L3 or L4 Switch and firewall

ppaik

Platinum Member
Nov 11, 2000
2,408
0
76
What does an L3 and L4 switch do? I know that either the L3 or L4 is used as a load balancer, but thats all I know.

I read a technical document today that said if you have an L3 switch with ACL, there is no need for a firewall. So now I have no idea what the difference is. Is an L3 switch actually a firewall?
 

ITJunkie

Platinum Member
Apr 17, 2003
2,512
0
76
www.techange.com
no...a layer 3 switch gives you routing capabilities, such as multiple subnets (vlans) on one switch and being able to forward packets between them. ACL's are access lists...they do act like a firewall in that they can block and allow traffic based on ports, ip addresses and whatnot but I don't think they offer all of the functionality that you might get from a full-service firewall. Such as Intrusion Detection and upper OSI layer inspection(?).
Please feel free to correct weaknesses in the above info, though.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
that's pretty much it. A L3 switch is at it's core just a switch that can route at layer3 via hardwere that detects the traffic flow and from then on that L3 conversation is hardware switched. It may also have other functionality like access control lists, NAT, DHCP and arp inspection for security and VLAN access control lists, private vlans or port based/802.1x security.

But it is not a full featured firewall, mainly because of stateful inspection and deep packet inspection along with a whole slew of other features designed around firewall functionality. That functionality being to securely manage and log traffic flows and detect attacks as traffic flows between interfaces based on L3 - L7 information.

There is also a L7 switch but that is another topic.
 

ppaik

Platinum Member
Nov 11, 2000
2,408
0
76
thanks for the info guys and hi again spidey ^^. I think I got it, cause I used to think L3 switches were basically fancy switches that can have multiple vlans behind it.

Can I just ask what other features a firewall would have that an L3 switch wouldn't be able to do?
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
Statefull inspection
deep packet inspection
redundancy tools wth stateful failover
redirection to virus scubbers/proxies
other security features, too numerous to list - specifically recognizing unusual activity/patterns like IDS/IPS
Software/hardware that is optimized for the task at hand - being a firewall, large NAT/PAT tables, better logging, higher performance
VPNs
SSL VPNs

The list really can go on and on

A switch switches
A firewall, firewalls

They really can't be compared
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |