Skip to content

300,000+ products in stockAI infrastructure + enterprise IT hardware. Genuine product, full manufacturer warranty.

Networking hardware: Layer 2 vs Layer 3 Switch: Do You Need Routing on the Switch?
Networking
Back to Resources
Networking 7 min read 25 September 2026

Layer 2 vs Layer 3 Switch: Do You Need Routing on the Switch?

A Layer 2 switch forwards traffic inside a VLAN by MAC address. A Layer 3 switch also routes between VLANs, which most multi-VLAN networks need.

Layer 2 or Layer 3 is the first line on almost every switch spec sheet, and it is often misread. The short version: a Layer 2 switch moves traffic between devices on the same network segment, and a Layer 3 switch can also route traffic between segments. If your network has more than one VLAN, something has to route between them. The design question is whether that job belongs on the switch, on a router, or on a firewall. This guide answers the three questions buyers ask most and shows where each class of switch fits.

What is the difference between a Layer 2 and Layer 3 switch?

The layers refer to the OSI model. Layer 2 is the data link layer, where Ethernet frames are addressed by MAC address. A Layer 2 switch learns which MAC addresses sit behind which port and forwards frames accordingly. It understands VLANs, 802.1Q trunks, link aggregation and spanning tree, but it does not use IP addresses to make forwarding decisions. Every device in a VLAN shares one broadcast domain, and traffic bound for another VLAN has to leave the switch for something that routes.

Layer 3 is the network layer, where packets are addressed by IP. A Layer 3 switch keeps a routing table as well as a MAC table. You give each VLAN a routed interface (usually called an SVI, or switched virtual interface) that acts as the default gateway for hosts in that VLAN, and the switch routes between them in its forwarding ASIC rather than in software. Depending on the model and license, it can also run static routes, OSPF, BGP and first-hop redundancy protocols such as VRRP.

  • Forwarding decision: Layer 2 uses MAC addresses only. Layer 3 uses MAC addresses within a VLAN and IP routes between VLANs.
  • Traffic between VLANs: a Layer 2 switch sends it to an external router or firewall. A Layer 3 switch routes it locally.
  • Broadcast domains: Layer 2 designs tend toward large, flat VLANs stretched across many switches. Layer 3 lets you keep VLANs small and route between them.
  • Redundant links: Layer 2 relies on spanning tree, which blocks redundant paths. Routed Layer 3 uplinks can load-share across equal-cost paths (ECMP).
  • Typical placement: Layer 2 at the access edge of small or simple networks. Layer 3 at distribution and core, and increasingly at the access layer and the data center top of rack.

Between the two sits a class of switches sold as Layer 2/3, Layer 2+ or 'lite Layer 3'. These usually support static routes and routing between locally connected VLANs, but have limited or no dynamic routing, smaller route tables and fewer routed interfaces. For a branch office that needs a handful of VLANs routed locally, that is often enough. The Fortinet FortiSwitch FS-424E, for example, is listed as a Layer 2/3 managed access switch and is designed to be managed from a FortiGate over FortiLink, so the firewall stays the policy point. Read the routing section of any datasheet rather than the headline: the words 'Layer 3' cover everything from static routes only to full BGP.

Do I need a Layer 3 switch?

You need Layer 3 somewhere as soon as you have more than one VLAN. Whether it belongs on the switch comes down to how much traffic crosses VLAN boundaries and where you want security policy enforced. These are the signs that routing should move onto the switch:

  • You run several VLANs (users, voice, cameras, servers, management) and a large share of traffic moves between them, for example users reaching internal servers, or hosts reaching storage on a different subnet.
  • Your router or firewall is the default gateway for every VLAN, and inter-VLAN traffic is loading its interfaces or its CPU.
  • You want to stop stretching VLANs across the building or the data center, and replace spanning-tree-blocked links with routed uplinks that use every path.
  • You are building a leaf-spine data center fabric, where routing at the top of rack is the standard design.
  • You need gateway redundancy with VRRP or a vendor equivalent, so hosts keep a working default gateway if one switch fails.

Layer 2 is still enough for a small, single-VLAN office, or for access switches in a design where a distribution or core switch does all the routing. In practice most managed business switches are Layer 3 capable anyway, and many teams buy Layer 3 access switches and run them at Layer 2 until the design needs more. That keeps the option open without a hardware swap later.

Can a Layer 3 switch replace a router?

Inside the LAN, yes: routing between VLANs, and between switches with OSPF or BGP, is exactly what Layer 3 switches are built for, in switching silicon at high port density. At the internet or WAN edge, usually not. Edge devices do jobs that switches either do not do or do not do well: network address translation, stateful firewalling, site-to-site and remote-access VPN, deep packet inspection, WAN interface types, traffic shaping, and holding large routing tables learned from service providers. Switch route tables are sized for a campus or data center, not for full internet routing. The usual pattern is a firewall or router at the edge, with a Layer 3 core switch behind it handling all internal routing. Our enterprise firewall buying guide covers the edge side of that design.

Which Layer 3 switches fit the campus access layer and core?

  • Access: the Cisco Catalyst C9200-24T (24 x 1GbE, 128 Gbps switching capacity, fixed or modular 1/10G uplinks) and the Catalyst C9300-24T (24 x 1GbE, 208 Gbps, modular 1/10/25/40G uplinks), both stackable and running Cisco IOS XE. The C9300 is the step up when you want modular, higher-speed uplinks.
  • Access on other platforms: the HPE Aruba CX 6300M JL661A (24 x 1GbE, 4 x 50GbE SFP56 uplinks, AOS-CX) and the Juniper EX4400-24T (24 x 1GbE, 480 Gbps, Junos OS with Mist AI cloud management). Standardize on the platform your team already operates.
  • Small office or lab: the Ubiquiti UniFi USW-Pro-24-PoE (24 x 1GbE PoE+ plus 2 x 10G SFP+, 88 Gbps) and the NETGEAR M4300-12X12F (12 x 10GBase-T plus 12 x 10G SFP+, 480 Gbps) bring Layer 3 to smaller networks.
  • Core and aggregation: the Catalyst C9500-24Y4C (24 x 25GbE SFP28 plus 4 x 100GbE QSFP28, 2.0 Tbps) aggregates access stacks and does the heavy inter-VLAN routing. See the Layer 3 core and aggregation category.

What about Layer 3 in the data center?

Modern data center networks route almost everything. In a leaf-spine fabric each top-of-rack leaf is a Layer 3 switch, the uplinks to the spines are routed, and ECMP spreads traffic across every spine; where workloads need Layer 2 adjacency across racks, VXLAN with an EVPN control plane carries it over the routed underlay (our leaf-spine topology guide goes deeper). Typical 1U leaves are the Cisco Nexus N9K-C93180YC-FX (48 x 25GbE SFP28 plus 6 x 100GbE QSFP28, 3.6 Tbps, NX-OS and ACI-ready), the Arista 7050SX3-48YC8 (48 x 25GbE SFP28 plus 8 x 100GbE QSFP28, 4.0 Tbps, EOS with CloudVision) and the Dell PowerSwitch S5248F-ON (48 x 25GbE SFP28 plus 4 x 100GbE QSFP28, 4.0 Tbps, SmartFabric OS10 with ONIE), all on the Layer 3 data center switch page. The choice between them comes down to which network operating system and automation tooling your team runs, and how many 100G uplinks the spine design needs.

What should you check before buying a Layer 3 switch?

  • Which routing features are included in the software license you are buying. Some platforms put dynamic routing protocols, VXLAN or higher scale behind a higher license tier.
  • Route table and routed interface scale against your design, including future VLANs and sites.
  • Uplink speed and type (SFP+, SFP28, SFP56 or QSFP28) and the optics or DAC cables to match the far end.
  • Stacking at the access layer, or routed uplinks with first-hop redundancy, depending on how you want to handle a switch failure.
  • PoE budget, if the access switch powers phones, access points or cameras.
  • Airflow direction (front-to-back or port-side exhaust) to match hot and cold aisles in the rack.
  • The management model: CLI, a controller such as Cisco DNA Center, or a cloud dashboard.
Every multi-VLAN network needs Layer 3 somewhere. Put it on the switch for traffic that stays inside your network, and keep the router or firewall for traffic that leaves it.

Nexus Compute supplies new switches from Cisco, Arista, Juniper, HPE Aruba, Dell, Fortinet, Ubiquiti and NETGEAR through authorized distribution, with the full manufacturer warranty. Send us your VLAN count, uplink speeds and the platform you run today, and we will check the switch, license tier and optics against your design and quote within 48 business hours.

Frequently asked questions

What is the difference between a Layer 2 and Layer 3 switch?

A Layer 2 switch forwards Ethernet frames by MAC address inside a VLAN. A Layer 3 switch also routes IP packets between VLANs and subnets, using routed interfaces as the default gateways. Both forward in hardware; only the Layer 3 switch makes forwarding decisions based on IP addresses.

Do I need a Layer 3 switch?

If you run more than one VLAN and a meaningful share of traffic crosses between them, routing on a Layer 3 switch is usually the right design. A single-VLAN office, or an access layer behind a routing core, can run on Layer 2. Many teams still buy Layer 3 capable access switches so the option is there later.

Can a Layer 3 switch replace a router?

For routing inside your LAN or data center, yes. At the internet or WAN edge, generally no, because switches typically lack NAT, stateful firewalling, VPN and the route table size an edge router or firewall provides. Most designs keep a firewall at the edge and a Layer 3 core switch behind it.

Can I run a Layer 3 switch as a Layer 2 switch?

Yes. A Layer 3 switch forwards at Layer 2 within each VLAN, and routing only happens once you configure routed interfaces. Many access switches are deployed this way, with routing handled at the distribution or core layer.

What does Layer 2/3 mean on a switch?

It usually means the switch supports some Layer 3 features, typically static routes and routing between local VLANs, without the full dynamic routing and scale of a core or data center switch. Check the datasheet for the supported protocols and route table size.

Which Layer 3 switch should I buy for a data center leaf?

For 25GbE server access with 100GbE uplinks, a 1U leaf such as the Cisco Nexus N9K-C93180YC-FX (48 x 25GbE plus 6 x 100GbE) or the Arista 7050SX3-48YC8 (48 x 25GbE plus 8 x 100GbE) is the typical fit. Pick the one whose operating system and automation tooling your team already runs.

Systems covered in this article

Planning a hardware investment?

Tell us what you're trying to build. A procurement specialist will help you specify and quote the right configuration within 48 business hours, no obligation.

layer 2 vs layer 3 switchdo I need a layer 3 switchlayer 3 switch vs routerinter-VLAN routing switchlayer 3 data center switchCisco Catalyst C9300-24TCisco Nexus N9K-C93180YC-FXCatalyst C9500-24Y4C