Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.
Routers are (by definition) Layer 3 devices designed to pass packets between networks. These days, pretty much every router has the ability to do some filtering at Layer 3 as well. Most can examine Layer 4 sockets to some degree, and at least filter traffic based on source/destination port.
Routers are typically involved in investigations for one of a few reasons:
• Traffic of interest may traverse the router, resulting in associated flow data and related records. (A router is one of the most basic logging devices you will find on any network and also one of the most fundamental.)
• The network topology is key to understanding evidence and incidents, and is described at Layer 3 by the aggregate of routing tables.