Common Types of Network Devices and Their Functions
Sep 5, 2026
Network devices, including routers, switches, firewalls, and more, form the infrastructure that determines how data moves through a network and where security controls apply. Each type carries its own function and risk, from repeaters and switches that move traffic to firewalls and IDPS appliances that defend it. Getting the OSI layer and security implications of each device right is the foundation for a defensible network.
The modern enterprise network is a collection of dozens of physical and virtual devices, each handling a specific job. Routers direct traffic between networks. Switches connect devices within them. Firewalls decide what gets through and what doesn't. Intrusion prevention systems watch for threats in real time.
Every one of those devices is also a potential target: 28% of organizations experienced a targeted attack on their on-premises infrastructure in 2025, according to the Netwrix Cybersecurity Trends Report 2025.
Network devices manage traffic flow, direct data packets, enforce security policies, and enable connectivity between network segments or the internet. Understanding what each device does and where it can be exploited is foundational for any IT or security team managing a modern environment.
What follows covers the most common types of network devices, how they're classified, and the security implications that matter for each.
What is a network device?
A network device is a hardware or software component essential for communication between computers and other connected systems. These devices manage traffic flow, direct data packets, provide security, and enable connectivity between network segments or the internet. Each device serves a specific purpose, enabling information to flow within an organization's IT ecosystem.
Common network devices include routers, switches, firewalls, hubs, modems, and wireless access points. Some devices, such as switches and routers, move data. Others, like firewalls and intrusion detection systems, control which traffic is permitted and flag traffic that appears malicious. Most modern networks rely on both categories working in coordination.
Why network devices matter
Network devices aren't just the plumbing of your IT environment. They're the infrastructure that determines your security posture, your exposure to attack, and how far damage can spread when something goes wrong.
They define your attack surface
Every internet-facing or misconfigured network device represents a potential entry point for attackers. Open ports on a router, an overly permissive firewall rule, or a wireless access point with default credentials are all gaps in your perimeter. The Netwrix Cybersecurity Trends Report 2025 also found that 51% of organizations experienced a security incident in the past 12 months serious enough to require a dedicated response from their security team, and perimeter-facing network devices are frequently where that response begins.
They enable or prevent lateral movement
Once an attacker gains a foothold inside a network, they move laterally, jumping from device to device to reach sensitive systems. Properly segmented networks, enforced through managed switches and firewalls, limit how far that movement can go. An attacker who compromises a workstation in a flat network can reach every server in the environment, but an attacker in a properly segmented network hits a boundary. Understanding lateral movement and how network devices either enable or constrain it is central to network security design.
They're a primary target for external threat actors
Network devices run software, and that software has vulnerabilities. Cisco, Fortinet, Ivanti, and Palo Alto Networks all released critical device-level CVEs in 2024 and 2025. Attackers often exploit these before patches are applied, and in many organizations, firmware update cycles lag far behind the threat. Knowing which devices you're running and which CVEs apply to them is a core part of maintaining your security posture.
Types of network devices
Understanding the different types of network devices helps you optimize and secure your organization's network infrastructure. The table below maps each device to its OSI layer and primary function, followed by a detailed breakdown of each type.
Network Device | OSI Layer | Primary Function |
|---|---|---|
|
Repeater |
Layer 1 (Physical) |
Amplifies and retransmits signals to extend range |
|
Hub |
Layer 1 (Physical) |
Broadcasts signals to all connected ports |
|
Bridge |
Layer 2 (Data Link) |
Connects and filters traffic between network segments |
|
Switch |
Layer 2 to 3 (Data Link/Network) |
Directs data to specific ports using MAC/IP addresses |
|
Router |
Layer 3 (Network) |
Routes data packets between different networks |
|
Gateway |
Layers 4 to 7 (Transport to Application) |
Translates data between different network protocols |
|
Network Interface Card (NIC) |
Layers 1 to 2 (Physical/Data Link) |
Connects a device to a network |
|
Modem |
Layer 1 (Physical) |
Converts digital data for transmission over analog media |
|
Firewall |
Layers 3 to 7 |
Monitors and filters traffic based on security rules |
|
Wireless Access Point (WAP) |
Layers 1 to 2 |
Connects wireless devices to a wired network |
|
IDPS |
Layers 3 to 7 |
Detects and prevents network intrusions |
|
VPN Appliance |
Layers 3 to 7 |
Creates encrypted tunnels for secure remote access |
Repeater
A digital signal degrades over distance, a process called attenuation. A repeater, operating at the physical layer (Layer 1) of the OSI model, regenerates the signal so it can travel further without loss. Dedicated repeaters are rare in modern networks, since switches and routers handle this function as part of their standard operation. You'll still find them in industrial environments and long-range wireless setups where you need signal extension without adding routing complexity.
From a security standpoint, repeaters don't offer traffic inspection or filtering. They amplify everything, including malicious traffic. If a repeater sits in your network path, it adds no protection to what passes through it.
Hub
A network hub connects multiple Ethernet devices into a single network segment. There are three types:
- Passive hub: Connects devices without amplification and requires no power source.
- Active hub: Amplifies incoming signals before retransmitting them and requires external power, effectively acting as a repeater.
- Intelligent hub: Adds basic network management, monitoring, and diagnostic capabilities.
Hubs are deprecated. The IEEE 802.3 standard formally deprecated hubs in 2011, and managed switches have replaced them in virtually all modern networks. The reason is straightforward: a hub broadcasts incoming data to every connected port regardless of the intended destination. Any device on that hub can intercept all traffic, making packet capture trivial. If your network still uses hubs, replacing them with managed switches should be a priority.
Bridge
A network bridge connects two or more network segments and filters traffic between them. While a hub broadcasts to all connected devices, a bridge examines the source MAC address of incoming frames and makes forwarding decisions based on a MAC address table it maintains, reducing unnecessary traffic and improving network performance. There are two types:
- Transparent bridge: Automatically builds and maintains a MAC address table by examining the source addresses of incoming frames. The standard type in use today.
- Source bridge: Relies on a different forwarding approach, common with token ring networks that are now effectively obsolete.
Wireless bridging, connecting two network segments via a wireless link, is the most common modern use case for dedicated bridge devices. In most modern environments, managed switches handle bridging as part of their core operation.
Switch
A switch is one of the most important devices in any network. It connects multiple devices on a LAN and directs incoming data to the destination port, rather than broadcasting to all ports like a hub. Switches come in several types, distinguished by management capability, OSI layer, and form factor:
- Unmanaged: Plug-and-play devices with fixed configuration. No remote access, no monitoring. Suitable only for small or home networks.
- Managed: Fully configurable via web interface, CLI, or SNMP. Supports VLANs, port security, 802.1X authentication, and traffic monitoring.
- Smart: A middle ground between unmanaged and fully managed, offering basic web-based management features.
- Layer 2: Operates at the data link layer and forwards traffic within a LAN using MAC addresses, reducing collisions by segmenting traffic into separate collision domains.
- Layer 3: Combines switching and routing, enabling traffic routing between VLANs and subnets using IP addresses.
- PoE (Power over Ethernet): Delivers data and power over a single Ethernet cable, commonly used for cameras, VoIP phones, and wireless access points.
- Gigabit: Supports data transfer rates of 1 Gbps or greater.
- Rack-mounted: Built to fit a standard 19-inch server rack, common in data centers and server rooms.
- Desktop: Compact switches suited for small offices or home environments.
- Modular: Support add-on modules or expansion cards for future scalability.
Managed switches, including their Layer 2, Layer 3, and PoE variants, are the foundation of network segmentation. By creating separate VLANs for different user groups, servers, IoT devices, and guests, you limit how far an attacker can move if they compromise a single endpoint. Port security controls which MAC addresses can connect to each port, and 802.1X requires device authentication before granting network access.
Router
A router's primary task is directing traffic between networks. Routers transfer data packets to their destinations by tracing paths through interconnected devices using IP addresses. They maintain routing tables that map destination networks to the best available path and update them automatically when using dynamic routing protocols such as OSPF, RIP, or BGP. There are two routing modes:
- Static routers: Use manually configured routes. Reliable and predictable. Ideal for small, stable networks.
- Dynamic routers: Automatically communicate with other routers to update routing tables in real time. Support failover and load balancing across complex, large-scale networks.
Modern routers increasingly bundle additional capabilities, including firewall functionality, VPN endpoints, and, in enterprise environments, SD-WAN support. From a security perspective, routers are a primary external target. Default credentials, overly permissive access control lists (ACLs), and unpatched firmware are the most commonly exploited paths. Routers also divide networks into subnets, making them central to any segmentation strategy.
Gateway
A gateway connects networks that use different protocols or architectures and translates between them. While a router connects networks using the same protocol (IP), a gateway enables communication between fundamentally different systems. A LAN connecting to the internet through an ISP is a classic example: the gateway translates between your internal network and the broader internet infrastructure.
Gateways typically operate at the transport and session layers (Layers 4 and 5), though application-layer gateways, including web application gateways and API gateways, operate at Layer 7. Most modern home and SMB routers combine routing and gateway functions in a single device. In enterprise environments, gateways increasingly appear as cloud-delivered services, particularly for hybrid and multi-cloud connectivity.
Network interface card (NIC)
A network interface card (NIC), also called an Ethernet card or network adapter, connects a device to a network and manages data transmission and reception. Every networked device, including servers, workstations, printers, and access points, contains a NIC, either as a physical expansion card or as a component integrated directly into the motherboard. Common NIC types include:
- Wired Ethernet: Uses RJ45 connectors for a physical cable connection.
- Wireless: Connects over Wi-Fi using an integrated or external antenna.
- Fiber optic: Uses optical connectors for high-speed, long-distance connections.
NICs identify themselves on the network using a unique MAC (Media Access Control) address. From a security standpoint, NIC firmware attacks are an emerging concern. Attackers who compromise NIC firmware can persist below the operating system level, surviving reboots and even OS reinstallation.
Modem
A modem (short for modulator-demodulator) converts digital data from your network into a format suitable for transmission over analog media, such as telephone lines, cable systems, or cellular networks, and converts incoming signals back into digital data. It's the point where your internal network connects to your internet service provider (ISP). There are four main types:
- DSL modem: Uses telephone lines. The slowest of the common modem types.
- Cable modem: Transmits data over TV infrastructure, faster than DSL.
- Wireless modem: Connects devices using nearby Wi-Fi signals.
- Cellular modem: Connects to the internet via a cellular network rather than Wi-Fi or a landline.
In many modern deployments, fiber-connected buildings use an optical network terminal (ONT) instead of a traditional modem. Consumer-grade modems with default credentials are a persistent and frequently exploited attack vector.
Changing default usernames and passwords, disabling remote management where it isn't needed, and keeping firmware up to date are the minimum security steps for any modem in a production environment.
Network security devices
Connectivity devices move data. Security devices control it. The devices in this section form the active defense layer of your network: monitoring traffic, enforcing policy, detecting threats, and protecting remote access. In any environment handling sensitive data, these devices determine whether an attack succeeds or is stopped.
Firewall
A firewall monitors and controls incoming and outgoing network traffic based on predefined security rules, establishing a barrier between trusted internal networks and untrusted external ones. It connects multiple zones, including LAN, WAN, and DMZ, and applies security policies to traffic moving between them. Firewalls have evolved through three generations:
- Packet filtering: Examines individual packets by IP address, port number, and protocol. Fast but stateless. It can't track whether a packet belongs to a legitimate ongoing connection.
- Stateful inspection: Tracks the state of active connections, distinguishing legitimate return traffic from unsolicited inbound packets.
- Next-Generation Firewall (NGFW): Goes beyond traffic filtering to include deep packet inspection, integrated intrusion prevention, application awareness, and AI-assisted threat detection. NGFWs identify applications by behavior rather than port number, which matters when attackers use common ports to mask malicious traffic.
Firewalls can also be deployed as cloud-delivered services (Firewall-as-a-Service), a model that is increasingly common in distributed environments. Misconfigured firewalls, including overly permissive rules, unused ports left open, and management interfaces exposed to the internet, are among the most common causes of data exposure.
Wireless access point (WAP)
A wireless access point (WAP) provides a connection point between wireless devices and a wired network using a built-in antenna and transmitter. WAPs come in three main deployment models:
- Autonomous (standalone): Each WAP is configured and managed independently. Suitable for small networks with a limited number of access points.
- Controller-based: A central wireless LAN controller manages multiple WAPs, enabling centralized policy, roaming support, and unified monitoring. Standard for enterprise environments.
- Cloud-managed: Configuration and monitoring happen through a cloud platform. Well suited for distributed organizations managing access points across multiple sites.
WAPs carry significant security implications. The primary risks are default SSIDs and passwords left unchanged, weak encryption (WPA2 vs. WPA3), and rogue access points set up by employees or attackers.
Enterprise WAPs support 802.1X authentication, requiring connecting devices to authenticate against a RADIUS server before gaining access. Consumer-grade WAPs rarely support this, making them unsuitable for environments that handle sensitive data.
Intrusion detection and prevention system (IDPS)
An intrusion detection and prevention system (IDPS) monitors network traffic for suspicious activity, detects potential threats, and takes action to block or contain them.
The two components work together: the intrusion detection system (IDS) identifies and alerts on suspicious traffic, while the intrusion prevention system (IPS) actively drops malicious packets or terminates sessions before damage occurs. Modern IDPS solutions rely on two detection methods:
- Signature-based detection: Matches traffic against a database of known attack patterns.
- Behavioral analytics: Flags traffic that deviates from established baselines, often using AI to catch threats signatures miss.
IDPS functionality is commonly integrated into NGFWs and Unified Threat Management (UTM) appliances, providing a consolidated view of threats across the network. Integration with a SIEM platform lets IDPS alerts feed into centralized logging and incident-response workflows, and continuous monitoring of network devices makes that response cycle effective.
VPN appliances
A VPN appliance creates an encrypted tunnel over a public network, allowing remote users or branch offices to securely connect to a corporate network. The connection consists of a VPN server, often a dedicated appliance or a firewall with VPN capabilities, and a VPN client application on the connecting device. VPN appliances support two primary deployment models:
- Remote access VPN: Allows individual users to connect securely from outside the network. The standard model for remote workers.
- Site-to-site VPN: Connects entire networks, for example, linking a branch office to headquarters over an encrypted tunnel.
VPN firmware vulnerabilities have become one of the most exploited attack categories in recent years. Attackers actively exploit critical CVEs in Ivanti, Pulse Secure, Cisco, and Palo Alto Networks VPN products, often within days of disclosure. Keeping VPN firmware up to date and monitoring authentication logs for anomalous access attempts are non-negotiable practices.
For remote access security in environments moving toward Zero Trust, Zero Trust Network Access (ZTNA) is the emerging successor. While VPN grants broad network access after authentication, ZTNA grants access only to the specific resources a user is authorized to access, significantly reducing the blast radius of a compromised account.
Common challenges in network device management
Modern networks comprise dozens or hundreds of interconnected devices, and several factors can undermine their security. The challenges below aren't hardware failures or ventilation problems. They're the security-relevant gaps that enable real-world attacks.
Configuration drift and misconfigurations
Network devices ship with default configurations that prioritize ease of setup over security. Default credentials, open management interfaces, and overly permissive firewall rules are common starting points, and if teams don't actively harden devices before deployment, those settings often remain in place. Over time, incremental changes accumulate across devices, and your network's actual state diverges from any documented baseline. This is configuration drift.
A single misconfigured firewall rule can expose internal systems to the internet. A switch with default credentials gives an attacker administrative control over your network segmentation. Leaving service protocols like SMB accessible across network segments further extends that exposure. Continuous monitoring and automated configuration auditing are the most effective defenses. You can't correct what you can't detect.
Outdated firmware and unpatched vulnerabilities
Network device firmware contains vulnerabilities, and attackers closely track CVE disclosures. The gap between when a vulnerability is published and when organizations apply the patch is an active window for exploitation. VPN appliances, routers, and firewalls are among the most targeted device categories for firmware exploitation. Many significant network breaches in 2024 and 2025 began with an unpatched perimeter device.
The Netwrix Cybersecurity Trends Report 2025 found that 54% of insured organizations must maintain patch management controls as a condition of coverage. Establishing a firmware update cadence, tracking CVEs for every device model in your environment, and applying the same patching discipline to network devices as to servers and endpoints significantly reduces your exposure.
Unauthorized access and privilege misuse
Network devices are administered via privileged accounts, which are high-value targets. Shared admin credentials, accounts that are never rotated, and management interfaces accessible from the broader network all increase the risk of unauthorized access. An attacker who gains administrative access to a core switch or router can reconfigure network segmentation, intercept traffic, or disable security controls outright.
The same principles that apply to user accounts apply to device management: least privilege, no shared credentials, and MFA on all management interfaces. TACACS+ and RADIUS provide centralized authentication for network device administration, ensuring every management session is logged and tied to an individual account. Unauthorized privilege use on network devices is one of the primary paths that enable lateral movement within an environment.
Best practices for network device security
Understanding the different types of network devices is the foundation. Securing them determines whether your network holds up under real-world attack. The following practices apply across device types and form the baseline for any defensible network infrastructure.
Harden all device configurations before deployment
Default configurations on network devices prioritize ease of use over security. Before any device goes into production, change default credentials, disable unused services and ports, and switch management protocols from insecure options (Telnet, HTTP) to encrypted ones (SSH, HTTPS). Apply CIS Benchmark hardening guidelines for the specific device model. Most major vendors offer these for free. A device deployed with its default configuration is a liability from day one.
Segment your network with VLANs
Network segmentation limits how far an attacker can move after gaining a foothold. Use managed switches to create separate VLANs for different environments: user workstations, servers, IoT devices, and guest access should each exist in their own segment, with defined rules governing what can communicate across boundaries. The network security best practices guide covers segmentation implementation in detail. Segmentation is the most effective single control for limiting a breach's blast radius.
Keep firmware current
Treat network device firmware the same way you treat server OS patches: a security-critical update cycle with real consequences for skipping it. Subscribe to vendor security advisories for every device model in your environment and establish a patch SLA that reflects the severity of each CVE. Critical vulnerabilities on internet-facing devices, including routers, firewalls, and VPN appliances, warrant emergency patching. Devices that no longer receive firmware updates from their vendors represent unmitigable risk and should be replaced.
Enforce least-privilege administrative access
Every network device should have individual, role-appropriate admin accounts. Don't rely on shared credentials. The principle of least privilege applies here directly: each account should have only the permissions its role requires, nothing more. Use TACACS+ or RADIUS for centralized authentication, ensuring every management session is logged and tied to a specific user. Apply MFA to management interfaces, particularly for internet-accessible devices. For high-privilege operations on critical infrastructure, just-in-time access models limit the window during which credentials can be misused.
Monitor device activity continuously
Configuration changes, authentication events, and traffic anomalies on network devices should all feed into centralized logging. An unauthorized firewall rule change, a failed login attempt on a router management interface, or a spike in outbound traffic from a switch are all signals that warrant investigation. Effective network monitoring converts device logs into actionable security intelligence and reduces the time between compromise and detection.
Conduct regular security assessments
Don't assume your network devices are secure. Scheduled configuration audits, which compare each device's running configuration against your approved baseline, surface drift before it becomes a breach. Penetration testing that specifically targets network infrastructure reveals how your segmentation, filtering rules, and access controls hold up under realistic attack conditions. CIS Control 13 provides a detailed framework for network monitoring and defense that maps directly to the device security controls in this guide.
How Netwrix Auditor for Network Devices helps you secure your network devices
Knowing what to do about configuration drift, unauthorized access, and unpatched firmware is one problem. Doing it consistently across every router, switch, and firewall in your environment is another. Netwrix Auditor for Network Devices closes that gap by providing a single source of visibility across Cisco, Fortinet, Palo Alto, SonicWall, Juniper, Cisco Meraki, HPE Aruba, and Pulse Connect Secure devices.
Automated configuration change auditing
Every configuration change on a monitored device is automatically logged and linked to the account that made it. Instead of discovering a drifted firewall rule during a scheduled audit weeks later, you get an alert when the change happens, with a clear record of who made it, when, and what changed. That turns configuration drift from a periodic cleanup task into something you catch in real time.
Remote and suspicious access tracking
It flags logins and access attempts from unexpected accounts, locations, or times. If someone accesses a core switch from an unfamiliar IP address at 2 a.m., or an account without admin rights authenticates to a router's management interface, you find out immediately rather than during incident response after the fact.
One platform across Cisco, Fortinet, HP, Juniper, and SonicWALL
Multi-vendor environments usually mean multiple consoles, each with its own logging format and alerting quirks. Consolidating activity across all eight vendors into one platform means your team isn't stitching together logs from eight different places just to answer what changed and who changed it.
Request a demo to see how Netwrix can help you audit network device configurations, detect unauthorized changes, and maintain continuous visibility across your network infrastructure.
Frequently asked questions about network devices
Share on
Learn More
About the author
Dirk Schrader
VP of Security Research
Dirk Schrader is a Resident CISO (EMEA) and VP of Security Research at Netwrix. A 25-year veteran in IT security with certifications as CISSP (ISC²) and CISM (ISACA), he works to advance cyber resilience as a modern approach to tackling cyber threats. Dirk has worked on cybersecurity projects around the globe, starting in technical and support roles at the beginning of his career and then moving into sales, marketing and product management positions at both large multinational corporations and small startups. He has published numerous articles about the need to address change and vulnerability management to achieve cyber resilience.
Learn more on this subject
Your AI policy is just paper without endpoint enforcement
Configuration management for secure endpoint control
How to create, change, and test passwords using PowerShell
How to Create, Delete, Rename, Disable and Join Computers in AD Using PowerShell
How to Disable Inactive User Accounts Using PowerShell