Switch, router, firewall and access point: what each device decides on
Four devices, four different decisions: the information each one uses, the scope it applies in, and why "which layer it is" is the wrong question.

A switch, a router, a firewall and an access point are not four layers on a stack. They are four different decisions, each defined by the information it uses and the scope it applies in. Read the four devices this way and which OSI layer is it stops being the useful question.
The model: different information, different scope
The reading key is a matrix. Each device asks a different question, on different information, inside a different scope; every section below fills one row.
| Device | Information it decides on | Scope of the decision |
|---|---|---|
| Switch | destination MAC address | one broadcast domain (a VLAN) |
| Router | destination IP prefix, by longest match | between IP subnets |
| Firewall | a policy applied to a flow | between zones or trust levels |
| Access point | which medium the frame arrives on | the wireless link and the wired LAN, at Layer 2 |
Terms used here
- MAC address — the 48-bit link-layer address a frame carries; the term used in commands, captures and vendor documentation.
- Broadcast domain — the set of interfaces reached by a Layer-2 broadcast; a router ends it.
- Prefix (subnet) — the network part of an IP address; longest prefix match picks the most specific route.
- Flow — packets related as one conversation (same addresses, ports and protocol); a firewall’s unit of decision.
- Zone — a name for a trust level; a firewall applies policy between zones.
What each device decides on
A switch forwards Ethernet frames on Layer 2. It reads the destination MAC address and looks it up in its MAC address table, built from the source address of the frames it receives; a destination it has not learned is flooded within the same VLAN. Its scope is a single broadcast domain: it sees no IP address, prefix or route. RFC 1812 calls these Link Layer packet-switching devices bridges and notes that the segments they join share the same IP network prefix.
A router forwards on Layer 3. It removes the incoming link header, reads the destination IP address and looks it up in its routing table. When several routes match, it keeps the most specific one: the longest prefix match. A packet matching 10.144.2.0/24, 10.144.0.0/16 and 10.0.0.0/8 is sent by the /24. The router also decrements the header’s hop counter on every pass: a packet whose counter reaches zero is discarded. Its scope is between IP subnets.
A firewall applies a policy — permit, drop or inspect — to traffic, and its unit of decision is the flow, not the individual packet: a stateful firewall tracks the connections it has already allowed. Its scope is zones or trust levels: what may cross between a trusted and an untrusted side.
An access point bridges a wireless medium to a wired one. In bridge mode it moves frames between the wireless link and the wired network, so a wireless client keeps its own address and stays in the same upstream subnet. On its own it creates no new subnet.
A common misconception: a device is not “a layer”
It is tempting to treat a device as a fixed layer, as if a firewall were “a Layer 4 device” or “a Layer 7 device” by nature. A firewall is not a layer; it is a policy engine, and the layer it is described at depends on what it actually inspects: addresses and ports, application content, or a stateless tuple. The same appliance can be described meaningfully at more than one layer depending on its configuration.
Where one device performs several roles
None of these roles needs its own box. A Layer 3 switch routes between VLANs; a firewall can hold routing tables and act as a router; an access point can bridge, tunnel to a controller, or both. RFC 1812 even describes an “embedded router”: a multi-homed host that also forwards. One appliance can perform several roles, but the roles stay distinct — only the enclosure is shared. The useful question is which decision is being made, on what information, and in what scope.
A security note: the appliance is not the control
A network device is not automatically a security control, and installing a firewall does not by itself create a boundary. A boundary is the product of three things: placement (what is on each side and what can bypass it), policy (what is permitted or denied, and whether the default is deny) and verification (whether the policy is enforced and observed). Permissive access lists on a router, one flat VLAN on a switch, or an access point bridging guests onto production can pass traffic a firewall would block. The control exists because of placement, policy and verification, not because of the device.
What to remember
- A role is defined by the information it decides on and the scope it applies in, not by an OSI layer it is said to be.
- Switch: destination MAC address, inside one broadcast domain.
- Router: destination prefix by longest match, between subnets, decrementing the hop counter.
- Firewall: policy over flows, across zones.
- Access point: a bridge between the wireless link and the wired LAN.
Level and prerequisites. L1 — fundamentals. Prerequisites: the OSI and TCP/IP models, IPv4 addressing and prefixes (CIDR), and MAC addresses and Ethernet frames. The sheet covers the roles and the forwarding decisions; configuring each device, and the stateful mechanics of a firewall, belong to the L2/L3 material.
Where to go next
- Networking — the area this sheet belongs to.
References
- RFC 1812 — Requirements for IP Version 4 Routers: the router’s forwarding decision, longest prefix match, the hop counter.
- Cisco — Nexus 9000 Series NX-OS Layer 2 Switching Configuration Guide (9.3x): the MAC address table and forwarding.
- Cisco — “Understand the Zone-Based Policy Firewall Design” (Doc ID 98628): zones and stateful inspection.
- Cisco Meraki — “SSID Modes for Client IP Assignment”: an access point bridging wireless clients onto the wired LAN.
- RFC 9293 and RFC 768 — TCP and UDP: the transport context behind a firewall’s notion of a flow.