Network appliances are the building blocks you connect to make a network work. They can be dedicated physical boxes, virtual appliances running on a hypervisor, or cloud services that do the same job. The exam expects you to know what each one does, which OSI layer it mainly operates at, where it sits in the network and when to choose one over another. Most questions describe a need, such as 'block attacks automatically' or 'spread load across servers', and ask which appliance meets it.
A router connects different IP networks and forwards packets between them using a routing table (Layer 3). Every subnet needs a router interface as its default gateway to reach other networks, and routers also separate broadcast domains: a broadcast on one side is not forwarded to the other. A switch connects devices within the same network and forwards frames by learning which MAC address lives on which port (Layer 2). It builds this MAC address table by reading the source address of every incoming frame. Unlike an old hub, which repeated every bit out every port, a switch sends unicast frames only to the correct port, and each switch port is its own collision domain. A Layer 3 or multilayer switch can also route between VLANs at wire speed, which is why it is common in the core of campus networks.
A firewall enforces a security policy by allowing or blocking traffic. A basic stateless packet filter checks addresses and ports in each packet in isolation. A stateful firewall tracks connections in a state table, so return traffic for a session a user started is allowed automatically while unsolicited inbound traffic is dropped. A next-generation firewall (NGFW) adds application awareness (it can tell a video stream from a file upload even on port 443), user identity, TLS inspection and often built-in intrusion prevention. An intrusion detection system (IDS) watches a copy of traffic, for example from a switch port mirror (SPAN) or a network tap, and alerts on suspicious patterns; it does not block. An intrusion prevention system (IPS) sits inline and can drop malicious traffic as it happens. Both use signature detection (known patterns) and anomaly or behaviour detection (deviations from a learned baseline). A host-based version (HIDS or HIPS) runs on an individual computer instead of the network.
A load balancer spreads client requests across a pool of servers to improve performance and availability. Clients connect to one virtual IP address, and the balancer decides which real server gets each request using methods such as round robin, weighted round robin or least connections. It performs health checks so it stops sending traffic to a failed server, and it can terminate TLS so servers do not have to, and keep a user on the same server (session persistence or 'sticky sessions'). A proxy server makes requests on behalf of clients. A forward proxy sits in front of users and can cache content, log activity and filter web access; a reverse proxy sits in front of servers, receives requests from the internet and hides the servers' real addresses. Many load balancers are, in effect, reverse proxies with extra features.
Storage appliances come in two flavours. Network-attached storage (NAS) is a file server: clients access shared folders over the normal network using file protocols such as SMB (Windows) or NFS (Unix and Linux). A storage area network (SAN) provides block-level storage that servers see as local disks; the server formats the volume itself. A SAN usually runs on a dedicated high-speed network using Fibre Channel, or over Ethernet with iSCSI (SCSI commands carried in IP) or Fibre Channel over Ethernet (FCoE). The short version: NAS shares files, SAN shares blocks. Databases and virtual machine storage usually prefer SAN; shared department folders suit NAS.
A wireless LAN controller (WLC) centrally manages many lightweight access points: it pushes configuration, coordinates channels and transmit power, enforces security policy and handles seamless roaming and authentication. Without a controller, each autonomous access point must be configured one by one, which is fine for a small office and painful for a campus. Access points themselves bridge wireless clients onto the wired network. Controllers can be physical boxes, virtual machines or cloud-hosted services.
Common mistakes include thinking an IDS can stop an attack (it only reports), assuming a switch separates broadcast domains (only VLANs or routers do), and confusing forward with reverse proxies. Remember direction: a forward proxy protects and controls clients going out; a reverse proxy protects servers receiving traffic coming in. Also note placement: an IPS or firewall must be inline to block, which means if it fails it can take the link down, so many are deployed with fail-open or high-availability pairs.
On the exam, look for clue words. 'Alert', 'passive', 'monitor', 'span port' point to IDS; 'inline', 'block', 'drop' to IPS. 'Distribute', 'health check', 'virtual IP', 'server pool' mean load balancer. 'Cache web content', 'filter user browsing' mean forward proxy; 'hide internal servers' means reverse proxy. 'Block-level', 'appears as a local disk', 'Fibre Channel', 'iSCSI' mean SAN; 'file share', 'SMB', 'NFS' mean NAS. 'Centrally manage hundreds of APs' means wireless LAN controller.
Key terms
- Stateful firewall
- A firewall that tracks the state of connections and automatically allows return traffic that belongs to an established session.
- NGFW
- Next-generation firewall: a firewall that adds application awareness, user identity, TLS inspection and intrusion prevention to stateful filtering.
- IDS
- Intrusion detection system: a passive device that monitors a copy of traffic and alerts on suspicious activity without blocking it.
- IPS
- Intrusion prevention system: an inline device that detects and blocks malicious traffic in real time.
- Reverse proxy
- A proxy that sits in front of servers, receiving client requests on their behalf and hiding the servers' details.
- SAN
- Storage area network: a dedicated network that gives servers block-level access to shared storage, typically via Fibre Channel or iSCSI.
- Wireless LAN controller
- A device or service that centrally configures and manages lightweight access points, including channels, power, security and roaming.
An online store runs three web servers behind a load balancer that presents a single virtual IP to customers. When one server crashes during a sale, the balancer's health check fails and it quietly sends all customers to the other two, so nobody notices the outage. An NGFW in front of the balancer blocks traffic that does not match policy, and an IDS fed by a SPAN port alerts the security team when someone starts scanning the servers. Product images and order data live on a SAN, which the database servers mount as local disks.
Check yourself
A company wants a device that drops attack traffic automatically but worries about it becoming a single point of failure. What should it deploy and what design concern applies?
An IPS, because it sits inline and can block. Because it is inline, a failure can cut the link, so it should be deployed in a high-availability pair or with a fail-open setting.
A switch has 24 ports and no VLANs. How many collision domains and broadcast domains does it create?
24 collision domains (one per port) and one broadcast domain, because switches do not stop broadcasts unless VLANs are configured.
Staff should be blocked from gambling sites and frequently used pages should load faster. Which appliance fits, and is it a forward or reverse proxy?
A forward proxy, because it sits in front of users, caches content and filters outbound web requests.
A hypervisor cluster needs shared storage it can format with its own file system. NAS or SAN, and why?
SAN, because it presents raw block storage that the host sees as a local disk; NAS only shares files through SMB or NFS.