whole small network in one box.
Knowledge check
You need to connect two networks, 192.168.1.0/24 and 192.168.2.0/24, so that hosts can talk to each other but broadcasts stay inside each network. Which device do you need?
A PC sends a frame that crosses a switch and then a router on its way to another network. Which device puts a new source MAC address on it?
You replace an old 8-port hub with an 8-port switch. Eight PCs are connected. How do the collision domains change?
A small business has one provider line entering the building and wants Wi-Fi for staff and a firewall. Which list shows the minimum set of jobs needed?
Laptops on a new ceiling access point get 192.168.1.x addresses from the main router, the same as wired PCs. What does this tell you?
Where to go next
Every comparison in this lesson used OSI layers. The next unit explains them in detail, starting with The OSI model. To revisit a device, use the links below.
Learn more: Network Interface CardsHubsSwitchesRoutersModemsFirewallsWireless Access Points