Router

A layer 3 device that forwards packets between separate networks by destination IP address, using a routing table, and separates broadcast domains.

A router connects separate networks and forwards packets between them at the network layer of the OSI model. It reads each packet’s destination IP address, finds the best matching route in its routing table, and sends the packet toward the next hop. Routes are set by hand or learned through protocols such as Border Gateway Protocol between organisations. Routers do not forward broadcasts by default, so each interface bounds a broadcast domain.

The usual confusion is with a network switch. A switch moves frames by MAC address within one network at layer 2; a router moves packets between networks at layer 3. Traffic between two VLANs is designed to pass through a layer 3 device, a router or a layer 3 switch, which makes that device a natural place for policy. Router access control lists give the stateless filtering of a packet-filtering firewall but not the connection tracking of a stateful one. False routes can redirect traffic, and a router’s management interfaces need the same protection as any administrative system.

Exam relevance: questions in this area tend to describe a device by what it reads. Forwarding by IP address between networks points to a router; forwarding by MAC address within one network points to a switch. Candidates are expected to know that router access lists are not a full firewall.