
If the on-premise Layer 3 core is overkill for most sites, what replaces it? Not nothing, the requirements are real, they just moved. Here is what the New Enterprise edge actually requires.
Fast Layer 2 switching with routing at the edge. Local devices still need to talk to each other quickly. But the dedicated, feature-rich L3 core switch, sized for heavy on-prem east-west routing that has largely moved to the cloud, is overkill for the majority of sites. The routing that remains can live in the edge appliance. The argument is not “Layer 3 is dead.” It is that dedicated L3 core switching is now overprovisioned for most medium and large sites, because the traffic it was built to route left for the cloud. The genuine Disney-scale or latency-critical-local-compute exceptions are real and are addressed in Part Eight.
VLAN isolation and segmentation. Separating traffic, guest from corporate, IoT from users, payment systems from everything else, remains essential and arguably matters more as the edge multiplies.
Zero Trust instead of a perimeter. When users and applications are everywhere, the perimeter is gone. The replacement is continuous verification and least-privilege access, the Zero Trust model. Adoption is now mainstream, with a large share of organizations implemented or in progress. The New Enterprise assumes no inside and no outside. There is only verified and unverified.
Enterprise authentication: 802.1X and RADIUS. Every device that joins the network proves who it is. This is the access-control backbone of the distributed edge.
Enterprise Wi-Fi. With BYOD near-universal and most work happening over wireless, the wireless network is not an amenity. It is the primary access layer, and it has to carry enterprise authentication, segmentation, and reliability.
Centralized, zero-touch management. Everything above has to be configurable and observable from one place, or it does not scale to a thousand edges.
Notice what is on this list and what is not. It is not a list of features. It is a list of behaviors: isolate, verify, authenticate, manage centrally, never depend on one link. The New Enterprise is defined by how it behaves, not by how much it can do.
Why the core switch existed, and why that reason expired
It is worth understanding why the Layer 3 core switch was ever necessary, because the reason is the whole story. In the 1990s and early 2000s, internet connections ran from a few megabits to maybe 100 Mbps, and a gigabit internet connection was almost unheard of. Your local network was faster than your internet connection. Your servers lived on that local network, and you needed a switching fabric fast enough to handle high-capacity traffic between machines inside the building. The router only had to handle the firewall and the comparatively slow connection to the outside world. Firewalls were never as fast as core switches, and they did not need to be.
Two things changed at once, starting around 2008. Gigabit internet arrived and kept getting faster, so the router now had to be fast, multi-gigabit, and multi-gigabit routing means multi-gigabit inter-VLAN routing too. At the same time, the cloud migration began in earnest. Servers started moving off the local network and into colocation and then the cloud. The heavy east-west traffic that justified the core switch began leaving the building.
Put those together and the result is a high-performance router that handles gigabits per second of throughput, inter-VLAN routing, security, and high-availability redundancy, for pennies on the dollar compared to the traditional enterprise core our predecessors built. The core switch was fast because, once, it had to be. Most networks no longer have the traffic that made it necessary.
The precise way to state this matters. The core switch is not obsolete; it belongs in the data center, where terabits per second of machine-to-machine traffic genuinely demand a high-capacity switching fabric. The error is architectural displacement: taking that data-center and carrier-grade design and pushing it out to branches and sites whose workloads moved to the cloud and which never move anything close to that volume. The branch is sold a miniature data center it does not need. The fix is not to strip the data center; it is to stop replicating data-center architecture everywhere else.
From the Field: making the router the core.
“Around 2019 and 2020 we worked with a construction enterprise that had spent decades pouring money into infrastructure, trying to fix a problem that never needed to exist, on top of a managed MPLS that simply was not fast enough for a growing business. Over about two years we converted them completely to dual-HA SD-WAN. We used the router as the core switch. We removed the complexity that a cloud-centric business no longer needed, because there were no on-site servers left, it was essentially a set of access switches. By moving the core routing into the SD-WAN appliance, VLAN management got easier, support got easier, and everything became visible from a single management console. Scalability, affordability, accountability, reliability, all of it improved at once, and they stopped having outages. We load-balanced and bonded across multiple WAN circuits based on the price and performance of each one.
I want to be careful here. We are not saying every enterprise can eliminate the core switch. We are saying that more companies than not no longer need one. Their workloads moved to the cloud, and modern routers are fast enough to handle what remains. Many businesses are holding onto a core switch for reasons that expired years ago.”
There is a second, hidden cost to the old core that never appears on a spec sheet: it became so complex that most companies could no longer operate it themselves. So they outsource the management. And in doing that, they lose ownership of their own network, paying subscriptions and perpetual maintenance fees for a level of complexity they never actually needed. The genuine carrier-tier organization has skilled network staff on site who understand the network and are fully necessary. The other ninety-five percent do not have a team whose entire job is managing switch complexity, so they rent it, indefinitely, for infrastructure that was overkill from the start. Simplifying the architecture to where a company’s own people can see it and run it from one console is not only cheaper. It gives the business back ownership of its own network.