Flagg-Coburn House and Network switch: Difference between pages

From Wikipedia, the free encyclopedia
(Difference between pages)
Content deleted Content added
m Stub-sorting. You can help!
 
Dkhydema (talk | contribs)
 
Line 1: Line 1:
{{Other|Switch (disambiguation)}}
{{Infobox_nrhp | name =Flagg--Coburn House
| nrhp_type =
| image =
| caption =
| location= [[Lowell, Massachusetts]]
| lat_degrees = 42
| lat_minutes = 38
| lat_seconds = 45
| lat_direction = N
| long_degrees = 71
| long_minutes = 17
| long_seconds = 14
| long_direction = W
| locmapin = Massachusetts
| area =
| built =1926
| architect= Flagg,Ernest
| architecture= Other
| added = [[May 15]], [[1986]]
| governing_body = Private
| refnum=86001052
<ref name="nris">{{cite web|url=http://www.nr.nps.gov/|title=National Register Information System|date=2008-04-15|work=National Register of Historic Places|publisher=National Park Service}}</ref>
}}


{{Mergefrom|transparent bridge|talk:transparent bridge|date=August 2008}} <!-- I actually prefer to merge "transparent bridge" into "bridging (networking)," but I wish to let the community decide whether to do that or to merge transparent bridge into here instead. -->
'''Flagg-Coburn House''' is a historic house at 722 E. Merrimack Street in [[Lowell, Massachusetts]].
[[Image:Ethernet switch Atlantis A02-F5P 5 ports frontend.jpg|thumb|250px|Typical [[Small office|SOHO]] network switch.]]
[[Image:Ethernet switch Atlantis A02-F5P 5 ports backend.jpg|thumb|250px|Back view of Atlantis network switch with [[Ethernet]] [[Computer port (hardware)|ports]].]]
A '''network switch''' is a broad and imprecise marketing term for a [[computer networking device]] that connects [[computer network|network]] [[Network segment|segments]].


The term commonly refers to a [[Network bridge]] that processes and routes data at the [[Data link layer]] (layer 2) of the [[OSI model]]. Switches that additionally process data at the [[Network layer]] (layer 3) (and above) are often referred to as Layer 3 switches or [[Multilayer switch]]es.

The term Network switch does not generally encompass unintelligent or passive network devices such as [[Network hub|hubs]] and [[repeaters]].

The first [[Ethernet]] switch was introduced by [[Kalpana (company)|Kalpana]] in 1989. <ref>{{cite web|title=The 10 Most Important Products of the Decade|author=Robert J. Kohlhepp|date=2000-10-02|accessdate=2008-02-25|publisher=Network Computing|url=http://www.networkcomputing.com/1119/1119f1products_5.html}}</ref>

== Function ==

As with [[Network hub|hubs]], [[Ethernet]] implementations of network switches support either 10/100&nbsp;Mbit/s or 10/100/1000&nbsp;Mbit/s ports Ethernet standards. Large switches may have 10&nbsp;Gbit/s ports. Switches differ from [[Network hub|hubs]] in that they can have ports of different speed.

The '''network switch''', '''packet switch''' (or just '''switch''') plays an integral part in most [[Ethernet]] [[local area network]]s or ''LANs''. Mid-to-large sized LANs contain a number of linked [[Network switch#Configuration options|managed]] switches. [[Small office, home office]] (SOHO) applications typically use a single switch, or an all-purpose [[Technological convergence|converged device]] such as [[Residential gateway|gateway]] access to small office/home office [[broadband]] services such as [[Residential gateway|DSL router]] or [[Cable modem|cable]], [[Wi-Fi#Wireless Router|Wi-Fi router]]. In most of these cases, the end user device contains a [[router]] and components that interface to the particular physical broadband technology, as in the Linksys 8-port and 48-port devices. User devices may also include a telephone interface to [[VoIP]].

'''In simple terms''', in the context of a standard 10/100 Ethernet switch, a switch operates at the data-link layer of the OSI model to create a different collision domain per switch port. This basically says that if you have 4 computers A/B/C/D on 4 switch ports, then A and B can transfer data between them as well as C and D at the same time, and they will never interfere with each others' conversations. That is the basic idea. In the case of a "hub" then they would all have to share the bandwidth, run in half-duplex and there would be collisions and retransmissions. Using a switch is called micro-segmentation - it allows you to have dedicated bandwidth on point to point connections with every computer and to therefore run in full duplex with no collisions.

==Role of switches in networks==
Network switch is a marketing term rather than a technical one. Switches may operate at one or more [[OSI model| OSI]] layers, including [[physical layer|physical]], [[data link layer|data link]], [[network layer|network]], or [[transport layer|transport (i.e., end-to-end)]]. A device that operates simultaneously at more than one of these layers is called a [[multilayer switch]], although use of the term is diminishing.
In switches intended for commercial use, built-in or modular interfaces make it possible to connect different types of networks, for example [[Ethernet]], [[Fibre Channel]], [[Asynchronous Transfer Mode|ATM]], and [[802.11]]. This connectivity can be at any of the layers mentioned. While Layer 2 functionality is adequate for speed-shifting within one technology, interconnecting technologies such as [[Ethernet]] and [[token ring]] are easier at Layer 3.

Again, "switch" is principally a marketing term; interconnection of different Layer 3 networks is done by [[router]]s. If there are any features that characterize "Layer-3 switches" as opposed to general-purpose routers, it tends to be that they are optimized, in larger switches, for high-density Ethernet connectivity.

In some service provider and other environments where there is a need for much analysis of network performance and security, switches may be connected between WAN routers as places for analytic modules. Some vendors provide [[firewall]],<ref>[http://cisco.com/en/US/products/hw/modules/ps2706/ps4452/index.html Cisco Catalyst 6500 Series Firewall Services Module],Cisco Systems,2007</ref><ref>[http://www.3com.com/products/en_US/detail.jsp?tab=features&sku=3C17546&pathtype=purchase3Com® Switch 8800 Firewall Module],3Com Corporation, 2006</ref> network [[intrusion detection]],<ref>[http://cisco.com/en/US/products/hw/modules/ps2706/ps5058/index.html Cisco Catalyst 6500 Series Intrusion Detection System (IDSM-2) Module],Cisco Systems,2007</ref> and performance analysis modules that can plug into switch ports. Some of these functions may be on combined modules.<ref>[http://www.checkpoint.com/support/technical/online_ug/firewall-14.0/config.htm Getting Started with Check Point FireWall-1],Checkpoint Software Technologies Ltd., n.d.</ref>

In other cases, the switch is used to create a "mirror" image of data that can go to an external device. Since most switch port mirroring provides only one mirrored stream, [[network hub]]s can be useful for fanning out data to several read-only analyzers, such as [[intrusion detection system]]s and [[packet sniffer]]s.

== Layer-specific functionality ==
[[Image:Smartswitch6000.jpg|thumb|250px|A modular network switch with three network modules (a total of 24 Ethernet and 14 Fast Ethernet ports) and one power supply.]]
While switches may learn about topologies at many [[OSI model|layers]], and forward at one or more layers, they do tend to have common features. Other than for computer-room very high performance applications, modern commercial switches use primarily Ethernet interfaces, which can have different input and output speeds of 10, 100, 1000 or 10,000 [[megabits per second]]. Switch ports almost always default to [[full-duplex]] operation, unless there is a requirement for interoperability with devices that are strictly half duplex. [[Half-duplex]] means that the device can only send or receive at any given time, whereas full-duplex can send and receive at the same time.

At any layer, a modern switch may implement [[power over Ethernet]] (PoE), which avoids the need for attached devices, such as an IP telephone or [[wireless access point]], to have a separate power supply. Since switches can have redundant power circuits connected to [[uninterruptible power supply|uninterruptible power supplies]], the connected device can continue operating even when regular office power fails.

=== Layer-1 hubs versus higher-layer switches ===

A [[network hub]], or repeater, is a fairly unsophisticated cast device, and rapidly becoming obsolete. Hubs do not manage any of the traffic that comes through them. Any packet entering a [[computer port (hardware)|port]] is broadcast out or "repeated" on every other port, except for the port of entry. Since every packet is repeated on every other port, packet [[Collision (telecommunications)|collisions]] result, which slows down the network.

Hubs have actually become hard to find, due to the widespread use of switches. There are specialized applications where a hub can be useful, such as copying traffic to multiple network sensors. High end switches have a feature which does the same thing called [[port mirroring]]. There is no longer any significant price difference between a hub and a low-end switch.

=== Layer 2 ===
{{Citations missing|section|August 2008|date=August 2008}}
A [[network bridge]], operating at the [[Media Access Control]] (MAC) sublayer of the data link layer, may interconnect a small number of devices in a home or office. This is a trivial case of bridging, in which the bridge learns the [[MAC address]] of each connected device. Single bridges also can provide extremely high performance in specialized applications such as [[storage area networks]].

Bridges may also interconnect using a [[spanning tree protocol]] that allows the best path to be found within the constraint that it is a tree. In contrast to routers, bridges must have topologies with only one active path between two points. The older [[IEEE 802.1D]] spanning tree protocol could be quite slow, with forwarding stopping for 30-90 seconds while the spanning tree would reconverge. A [[Rapid Spanning Tree Protocol]] was introduced as IEEE [[802.1w]], but the newest edition of IEEE 802.1D-2004, adopts the 802.1w extensions as the base standard.

While "layer 2 switch" remains more of a marketing term than a technical term, the products that were introduced as "switches" tended to use [[microsegmentation]] and [[full duplex]] to prevent collisions among devices connected to Ethernets. By using an internal [[forwarding plane]] much faster than any interface, they give the impression of simultaneous paths among multiple devices.

Once a bridge learns the topology through a spanning tree protocol, it forwards data link layer frames using a layer 2 forwarding method. There are four forwarding methods a bridge can use, of which the second through fourth method were performance-increasing methods when used on "switch" products with the same input and output port speeds:

# [[Store and forward]]: The switch buffers and, typically, performs a [[checksum]] on each frame before forwarding it on.
# [[Cut-through switching|Cut through]]: The switch reads only up to the frame's hardware address before starting to forward it. There is no error checking with this method.
# [[Fragment free]]: A method that attempts to retain the benefits of both "store and forward" and "cut through". Fragment free checks the first 64 [[byte]]s of the [[Data frame|frame]], where [[Address space|addressing]] information is stored. This way the frame will always reach its intended destination. Error checking of the actual data in the packet is left for the end device in Layer 3 or Layer 4 ([[OSI model|OSI]]), typically a [[router]].
# [[Adaptive switching]]: A method of automatically switching between the other three modes.

Cut-through switches have to fall back to store and forward if the outgoing port is busy at the time the packet arrives. While there are specialized applications, such as storage area networks, where the input and output interfaces are the same speed, this is rarely the case in general LAN applications. In LANs, a switch used for end user access typically concentrates lower speed (e.g., 10/100&nbsp;Mbits/s) into a higher speed (at least 1&nbsp;Gbit/s). Alternatively, a switch that provides access to server ports usually connects to them at a much higher speed than is used by end user devices.

=== Layer 3 ===

[[Router]] is a marketing term for a Layer 3 switch, typically optimized for Ethernet interfaces. Like other switches, it connects devices to single ports for microsegmentation. The ports normally operate in full duplex.

Switches, even primarily Layer 2 switches, can be aware of Layer 3 [[multicast]] and increase efficiency by delivering the traffic of a multicast group only to ports where the attached device has signaled that it wants to listen to that group. If a switch not aware of multicasting and broadcasting, frames are also forwarded on all ports of each [[broadcast domain]], but in the case of IP multicast this causes inefficient use of bandwidth. To work around this problem some switches implement [[IGMP]] snooping.<ref>Morten Jagd Christensen et.al [http://www.ietf.org/rfc/rfc4541.txt?number=4541 IGMP Snooping]</ref>

=== Layer 4 ===

While the exact meaning of the term Layer-4 switch is vendor-dependent, it almost always starts with a capability for [[network address translation]], but then adds some type of [[Load balancing (computing)|load distribution]] based on [[Transmission Control Protocol|TCP]] sessions.<ref>[http://www.nanog.org/mtg-9901/ppt/alteon/alteon.ppt The Ins and Outs of Layer 4+ Switching],NANOG 15, S. Sathaye,January 1999</ref>

The device may include a stateful [[firewall]], a [[VPN]] concentrator, or be an [[IPSec]] security gateway.

=== Layer 7 ===

As with the other types of switches, Layer 7 is a marketing term. They may distribute loads based on [[Uniform Resource Locator|URL]] or by some installation-specific technique to recognize application-level transactions. A Layer-7 switch may include a [[web cache]] and participate in a [[content delivery network]].<ref>[http://www.irbs.net/internet/nanog/0110/0618.html How worried is too worried? Plus, a Global Crossing Story.],NANOG mailing list archives, S. Gibbard,October 2001</ref>
[[Image:24-port 3Com switch.JPG|thumb|right|260px|24-port [[3Com]] switch]]

== Types of switches ==
=== Form factor ===
* Desktop, not mounted in an enclosure, typically intended to be used in a home or office environment outside of a wiring closet
* [[19-inch rack|Rack]] mounted
* [[Chassis]] — with swappable "switch module" cards. e.g. Alcatel's OmniSwitch 7000; Cisco [[Catalyst switch]] 4500 and 6500; 3Com 7700, 7900E, 8800.

=== Configuration options ===
* ''Unmanaged'' switches — These switches have no configuration interface or options. They are "plug-and-play." They are typically the least expensive switches, found in home, [[SOHO network|SOHO]], or small businesses. They can be desktop or rack mounted.
* ''Managed'' switches — These switches have one or more ways, or interfaces, to modify the operation of the switch. Common management methods include: a [[serial console]] or Command Line Interface accessed via [[telnet]] or [[Secure Shell]]; an embedded Simple Network Management Protocol [[SNMP]] agent allowing management from a remote console or management station; a web interface for management from a web browser. Examples of configuration changes that one can do from a managed switch include: enable features such as [[Spanning Tree Protocol]]; set [[Transmission rate|port speed]]; create or modify [[VLAN]]s, etc. Two sub-classes of managed switches are marketed today:
** ''Smart'' (or intelligent) switches — These are managed switches with a limited set of management features. Likewise "web-managed" switches are switches which fall in a market niche between unmanaged and managed. For a price much lower than a fully managed switch they provide a web interface (and usually no CLI access) and allow configuration of basic settings, such as [[VLAN]]s, port-speed and duplex.<ref>[http://www.hp.com/rnd/products/switches/ProCurve_Switch_1800_Series/specs.htm Tech specs for a sample HP "web-managed" switch]</ref>
** ''Enterprise Managed'' (or fully managed) switches - These have a full set of management features, including Command Line Interface, SNMP agent, and web interface. They may have additional features to manipulate configurations, such as the ability to display, modify, backup and restore configurations. Compared with smart switches, enterprise switches have more features that can be customized or optimized, and are generally more expensive than "smart" switches. Enterprise switches are typically found in networks with larger number of switches and connections, where centralized management is a significant savings in administrative time and effort. A [[Stackable switch]] is a version of enterprise-managed switch.

==== Traffic monitoring on a switched network ====
Unless port mirroring or other methods such as [[RMON]]<ref>[http://www.ietf.org/rfc/rfc2819.txt Remote Network Monitoring Management Information Base],RFC 2819, S. Waldbusser,May 2000</ref> or [[SMON]] are implemented in a switch, it is difficult to monitor traffic that is bridged using a switch because all ports are isolated until one transmits data, and even then only the sending and receiving ports can see the traffic. These monitoring features rarely are present on consumer-grade switches.

Two popular methods that are specifically designed to allow a network analyst to monitor traffic are:

*[[Port mirroring]] — the switch sends a copy of network packets to a monitoring network connection.
*[[SMON]] — "Switch Monitoring" is described by RFC 2613 and is a protocol for controlling facilities such as port mirroring.

Another method to monitor may be to connect a Layer-1 hub between the monitored device and its switch port. This will induce minor delay, but will provide multiple interfaces that can be used to monitor the individual switch port.

====Typical switch management features ====
[[Image:Linksys48portswitch.jpg|thumb|250px|[[Linksys]] 48-port switch.]]
[[Image:Switch-and-nest.jpg|thumb|A rack-mounted switch with network cables]]
(In order of basic to advanced):
* Turn some particular port range on or off
* Link speed and [[duplex (telecommunications)|duplex]] settings
* Priority settings for ports
* [[MAC filtering]] — and other types of "port security" features which prevent [[MAC flooding]]
* Use of [[Spanning Tree Protocol]]
* [[SNMP]] monitoring of device and link health
* [[Port mirroring]] (also known as: port monitoring, spanning port, SPAN port, roving analysis port or link mode port)
* [[Link aggregation]] (also known as: bonding, trunking or teaming)
* [[VLAN]] settings
* [[802.1X]] [[network access control]]

[[Link aggregation]] allows you to use multiple ports for the same connection achieving higher data transfer speeds. Creating [[Virtual LAN|VLANs]] can serve security and performance goals by reducing the size of the [[broadcast domain]].

== See also==
*[[LAN switching]]
*[[10/100 switch]]
*[[Local area network]]
*[[Network bridge]]
*[[Multilayer switch]]
*[[Console server]]
*[[Router]]
*[[Telephone exchange]]


The house was built in 1926 by Ernest Flagg and was added to the National Register of Historic Places in 1986.<ref name="nris">{{cite web|url=http://www.nr.nps.gov/|title=National Register Information System|date=2008-04-15|work=National Register of Historic Places|publisher=National Park Service}}</ref>
==References==
==References==
{{reflist}}
{{Reflist}}

== External links ==
* [http://www.delloro.com/news/2006/ES051706.htm Ethernet Switch Market Retreats in the First Quarter of 2006]
* [http://www2.cio.com/research/surveyreport.cfm?id=9 CIO Second-Hand IT — Research Reports — CIO — Research]
* [http://www.networkworld.com/research/2006/020606-network-switch.html Network World examines the changing nature of the network switch — First Quarter of 2006]
* [http://www.ciena.com/products/9267.htm Now Convergence Makes Sense]


[[Category:Ethernet]]
{{Registered Historic Places}}
[[Category:Networking hardware|Switch]]


[[ast:Switch]]
[[Category:Registered Historic Places in Massachusetts]]
[[bs:Switch]]
{{lowellMA-NRHP-stub}}
[[ca:Commutador (xarxa)]]
[[cs:Switch]]
[[da:Netværksswitch]]
[[de:Switch (Computertechnik)]]
[[es:Conmutador (dispositivo de red)]]
[[eu:Switch]]
[[fa:سوئیچ کردن]]
[[fr:Commutateur réseau]]
[[gl:Switch]]
[[ko:이더넷 스위치]]
[[id:Switch jaringan]]
[[ia:Commutator (rete de computatores)]]
[[it:Switch]]
[[he:מתג (רשתות מחשבים)]]
[[ml:നെറ്റ്വര്‍ക്ക് സ്വിച്ച്]]
[[nl:Switch (hardware)]]
[[ja:スイッチングハブ]]
[[no:Switch]]
[[pl:Przełącznik]]
[[pt:Comutador (redes)]]
[[ru:Сетевой коммутатор]]
[[sk:Prepínač (prvok počítačovej siete)]]
[[sl:Omrežno stikalo]]
[[fi:Kytkin (tietoliikenne)]]
[[sv:Switch]]
[[vi:Switch]]
[[tr:Ağ anahtarı]]
[[zh:交换机]]

Revision as of 02:48, 11 October 2008

Typical SOHO network switch.
Back view of Atlantis network switch with Ethernet ports.

A network switch is a broad and imprecise marketing term for a computer networking device that connects network segments.


The term commonly refers to a Network bridge that processes and routes data at the Data link layer (layer 2) of the OSI model. Switches that additionally process data at the Network layer (layer 3) (and above) are often referred to as Layer 3 switches or Multilayer switches.

The term Network switch does not generally encompass unintelligent or passive network devices such as hubs and repeaters.

The first Ethernet switch was introduced by Kalpana in 1989. [1]

Function

As with hubs, Ethernet implementations of network switches support either 10/100 Mbit/s or 10/100/1000 Mbit/s ports Ethernet standards. Large switches may have 10 Gbit/s ports. Switches differ from hubs in that they can have ports of different speed.

The network switch, packet switch (or just switch) plays an integral part in most Ethernet local area networks or LANs. Mid-to-large sized LANs contain a number of linked managed switches. Small office, home office (SOHO) applications typically use a single switch, or an all-purpose converged device such as gateway access to small office/home office broadband services such as DSL router or cable, Wi-Fi router. In most of these cases, the end user device contains a router and components that interface to the particular physical broadband technology, as in the Linksys 8-port and 48-port devices. User devices may also include a telephone interface to VoIP.

In simple terms, in the context of a standard 10/100 Ethernet switch, a switch operates at the data-link layer of the OSI model to create a different collision domain per switch port. This basically says that if you have 4 computers A/B/C/D on 4 switch ports, then A and B can transfer data between them as well as C and D at the same time, and they will never interfere with each others' conversations. That is the basic idea. In the case of a "hub" then they would all have to share the bandwidth, run in half-duplex and there would be collisions and retransmissions. Using a switch is called micro-segmentation - it allows you to have dedicated bandwidth on point to point connections with every computer and to therefore run in full duplex with no collisions.

Role of switches in networks

Network switch is a marketing term rather than a technical one. Switches may operate at one or more OSI layers, including physical, data link, network, or transport (i.e., end-to-end). A device that operates simultaneously at more than one of these layers is called a multilayer switch, although use of the term is diminishing.

In switches intended for commercial use, built-in or modular interfaces make it possible to connect different types of networks, for example Ethernet, Fibre Channel, ATM, and 802.11. This connectivity can be at any of the layers mentioned. While Layer 2 functionality is adequate for speed-shifting within one technology, interconnecting technologies such as Ethernet and token ring are easier at Layer 3.

Again, "switch" is principally a marketing term; interconnection of different Layer 3 networks is done by routers. If there are any features that characterize "Layer-3 switches" as opposed to general-purpose routers, it tends to be that they are optimized, in larger switches, for high-density Ethernet connectivity.

In some service provider and other environments where there is a need for much analysis of network performance and security, switches may be connected between WAN routers as places for analytic modules. Some vendors provide firewall,[2][3] network intrusion detection,[4] and performance analysis modules that can plug into switch ports. Some of these functions may be on combined modules.[5]

In other cases, the switch is used to create a "mirror" image of data that can go to an external device. Since most switch port mirroring provides only one mirrored stream, network hubs can be useful for fanning out data to several read-only analyzers, such as intrusion detection systems and packet sniffers.

Layer-specific functionality

A modular network switch with three network modules (a total of 24 Ethernet and 14 Fast Ethernet ports) and one power supply.

While switches may learn about topologies at many layers, and forward at one or more layers, they do tend to have common features. Other than for computer-room very high performance applications, modern commercial switches use primarily Ethernet interfaces, which can have different input and output speeds of 10, 100, 1000 or 10,000 megabits per second. Switch ports almost always default to full-duplex operation, unless there is a requirement for interoperability with devices that are strictly half duplex. Half-duplex means that the device can only send or receive at any given time, whereas full-duplex can send and receive at the same time.

At any layer, a modern switch may implement power over Ethernet (PoE), which avoids the need for attached devices, such as an IP telephone or wireless access point, to have a separate power supply. Since switches can have redundant power circuits connected to uninterruptible power supplies, the connected device can continue operating even when regular office power fails.

Layer-1 hubs versus higher-layer switches

A network hub, or repeater, is a fairly unsophisticated cast device, and rapidly becoming obsolete. Hubs do not manage any of the traffic that comes through them. Any packet entering a port is broadcast out or "repeated" on every other port, except for the port of entry. Since every packet is repeated on every other port, packet collisions result, which slows down the network.

Hubs have actually become hard to find, due to the widespread use of switches. There are specialized applications where a hub can be useful, such as copying traffic to multiple network sensors. High end switches have a feature which does the same thing called port mirroring. There is no longer any significant price difference between a hub and a low-end switch.

Layer 2

A network bridge, operating at the Media Access Control (MAC) sublayer of the data link layer, may interconnect a small number of devices in a home or office. This is a trivial case of bridging, in which the bridge learns the MAC address of each connected device. Single bridges also can provide extremely high performance in specialized applications such as storage area networks.

Bridges may also interconnect using a spanning tree protocol that allows the best path to be found within the constraint that it is a tree. In contrast to routers, bridges must have topologies with only one active path between two points. The older IEEE 802.1D spanning tree protocol could be quite slow, with forwarding stopping for 30-90 seconds while the spanning tree would reconverge. A Rapid Spanning Tree Protocol was introduced as IEEE 802.1w, but the newest edition of IEEE 802.1D-2004, adopts the 802.1w extensions as the base standard.

While "layer 2 switch" remains more of a marketing term than a technical term, the products that were introduced as "switches" tended to use microsegmentation and full duplex to prevent collisions among devices connected to Ethernets. By using an internal forwarding plane much faster than any interface, they give the impression of simultaneous paths among multiple devices.

Once a bridge learns the topology through a spanning tree protocol, it forwards data link layer frames using a layer 2 forwarding method. There are four forwarding methods a bridge can use, of which the second through fourth method were performance-increasing methods when used on "switch" products with the same input and output port speeds:

  1. Store and forward: The switch buffers and, typically, performs a checksum on each frame before forwarding it on.
  2. Cut through: The switch reads only up to the frame's hardware address before starting to forward it. There is no error checking with this method.
  3. Fragment free: A method that attempts to retain the benefits of both "store and forward" and "cut through". Fragment free checks the first 64 bytes of the frame, where addressing information is stored. This way the frame will always reach its intended destination. Error checking of the actual data in the packet is left for the end device in Layer 3 or Layer 4 (OSI), typically a router.
  4. Adaptive switching: A method of automatically switching between the other three modes.

Cut-through switches have to fall back to store and forward if the outgoing port is busy at the time the packet arrives. While there are specialized applications, such as storage area networks, where the input and output interfaces are the same speed, this is rarely the case in general LAN applications. In LANs, a switch used for end user access typically concentrates lower speed (e.g., 10/100 Mbits/s) into a higher speed (at least 1 Gbit/s). Alternatively, a switch that provides access to server ports usually connects to them at a much higher speed than is used by end user devices.

Layer 3

Router is a marketing term for a Layer 3 switch, typically optimized for Ethernet interfaces. Like other switches, it connects devices to single ports for microsegmentation. The ports normally operate in full duplex.

Switches, even primarily Layer 2 switches, can be aware of Layer 3 multicast and increase efficiency by delivering the traffic of a multicast group only to ports where the attached device has signaled that it wants to listen to that group. If a switch not aware of multicasting and broadcasting, frames are also forwarded on all ports of each broadcast domain, but in the case of IP multicast this causes inefficient use of bandwidth. To work around this problem some switches implement IGMP snooping.[6]

Layer 4

While the exact meaning of the term Layer-4 switch is vendor-dependent, it almost always starts with a capability for network address translation, but then adds some type of load distribution based on TCP sessions.[7]

The device may include a stateful firewall, a VPN concentrator, or be an IPSec security gateway.

Layer 7

As with the other types of switches, Layer 7 is a marketing term. They may distribute loads based on URL or by some installation-specific technique to recognize application-level transactions. A Layer-7 switch may include a web cache and participate in a content delivery network.[8]

24-port 3Com switch

Types of switches

Form factor

  • Desktop, not mounted in an enclosure, typically intended to be used in a home or office environment outside of a wiring closet
  • Rack mounted
  • Chassis — with swappable "switch module" cards. e.g. Alcatel's OmniSwitch 7000; Cisco Catalyst switch 4500 and 6500; 3Com 7700, 7900E, 8800.

Configuration options

  • Unmanaged switches — These switches have no configuration interface or options. They are "plug-and-play." They are typically the least expensive switches, found in home, SOHO, or small businesses. They can be desktop or rack mounted.
  • Managed switches — These switches have one or more ways, or interfaces, to modify the operation of the switch. Common management methods include: a serial console or Command Line Interface accessed via telnet or Secure Shell; an embedded Simple Network Management Protocol SNMP agent allowing management from a remote console or management station; a web interface for management from a web browser. Examples of configuration changes that one can do from a managed switch include: enable features such as Spanning Tree Protocol; set port speed; create or modify VLANs, etc. Two sub-classes of managed switches are marketed today:
    • Smart (or intelligent) switches — These are managed switches with a limited set of management features. Likewise "web-managed" switches are switches which fall in a market niche between unmanaged and managed. For a price much lower than a fully managed switch they provide a web interface (and usually no CLI access) and allow configuration of basic settings, such as VLANs, port-speed and duplex.[9]
    • Enterprise Managed (or fully managed) switches - These have a full set of management features, including Command Line Interface, SNMP agent, and web interface. They may have additional features to manipulate configurations, such as the ability to display, modify, backup and restore configurations. Compared with smart switches, enterprise switches have more features that can be customized or optimized, and are generally more expensive than "smart" switches. Enterprise switches are typically found in networks with larger number of switches and connections, where centralized management is a significant savings in administrative time and effort. A Stackable switch is a version of enterprise-managed switch.

Traffic monitoring on a switched network

Unless port mirroring or other methods such as RMON[10] or SMON are implemented in a switch, it is difficult to monitor traffic that is bridged using a switch because all ports are isolated until one transmits data, and even then only the sending and receiving ports can see the traffic. These monitoring features rarely are present on consumer-grade switches.

Two popular methods that are specifically designed to allow a network analyst to monitor traffic are:

  • Port mirroring — the switch sends a copy of network packets to a monitoring network connection.
  • SMON — "Switch Monitoring" is described by RFC 2613 and is a protocol for controlling facilities such as port mirroring.

Another method to monitor may be to connect a Layer-1 hub between the monitored device and its switch port. This will induce minor delay, but will provide multiple interfaces that can be used to monitor the individual switch port.

Typical switch management features

File:Linksys48portswitch.jpg
Linksys 48-port switch.
A rack-mounted switch with network cables

(In order of basic to advanced):

Link aggregation allows you to use multiple ports for the same connection achieving higher data transfer speeds. Creating VLANs can serve security and performance goals by reducing the size of the broadcast domain.

See also

References

  1. ^ Robert J. Kohlhepp (2000-10-02). "The 10 Most Important Products of the Decade". Network Computing. Retrieved 2008-02-25.
  2. ^ Cisco Catalyst 6500 Series Firewall Services Module,Cisco Systems,2007
  3. ^ Switch 8800 Firewall Module,3Com Corporation, 2006
  4. ^ Cisco Catalyst 6500 Series Intrusion Detection System (IDSM-2) Module,Cisco Systems,2007
  5. ^ Getting Started with Check Point FireWall-1,Checkpoint Software Technologies Ltd., n.d.
  6. ^ Morten Jagd Christensen et.al IGMP Snooping
  7. ^ The Ins and Outs of Layer 4+ Switching,NANOG 15, S. Sathaye,January 1999
  8. ^ How worried is too worried? Plus, a Global Crossing Story.,NANOG mailing list archives, S. Gibbard,October 2001
  9. ^ Tech specs for a sample HP "web-managed" switch
  10. ^ Remote Network Monitoring Management Information Base,RFC 2819, S. Waldbusser,May 2000

External links