Switches, Routers and Firewalls
Switch: Layer 2
A switch connects devices inside the same local network (LAN). It works at Layer 2 of the OSI model, using MAC addresses to deliver frames to the right port.
How it works
- A device sends an Ethernet frame.
- The switch reads the source MAC address and records which port it arrived on (the MAC / CAM table).
- It looks up the destination MAC address in that table to pick the outgoing port.
- If the destination is unknown, it floods the frame out of every port until it learns where the device lives. The switch builds its MAC table automatically — no configuration needed for basic forwarding.
Router: Layer 3
A router connects different networks together. It works at Layer 3, using IP addresses and a routing table to decide where each packet goes — including the default route to the internet. On every hop it also decrements the packet’s TTL.
Network A (192.168.1.0/24) ──── [Router] ──── Network B (10.0.0.0/24)
│
Internet (0.0.0.0/0)
Firewall
A firewall sits between networks and decides which traffic is allowed through, based on rules (source, destination, port, application). Modern firewalls usually also handle NAT and VPN termination. In a typical small datacenter it is the border device — and often the edge router too.
Managed vs unmanaged
| Feature | Unmanaged | Managed |
|---|---|---|
| Configuration | Plug & play | CLI (SSH), web UI, SNMP |
| VLANs | No | Yes |
| QoS | No | Yes |
| Monitoring | None | Full (SNMP, syslog) |
| Port mirroring | No | Yes |
| Cost | Low | Medium–high |
| Use | Small offices | Datacenters, enterprise networks |
In a datacenter, always use managed switches. Being able to configure VLANs, monitor ports and manage the device remotely is non-negotiable.
Layer 3 switches
A Layer 3 switch combines switching and routing. It routes traffic between VLANs in hardware using switched virtual interfaces (SVIs), with no external router needed. It is the standard core device in modern datacenters.
| Function | L2 switch | L3 switch | Router | Firewall |
|---|---|---|---|---|
| MAC switching | Yes | Yes | No | No |
| VLANs | Yes | Yes | Subinterfaces | Subinterfaces |
| IP routing | No | Yes | Yes | Yes |
| NAT / traffic filtering | No | Limited | Basic | Yes (core job) |
| WAN links | No | Rarely | Yes | Yes |
Major vendors
| Vendor | Lines | CLI / OS | Notes |
|---|---|---|---|
| Cisco | Catalyst, Nexus | IOS, NX-OS | Industry standard |
| Juniper | EX, QFX | Junos | Strong in ISPs and datacenters |
| Aruba/HPE | CX, ProCurve | AOS-CX | Good value for money |
| MikroTik | CRS, CCR | RouterOS | Very flexible, low cost |
| Dell | PowerSwitch | OS10 | Integrates with Dell servers |
| Arista | 7000 series | EOS | Cloud datacenter, low latency |
CreaRack connects to these vendors over SSH through the Terminal — see [[crearack—terminal—sesiones-ssh]] — and the [[crearack—network—auto-provision-wizard]] can identify vendor and model automatically via SNMP.
Power over Ethernet (PoE)
PoE delivers power over the network cable itself, so devices like phones and access points need no separate power supply.
| Standard | Name | Max power | Typical use |
|---|---|---|---|
| 802.3af | PoE | 15.4 W | IP phones, basic cameras |
| 802.3at | PoE+ | 30 W | PTZ cameras, WiFi APs |
| 802.3bt | PoE++ | 60–90 W | Displays, thin clients, WiFi 6/7 APs |
Important: when planning rack power, add the switch’s PoE load to your PDU budget. A fully loaded 48-port PoE+ switch can draw well over 700 W on its own.
In CreaRack
Switches, routers and firewalls are documented as devices in the Rack Editor, with vendor-specific stencils. Observatory monitors their interfaces, CPU, memory and temperature via SNMP, and you can open an SSH session to any of them directly from the rack — see [[crearack—racks—ssh-desde-rack]].
Related
- [[crearack—redes-infra—vlans]] — logical segmentation on switches
- [[crearack—redes-infra—cableado]] — physically connecting this equipment
- [[crearack—redes-infra—direccionamiento-ip]] — the subnets routers connect
- [[crearack—redes-infra—conceptos-snmp]] — monitoring these devices via SNMP
- [[crearack—network—auto-provision-wizard]] — discovering switches and routers
- [[crearack—racks—ssh-desde-rack]] — SSH to a device from its rack
- [[crearack—terminal—sesiones-ssh]] — multi-vendor SSH session management
- [[crearack—monitoring—que-es-observatory]] — full monitoring of network gear
Véase también
- [[crearack—redes-infra—vlans]]
- [[crearack—redes-infra—cableado]]
- [[crearack—redes-infra—direccionamiento-ip]]
- [[crearack—redes-infra—conceptos-snmp]]
- [[crearack—network—auto-provision-wizard]]
- [[crearack—racks—ssh-desde-rack]]
- [[crearack—terminal—sesiones-ssh]]
- [[crearack—monitoring—que-es-observatory]]