Skip to content

Stage 1: Networking Models — OSI & TCP/IP

Key takeaways

  • OSI is a 7-layer conceptual model — nothing in it is mandatory to implement literally
  • TCP/IP is the 4-layer model the real internet actually runs on
  • Almost every "which layer does X operate at" interview question maps back to this page

Why a layered model at all?

Networking is broken into layers so that each layer only has to solve one problem, and can be swapped out independently. Ethernet can be replaced by Wi-Fi without touching how HTTP works, because they're at different layers and only agree on the interface between them.

The OSI model (7 layers)

Layer Name Job Example protocols/units
7 Application What the user-facing software talks HTTP, FTP, DNS
6 Presentation Formatting, encryption, compression TLS (often placed here or at 5)
5 Session Manages sessions/connections between apps Sockets, session tokens
4 Transport End-to-end delivery between applications TCP, UDP (unit: segment/datagram)
3 Network Addressing & routing between networks IP, routers (unit: packet)
2 Data Link Delivery within one local network Ethernet, switches, MAC (unit: frame)
1 Physical Actual bits on the wire/air Cables, radio, voltages (unit: bit)

Mnemonic: "All People Seem To Need Data Processing" (7→1).

Why interviewers love this model

Almost any "where does X happen" question is really asking you to place something on this table. A switch = Layer 2. A router = Layer 3. TLS = somewhere around 5/6. Once you can place a term on this table instantly, half of networking trivia questions become mechanical.

The TCP/IP model (4 layers) — what the internet actually uses

OSI is taught because it's a clean teaching model, but real-world protocol stacks (and the internet itself) follow the simpler TCP/IP model, which collapses several OSI layers together:

TCP/IP Layer Roughly maps to OSI Protocols
Application 5, 6, 7 HTTP, FTP, DNS, SSH
Transport 4 TCP, UDP
Internet 3 IP, ICMP
Link (Network Access) 1, 2 Ethernet, Wi-Fi

Practical rule of thumb: when someone says "Layer 3" or "Layer 7" casually in industry, they're almost always using OSI numbering even though the actual implementation is TCP/IP-based. This is why both models are worth knowing — OSI gives you the vocabulary, TCP/IP describes what's actually running.

Protocol roadmap

The protocols introduced later in this theory sequence solve different problems at different layers. Learning them in dependency order prevents them from becoming a disconnected list of acronyms.

Protocol What it does Layer/context Learn in
ARP Maps a local IPv4 address to the MAC address needed to deliver an Ethernet frame Link between Layers 2 and 3; local broadcast domain only Stage 3 — MAC Addresses & ARP
NAT/PAT Rewrites private addresses, and with PAT transport identifiers, at a routed boundary Layer 3 with Layer 4 awareness for PAT Stage 5 — Private IPs, NAT & PAT
DHCP Leases an IP address, subnet mask, default gateway, DNS servers, and other options to a host Application protocol using UDP; depends on local broadcast or relay Stage 6 — Subnetting & DHCP
OSPF Exchanges topology information so routers inside one organization can calculate routes Layer 3 routing control plane; IP protocol 89 Stage 8 — Routing
BGP Exchanges policy-controlled network reachability within or between autonomous systems Routing control plane over TCP 179 Stage 8 — Routing
DNS Resolves names to addresses and stores other namespace records Application protocol, normally UDP or TCP 53 Stage 10 — DNS & Ports

These protocols cooperate but do not replace one another. For example, DHCP can tell a client which DNS resolver to use; DNS can return a remote IP address; the routing table chooses a next hop; ARP resolves the local next hop's MAC address; and NAT/PAT may translate the flow at the network edge.

Encapsulation (how data moves down and up the stack)

As data travels down the stack on the sending side, each layer wraps the data from the layer above with its own header (and sometimes trailer):

Application data
  → [TCP header | data]                       (Segment)
    → [IP header | TCP header | data]         (Packet)
      → [Ethernet header | IP header | ... ]  (Frame)

The receiving side does the reverse — each layer strips its own header before passing the payload up. This is encapsulation and de-encapsulation, and it's the mechanical reason each layer can stay ignorant of the layers above and below it.

Cloud connection

Terraform and Kubernetes are not additional network layers. They configure resources—such as subnets, load balancers, Services, and policies—that operate at the existing layers.

Practice in Packet Tracer

Next

Packets & IP Addressing →