Layer 2 Switch
Image: Simon A. Eugster, CC BY-SA 3.0, Wikimedia Commons
In short: A classic switch that works exclusively at layer 2 of the OSI model and forwards packets based on MAC addresses.
In more detail: It knows no IP addresses and can’t route between different networks — in return it’s fast and cheap for pure switching within a local network or VLAN. Communication between different networks requires a router or a layer 3 switch.
In Depth
A layer 2 switch works exclusively with the information in the Ethernet header of a frame — above all the source and destination MAC addresses. It keeps an internal, learning MAC address table: if it sees a frame from a particular MAC address on port 3, it remembers “this address is on port 3”, and in future forwards frames to this address specifically only there, instead of flooding them to all ports (like a hub).
Frame arrives on port 1, destination MAC AA:BB:CC:11:22:33
└── Switch looks in its MAC table: AA:BB:CC:11:22:33 = port 5
└── Frame is forwarded ONLY to port 5
The decisive limitation: a pure layer 2 switch knows no IP addresses and therefore can’t switch between different networks (different subnets) — it works entirely within a single broadcast domain or a single VLAN. For communication ACROSS network boundaries, a device working at layer 3 is strictly required — either a dedicated router or a layer 3 switch, which integrates routing functionality directly into the switch hardware.
In practice, layer 2 switches today are usually the cheaper, simpler devices at the “edge” of a network (access layer, where end devices are connected directly), while layer 3 switches sit at the core of a larger network, where routing across VLANs is needed.
See also: Layer 3 switch, Switch