What a network switch does

A network switch is a device that connects computers, servers, and other equipment inside a data center so they can talk to each other. Think of it like a telephone switchboard — when one device sends data to another, the switch reads the destination address and forwards the data to the right port. Without switches, every device would have to connect directly to every other device, which would be chaotic and wasteful.

Switches operate at what's called Layer 2 or Layer 3 of network architecture. Layer 2 switches forward data based on MAC addresses (the physical hardware identifier of a device). Layer 3 switches, also called routers, forward data based on IP addresses (the logical network address). Most data centers use both types working together — Layer 2 switches handle traffic within the same network segment, and Layer 3 switches route traffic between different segments or to the outside world.

A single switch can have anywhere from 24 to 128 ports, depending on its size and purpose. Each port connects to a device or to another switch. When data arrives at one port, the switch examines it, looks up where it needs to go, and sends it out the correct port at wire speed — meaning there's almost no delay.

Key Takeaways

  • A network switch forwards data between devices inside a data center by reading destination addresses and sending packets to the correct physical port.
  • Layer 2 switches use MAC addresses to forward data within a local network, while Layer 3 switches use IP addresses to route data between different networks.
  • Switches come in different sizes and speeds, measured in gigabits per second (Gbps), and data centers typically use multiple switches arranged in a hierarchy.
  • Redundancy and failover are built into data center switch design so that if one switch fails, traffic automatically reroutes through another.

How switches are arranged in a data center

Data centers don't use just one switch. Instead, switches are stacked in layers, forming what's called a network topology. The most common arrangement is a three-tier model: access switches at the bottom connect directly to servers, aggregation switches in the middle collect traffic from access switches, and core switches at the top connect the aggregation layer to the outside world and to other data centers.

This layered design serves two purposes. First, it scales — you can add more servers by plugging them into access switches without rebuilding the whole network. Second, it provides redundancy. If one access switch fails, servers connected to it can reroute through a neighboring access switch. If an aggregation switch fails, traffic can flow through another aggregation switch. This redundancy is critical because data center downtime is expensive.

Switches also connect to each other using multiple links, not just one. A server might connect to two different access switches, and an access switch might connect to two different aggregation switches. This is called link aggregation or bonding, and it both increases speed and provides a backup path if one link fails.

Speed and port density

Switches are rated by how fast data moves through them, measured in gigabits per second (Gbps). Common speeds in modern data centers are 10 Gbps, 25 Gbps, 40 Gbps, 100 Gbps, and 400 Gbps. A faster switch can move more data in the same amount of time, which matters when thousands of servers are sending data simultaneously.

Port density refers to how many ports a switch has. A 48-port switch has 48 connections. A 128-port switch has 128. Higher port density means fewer switches are needed to connect the same number of devices, which saves space and power. However, higher density switches are more expensive and generate more heat, so data centers balance density against cost and cooling capacity.

The total throughput of a switch — how much data it can handle at once across all ports — is separate from the speed of individual ports. A switch with 48 ports running at 10 Gbps each has a total throughput of 480 Gbps, but only if the switch's internal fabric (the part that moves data between ports) can actually handle that much. Cheaper switches sometimes have a bottleneck in the fabric, meaning they can't use all ports at full speed simultaneously.

Managed versus unmanaged switches

Managed switches allow a network administrator to configure them — setting up which devices can talk to each other, monitoring traffic, creating separate virtual networks, and setting priorities for certain types of data. Managed switches have a web interface or command-line interface where you log in and make changes. They're more complex but give you control over how data flows.

Unmanaged switches straightforward forward data without any configuration. Plug in a cable and it works. They're cheaper and simpler but offer no control or visibility. Data centers almost never use unmanaged switches because they need to monitor traffic, troubleshoot problems, and enforce security policies.

Most data center switches are managed. They support features like VLAN (virtual LAN), which lets you create separate logical networks on the same physical switch; port mirroring, which copies traffic from one port to another so you can analyze it; and QoS (Quality of Service), which prioritizes certain types of traffic over others.

Power consumption and cooling

Large switches consume significant power. A 128-port switch running at 100 Gbps per port can draw 5,000 watts or more. In a data center with hundreds of switches, that adds up quickly. Power consumption affects both the electricity bill and the cooling load — every watt of power becomes heat that must be removed from the room.

Data centers are designed with this in mind. Switches are placed in racks with proper airflow, and the data center's cooling system is sized to handle the heat they generate. Some data centers use hot-aisle and cold-aisle layouts, where switches are arranged so that hot air exhausts in one direction and cold air flows in from the other. Others use in-row cooling units or liquid cooling for the most power-dense equipment.

Failover and redundancy

If a switch fails, data center operators want traffic to keep flowing. This is achieved through redundancy — having backup switches and backup connections so that if one path fails, another takes over automatically. Most data centers use spanning tree protocol (STP) or a newer protocol like TRILL or fabric path to manage this.

These protocols work by having switches communicate with each other about which paths are available. If a link goes down, the protocol detects it within seconds and reroutes traffic through a working link. The reroute happens automatically — servers and applications don't need to know about it. From the user's perspective, the connection might pause for a moment, but it doesn't drop.

Some data centers also use active-active configurations, where two switches handle traffic at the same time instead of one being a standby. This uses bandwidth more efficiently and means no capacity is wasted on a backup that's just sitting idle.

Switches versus routers

The terms "switch" and "router" are sometimes used interchangeably, but they do different jobs. A switch connects devices on the same local network and forwards data based on MAC addresses. A router connects different networks and forwards data based on IP addresses. In practice, modern network equipment often does both — a Layer 3 switch has switching capability and routing capability built in.

In a data center, you'll see both. Access and aggregation switches are primarily Layer 2 switches. Core switches and the equipment that connects to the internet are primarily routers or Layer 3 switches. The boundary between them is blurry in modern networks, but the distinction still matters for understanding how data moves.

Frequently Asked Questions

What happens if a switch port fails?

If a single port fails, the device plugged into that port loses connection. However, if the device is connected to two different switches (which is common in data centers), it automatically switches to the other connection. The data center's redundancy design means a single port failure rarely causes downtime for the whole system.

Can you add more ports to a switch?

No, a switch has a fixed number of ports. If you need more connections, you add another switch and connect it to the existing network. This is why data centers use multiple switches arranged in layers — it's easier to add a new switch than to replace an existing one with a larger model.

How do switches know where to send data?

Switches learn by watching traffic. When a device sends data out a port, the switch notes which device is on that port. When data arrives destined for that device, the switch sends it back out the same port. If the switch doesn't know where a destination is, it floods the data out all ports except the one it came in on, and the destination device responds, teaching the switch where it is.

Do all ports on a switch run at the same speed?

Usually yes, but not always. Some switches have a mix of port speeds — for example, 48 ports at 10 Gbps and 4 ports at 100 Gbps. The faster ports are typically used to connect to other switches or to high-traffic servers, while slower ports connect to regular servers or storage devices.

What's the difference between a switch and a patch panel?

A patch panel is just a collection of ports where cables plug in — it doesn't do anything with the data. A switch actively reads data, makes decisions about where to send it, and forwards it. A data center might use a patch panel to organize cables, but the actual networking work is done by switches.