Why layered models matter
Sending a web page from a server in Mumbai to a phone in Delhi involves dozens of jobs: turning bits into electrical or radio signals, getting a frame across one Wi-Fi hop, finding a route across many networks, recovering lost data, and finally understanding what "GET /index.html" means. No single program does all of this. Instead, the work is split into layers, each doing one job and offering a service to the layer above it.
A network model is a description of those layers. Two models matter. The OSI reference model (Open Systems Interconnection, from ISO) has seven layers and is the vocabulary everyone uses: "that's a layer 2 problem", "an L7 load balancer". The TCP/IP model has four (or five) layers and describes how the internet is actually built.
Interviewers use this topic to check fundamentals: can you list the layers in order, say what each one does, name its unit of data, place common protocols and devices correctly, and explain encapsulation? Follow-ups test the traps: "Which layer is ARP?", "Is TLS layer 4, 5 or 6?", "Why is a router a layer 3 device?" This lesson covers all of it.
Why layering exists
Layering is a design choice with concrete benefits.
- Separation of concerns. Each layer solves one problem. TCP does not care whether bits travel over fibre or Wi-Fi; Ethernet does not care whether the payload is a web page or a video.
- Independent change. You can swap one layer's technology without touching the others. Your browser did not change when your home moved from DSL to fibre, because the physical and link layers are hidden below IP.
- Interoperability. Different vendors can build different layers as long as they follow the interface and protocol rules. A Cisco router and a Juniper router can forward the same IP packet.
- Easier teaching and troubleshooting. You can debug bottom up: is the cable plugged in (layer 1)? Does the link have a MAC address and connectivity (layer 2)? Is there an IP route (layer 3)? Is the port open (layer 4)?
Two terms describe how layers talk:
- Service (vertical): what a layer offers to the layer directly above it on the same machine, through an interface. IP offers TCP "deliver this packet to that host, best effort."
- Protocol (horizontal): the rules a layer follows when talking to the same layer on another machine. TCP on your laptop speaks the TCP protocol with TCP on the server. These same-layer partners are called peers.
Layering has costs too: each layer adds a header (overhead), and strict separation can hide information that would help performance. Real stacks sometimes break the rules for speed, for example when TCP reads the link MTU to choose segment sizes.
The seven OSI layers
The OSI model lists layers from 1 (bottom, closest to the wire) to 7 (top, closest to the user). A common mnemonic from layer 1 up is "Please Do Not Throw Sausage Pizza Away": Physical, Data link, Network, Transport, Session, Presentation, Application.
Each layer's block of data is called a protocol data unit (PDU), and the name changes by layer.
+-------------------+ Layer 7 Application data
+-------------------+ Layer 6 Presentation data
+-------------------+ Layer 5 Session data
+-------------------+ Layer 4 Transport segment (TCP)
| | datagram (UDP)
+-------------------+ Layer 3 Network packet
+-------------------+ Layer 2 Data link frame
+-------------------+ Layer 1 Physical bits
Layer 1: Physical
The physical layer moves raw bits over a medium. It defines voltages or light levels that mean 0 and 1, bit timing, connector shapes, pin layouts, cable types, radio frequencies and the line coding that turns bits into signals (for example Manchester encoding in 10 Mbps Ethernet). It has no idea what a frame or address is.
- PDU: bits (or symbols).
- Examples: Ethernet physical standards such as 1000BASE-T over copper, fibre optics, DSL, the radio part of Wi-Fi, USB signalling.
- Devices: cables, connectors, repeaters (regenerate a weak signal), hubs (multi-port repeaters), modems, transceivers.
Layer 2: Data link
The data link layer moves frames between two directly connected nodes on the same link or LAN. Its jobs are framing (marking where a frame starts and ends), physical addressing with MAC addresses, error detection (usually a CRC in a trailer), sometimes flow control, and media access control (deciding who may transmit on a shared medium).
IEEE splits it into two sublayers: LLC (logical link control, the interface up to the network layer) and MAC (media access control, addressing and channel access).
- PDU: frame.
- Protocols: Ethernet (IEEE 802.3), Wi-Fi (IEEE 802.11), PPP, VLAN tagging (802.1Q), spanning tree (802.1D). ARP is usually placed between layers 2 and 3 (see the traps section).
- Devices: switches and bridges, network interface cards (NICs), wireless access points.
Layer 3: Network
The network layer delivers packets from the source host to the destination host across multiple networks. Its jobs are logical addressing (IP addresses), routing (computing paths) and forwarding (moving a packet out of the right interface at each router). It also handles fragmentation in IPv4 when a packet is too big for a link.
- PDU: packet (IP datagram).
- Protocols: IPv4, IPv6, ICMP, routing protocols such as OSPF (which runs directly over IP); IPsec.
- Devices: routers, layer 3 switches.
Layer 4: Transport
The transport layer provides process-to-process delivery: it gets data to the right application on a host, identified by a port number. Depending on the protocol it also provides reliability (retransmission), ordering, flow control (do not overwhelm the receiver) and congestion control (do not overwhelm the network). It splits application data into segments and reassembles them.
- PDU: segment for TCP, datagram for UDP.
- Protocols: TCP, UDP, SCTP. QUIC runs over UDP and does transport-layer jobs from user space.
- Devices: no dedicated device in the pure model; firewalls and layer 4 load balancers inspect port numbers.
Layer 5: Session
The session layer sets up, manages and ends sessions (dialogues) between applications. It covers dialogue control (who talks when, full or half duplex), and checkpointing: inserting sync points so a long transfer can resume from the last checkpoint instead of starting over.
- PDU: data.
- Examples: NetBIOS sessions, RPC session handling, the session-setup part of SQL and remote-procedure protocols. In the internet stack, these jobs are done inside applications or by TCP connections, so layer 5 is rarely a separate piece of software.
Layer 6: Presentation
The presentation layer makes sure the data from one system is understood by another. Its jobs are translation of formats (character encodings such as ASCII vs UTF-8, byte order), serialisation of data structures (ASN.1, XDR), compression and encryption.
- PDU: data.
- Examples: character encoding, JPEG and MPEG as data formats, TLS encryption is often cited here, MIME types.
Layer 7: Application
The application layer is the interface to network services that applications use. It is not the application itself (your browser) but the protocol the application speaks.
- PDU: data (often called a message).
- Protocols: HTTP, HTTPS, DNS, SMTP, IMAP, POP3, FTP, SSH, DHCP, SNMP, Telnet.
- Devices: gateways in the strict sense, layer 7 load balancers and proxies, web application firewalls.
OSI summary table
| # | Layer | Core job | PDU | Protocols / examples | Devices |
|---|---|---|---|---|---|
| 7 | Application | Network services to apps | Data | HTTP, DNS, SMTP, FTP, SSH | Proxy, L7 load balancer, gateway |
| 6 | Presentation | Format, encode, compress, encrypt | Data | UTF-8, JPEG, ASN.1, TLS (often) | - |
| 5 | Session | Open, manage, close dialogues | Data | NetBIOS, RPC sessions | - |
| 4 | Transport | Process-to-process, reliability | Segment / datagram | TCP, UDP, SCTP | Firewall, L4 load balancer |
| 3 | Network | Host-to-host across networks | Packet | IPv4, IPv6, ICMP, OSPF | Router, L3 switch |
| 2 | Data link | Node-to-node on one link | Frame | Ethernet, Wi-Fi, PPP, 802.1Q | Switch, bridge, NIC, AP |
| 1 | Physical | Bits as signals | Bits | 1000BASE-T, fibre, DSL | Hub, repeater, cable, modem |
Interview tip
Learn the scope of each of the lower three layers in one phrase: layer 2 is hop to hop (one link), layer 3 is host to host (across networks), layer 4 is process to process (to the right application). This answers half the follow-up questions on its own.
The TCP/IP model
OSI was designed by committee as a general reference before the protocols existed. The TCP/IP model went the other way: the protocols (TCP and IP) came first, and the model describes them. It is what the internet runs on.
The original model, described in RFC 1122, has four layers. Many textbooks use a five-layer "hybrid" that splits the bottom layer into data link and physical, because it is easier to teach.
Four-layer TCP/IP Five-layer (teaching)
+--------------------+ +--------------------+
| Application | | Application |
+--------------------+ +--------------------+
| Transport | | Transport |
+--------------------+ +--------------------+
| Internet | | Network |
+--------------------+ +--------------------+
| Link | | Data link |
| (network access) | +--------------------+
| | | Physical |
+--------------------+ +--------------------+
- Application: everything above transport. In TCP/IP there is no separate session or presentation layer; applications handle those jobs (HTTP has its own content encoding; TLS is a library the application uses).
- Transport: TCP and UDP.
- Internet: IP, plus ICMP. This is the "narrow waist" of the internet: everything above runs over IP, and IP runs over everything below.
- Link (network access): whatever technology moves frames on the local link, including the physical medium.
The hourglass picture shows why IP is so important:
HTTP SMTP DNS SSH QUIC-apps many applications
\ \ | / /
TCP UDP a few transports
\ /
IP ONE network protocol
/ \
Ethernet Wi-Fi 4G/5G fibre many link technologies
Because every application and every link only needs to work with IP, a new app (or a new radio technology) works everywhere at once.
Mapping OSI to TCP/IP
| OSI layer | Four-layer TCP/IP | Five-layer model | Example |
|---|---|---|---|
| 7 Application | Application | Application | HTTP, DNS |
| 6 Presentation | Application | Application | UTF-8, TLS |
| 5 Session | Application | Application | Session handling in apps |
| 4 Transport | Transport | Transport | TCP, UDP |
| 3 Network | Internet | Network | IP, ICMP |
| 2 Data link | Link | Data link | Ethernet, Wi-Fi |
| 1 Physical | Link | Physical | Cable, radio |
OSI vs TCP/IP
| Aspect | OSI | TCP/IP |
|---|---|---|
| Layers | 7 | 4 (or 5 in teaching) |
| Origin | Model first, protocols later | Protocols first, model describes them |
| Use today | Vocabulary and teaching | Actual internet implementation |
| Session / presentation | Separate layers | Folded into application |
| Network layer service | Connection-oriented and connectionless | Connectionless only (IP) |
| Transport service | Mainly connection-oriented | Both (TCP connection-oriented, UDP connectionless) |
| Distinction of service, interface, protocol | Very explicit | Less explicit |
Common mistake
Saying "TCP/IP has 5 layers" as if it were the official model. The original TCP/IP model has four layers; five is a common teaching hybrid. If an interviewer says four or five, agree and name which one you are using.
Encapsulation and decapsulation
Encapsulation is the process of each layer wrapping the data from the layer above with its own header (and, at layer 2, a trailer). The receiving side does the reverse, decapsulation: each layer reads and removes its own header, then hands the rest up.
Each layer treats everything it received from above as an opaque payload (also called the SDU, service data unit). It does not read or change it. The header holds the information that layer's peer needs on the other side.
Walk-through: a browser sends an HTTP request
You type a URL and your browser sends GET /index.html to a web server at 93.184.216.34, port 80. Your laptop is on Ethernet.
Step 1: Application layer. The browser builds the HTTP request text:
GET /index.html HTTP/1.1
Host: example.com
This is the application data, call it the message.
Step 2: Transport layer. TCP adds a 20-byte header (more with options). Key fields: source port (an ephemeral port chosen by the OS, say 51514), destination port 80, sequence number, acknowledgement number, flags, window size and checksum. Result: a TCP segment.
Step 3: Network layer. IP adds a 20-byte header (IPv4 without options). Key fields: source IP (your laptop, say 192.168.1.10), destination IP 93.184.216.34, TTL (time to live, a hop limit), protocol = 6 (meaning "the payload is TCP"), and header checksum. Result: an IP packet.
Step 4: Data link layer. Ethernet adds a 14-byte header and a 4-byte trailer. Header: destination MAC, source MAC, and EtherType 0x0800 (meaning "the payload is IPv4"). Trailer: the FCS (frame check sequence), a CRC-32 over the frame. Result: an Ethernet frame.
The destination MAC is not the server's MAC. It is the MAC of your default gateway (home router), found with ARP, because the frame only needs to cross one hop.
Step 5: Physical layer. The NIC adds an 8-byte preamble and start-of-frame delimiter for clock synchronisation and sends the frame as electrical signals.
Application [ HTTP data ]
Transport [TCP hdr][ HTTP data ]
Network [IP hdr][TCP hdr][ HTTP data ]
Link [Eth hdr][IP hdr][TCP hdr][ HTTP data ][Eth FCS]
Phys 0110100101011010010111010... (bits on the wire)
sizes: Eth 14 | IP 20 | TCP 20 | data ... | FCS 4 (bytes)
Each header points to the next
Notice how each header has a field telling the receiver what is inside it. This is what makes decapsulation work.
| Header | Field | Example value | Meaning |
|---|---|---|---|
| Ethernet | EtherType | 0x0800 | Payload is IPv4 (0x86DD = IPv6, 0x0806 = ARP) |
| IPv4 | Protocol | 6 | Payload is TCP (17 = UDP, 1 = ICMP) |
| TCP / UDP | Destination port | 80 | Hand data to the process listening on port 80 |
This chain is called demultiplexing: at each layer, a field in the header selects which upper-layer protocol or process gets the payload.
What happens at each hop
The frame reaches your home router. The router:
- Checks the FCS; discards the frame if it is corrupted.
- Removes the Ethernet header and trailer (decapsulates to layer 3).
- Reads the destination IP, looks it up in its routing table, decrements TTL, recomputes the IP header checksum. (A home router also rewrites the source address with NAT, covered in the addressing lesson.)
- Builds a new layer 2 frame for the next link, with new source and destination MACs.
- Sends it out.
So along the path:
- MAC addresses change at every hop (they are hop to hop).
- IP addresses stay the same end to end (ignoring NAT).
- Port numbers and the TCP segment are not touched by routers (ignoring NAT and middleboxes).
Laptop Switch Router ... Server
L7 ---------------------------------------------------- L7
L4 ---------------------------------------------------- L4
L3 ----------------------- L3 ------- (routers) ------- L3
L2 ---------- L2 --------- L2 L2
L1 ---------- L1 --------- L1 L1
switch works at L2; router works up to L3;
only the end hosts process L4 and L7
Decapsulation at the server
The server's NIC receives bits, checks the FCS, sees EtherType 0x0800 and passes the payload to IP. IP checks the destination address is its own, sees protocol 6 and passes the payload to TCP. TCP uses the 4-tuple (source IP, source port, destination IP, destination port) to find the matching connection, puts the bytes in order, sends an acknowledgement, and delivers the data to the web server process listening on port 80. The web server reads GET /index.html.
How much is overhead?
For a full-size TCP segment on Ethernet with a 1,500-byte MTU (maximum transmission unit, the largest IP packet the link carries):
- TCP payload: 1,500 - 20 (IP) - 20 (TCP) = 1,460 bytes (this is the usual MSS, maximum segment size).
- Frame size: 1,500 + 14 + 4 = 1,518 bytes.
- On the wire, add 8 bytes of preamble/SFD and a 12-byte inter-frame gap: 1,538 byte-times.
- Efficiency: 1,460 / 1,538 ≈ 94.9%.
For a small 100-byte payload: 100 + 20 + 20 + 14 + 4 = 158-byte frame, 178 byte-times on the wire, efficiency 100 / 178 ≈ 56.2%. Small messages pay a large header tax, which is one reason protocols batch writes (Nagle's algorithm, HTTP/2 multiplexing).
Devices: hub, repeater, bridge, switch, router, gateway
A device's "layer" is the highest layer whose headers it reads to make its decision.
Repeater and hub (layer 1)
A repeater receives a signal, regenerates it to full strength and sends it on, extending cable distance. A hub is a multi-port repeater: a signal arriving on one port is copied to all other ports. A hub does not understand frames or addresses. All ports form one collision domain (only one device can successfully transmit at a time) and one broadcast domain. Hubs are half duplex and obsolete in modern networks.
Bridge (layer 2)
A bridge connects two LAN segments and forwards frames between them based on MAC addresses. It learns which MAC addresses live on which side and only forwards frames that need to cross. This splits one collision domain into two. Classic bridges had few ports and were often software-based.
Switch (layer 2)
A switch is a multi-port bridge built in hardware. It reads the destination MAC of each frame and sends it only out the port where that MAC lives, using a MAC address table it learns automatically. Each port is its own collision domain, and with full duplex there are no collisions at all. All ports are still in one broadcast domain unless you configure VLANs. A layer 3 switch can also route between VLANs at hardware speed.
Router (layer 3)
A router connects different IP networks. It reads the destination IP address, finds the best match in its routing table, and forwards the packet out the right interface, rebuilding the layer 2 frame for the next link. Routers do not forward broadcasts, so each router interface is a separate broadcast domain. Routers run routing protocols, decrement TTL, and often do NAT and filtering.
Gateway (any layer, usually 4 to 7)
Gateway has two meanings, and interviewers may use either:
- Default gateway: the router a host sends packets to when the destination is not on its local network. In this sense a gateway is just a router.
- Protocol gateway: a device that translates between different protocol stacks, possibly at every layer, for example an email gateway converting between mail systems, a VoIP gateway converting between SIP and the phone network, or an IoT gateway converting between Zigbee and IP.
Comparison table
| Device | Layer | Decides using | Collision domains | Broadcast domains | Notes |
|---|---|---|---|---|---|
| Hub | 1 | Nothing (repeats all) | 1 for all ports | 1 | Obsolete, half duplex |
| Repeater | 1 | Nothing | 1 | 1 | Extends distance |
| Bridge | 2 | MAC address | 1 per port | 1 | Few ports, learns MACs |
| Switch | 2 | MAC address | 1 per port | 1 (per VLAN) | Hardware, full duplex |
| Router | 3 | IP address | 1 per port | 1 per port | Does not forward broadcasts |
| Gateway | 4 to 7 | Application data | - | - | Translates protocols |
Worked example: counting domains. A router has two interfaces. Interface 1 connects to a 24-port switch with 10 hosts plugged in. Interface 2 connects to an 8-port hub with 5 hosts. How many collision and broadcast domains?
- Broadcast domains: each router interface is one: 2.
- Collision domains: the switch side has one per used switch port: 10 host ports + 1 uplink to the router = 11. The hub side is one shared domain including its link to the router: 1. Total 12.
Interview tip
"Switches break up collision domains; routers break up broadcast domains." That one sentence answers most device-comparison questions. Add that VLANs let one switch create several broadcast domains.
Where protocols sit: the common traps
These are the questions where candidates most often slip. For each, give the usual answer and show you know why it is debated.
ARP: layer 2 or layer 3?
ARP (Address Resolution Protocol) maps an IP address to a MAC address on the local network. Its messages are carried directly in Ethernet frames (EtherType 0x0806), not inside IP packets, so it is not a network-layer protocol in the routing sense. But it exists to serve IP. The safest answer: "ARP works between layers 2 and 3; it is often called a layer 2.5 protocol. Many textbooks put it at layer 2 because it is not carried in IP and never leaves the local link."
ICMP: layer 3 or layer 4?
ICMP (used by ping and traceroute) is carried inside IP packets with protocol number 1, just like TCP (6) and UDP (17). So in terms of encapsulation it rides on IP. But it is part of the network layer's own control machinery (errors and diagnostics for IP). The accepted answer is layer 3, as a companion to IP.
TLS: layer 4, 5, 6 or 7?
TLS encrypts data between an application and TCP. In OSI terms, encryption is a presentation-layer job, and session setup is a session-layer job, so people say 5 or 6. In TCP/IP terms it is part of the application layer (a library the app calls). A strong answer: "TLS sits between the application and TCP; in OSI vocabulary it does presentation and session jobs. It is not layer 4, because it relies on TCP for transport."
Routing protocols
- OSPF runs directly over IP (protocol 89): usually placed at layer 3.
- RIP runs over UDP port 520, and BGP runs over TCP port 179. They are application-layer programs by encapsulation, but they exist to serve layer 3. Interviewers accept "they are routing protocols for the network layer, carried by UDP or TCP."
DHCP and DNS
Both are application-layer protocols, carried over UDP (ports 67/68 for DHCP, 53 for DNS; DNS also uses TCP 53 for large responses and zone transfers). They provide services the lower layers need, but they live at layer 7.
Other quick traps
- MAC addresses are layer 2; IP addresses layer 3; port numbers layer 4.
- Wi-Fi access points bridge between wireless and wired at layer 2; a home "Wi-Fi router" is a router, a switch and an access point in one box.
- Modems are layer 1 (they modulate and demodulate signals).
- NIC works at layers 1 and 2.
- Firewalls range from layer 3/4 (packet filters on IPs and ports) to layer 7 (inspecting HTTP).
- Load balancers are called L4 (route by IP and port, do not read HTTP) or L7 (read HTTP headers and URLs). See load balancing.
Common mistake
"HTTP is layer 7, so the browser is layer 7." The application layer is the protocol (HTTP), not the program. The browser is a user application that uses the HTTP protocol.
Common mistake
Saying a switch "routes" frames or a router "switches" by MAC. Switches forward on MAC addresses within a LAN; routers forward on IP addresses between networks. Precise words signal real understanding.
Layered troubleshooting in practice
When "the site does not load", walk up the stack:
| Layer | Question | Tool or check |
|---|---|---|
| 1 | Is the cable in, is Wi-Fi associated? | Link light, ip link, Wi-Fi status |
| 2 | Do I have a link-layer neighbour? Is ARP resolving? | ip neigh, arp -a |
| 3 | Do I have an IP address and a route? Can I reach the gateway? | ip addr, ip route, ping gateway |
| 3 | Can I reach the internet by IP? | ping 8.8.8.8, traceroute |
| 7 | Does the name resolve? | nslookup, dig |
| 4 | Is the port open? | nc -vz host 443, telnet host 80 |
| 7 | Does the app answer correctly? | curl -v https://host/ |
If ping 8.8.8.8 works but ping google.com fails, the network is fine and DNS is broken. If neither works but you can ping the gateway, the problem is beyond your LAN. This layered approach is a favourite practical question.
Interview questions
Q1. List the OSI layers and the PDU at each.
From bottom: Physical (bits), Data link (frame), Network (packet), Transport (segment for TCP, datagram for UDP), Session, Presentation and Application (data). A mnemonic is "Please Do Not Throw Sausage Pizza Away."
Q2. What is the difference between the OSI and TCP/IP models?
OSI is a seven-layer reference model designed before its protocols and used mainly as vocabulary. TCP/IP is a four-layer model that describes the protocols the internet actually uses; it folds session and presentation into the application layer and merges data link and physical into one link layer. TCP/IP's network layer is connectionless only.
Q3. What is encapsulation?
Each layer takes the data from the layer above as an opaque payload and adds its own header (and a trailer at layer 2) carrying information its peer needs. The receiver reverses the process, each layer removing its own header and handing the rest up. Fields such as EtherType, IP protocol and port number tell each layer whom to hand the payload to.
Q4. At which layer do switches and routers work, and what is the practical difference?
Switches work at layer 2 and forward frames by MAC address within a LAN. Routers work at layer 3 and forward packets by IP address between networks. Switches split collision domains; routers split broadcast domains and do not forward broadcasts.
Q5. Which addresses change as a packet crosses routers?
The MAC addresses in the Ethernet header change at every hop, because each frame only crosses one link. The source and destination IP addresses stay the same end to end, unless NAT rewrites them. TTL is decremented at every router and the IP checksum recomputed.
Q6. Where does ARP sit, and why is it debated?
ARP resolves IP addresses to MAC addresses and is carried directly in Ethernet frames, not in IP, so many place it at layer 2. Because it serves IP and deals with IP addresses, it is often called layer 2.5. The key point is that it never leaves the local network.
Q7. Why does the TCP/IP model not have session and presentation layers?
Its designers found those jobs are application-specific and better done inside applications or libraries. HTTP handles its own content encoding and sessions use cookies; TLS is a library applications call. Keeping the stack thin also kept IP simple.
Q8. What is the difference between a hub and a switch?
A hub is a layer 1 device that repeats every signal to all ports, creating one collision domain and running half duplex. A switch is a layer 2 device that learns MAC addresses and forwards each frame only to the right port, giving each port its own collision domain and allowing full duplex. Switches are faster and more secure because other hosts do not see unicast traffic.
Q9. What is a default gateway?
It is the router a host sends packets to when the destination IP is not on the host's own subnet. The host uses ARP to find the gateway's MAC and addresses the frame to it, while the IP header still carries the final destination.
Q10. At which layer does TLS operate?
It sits between the application and TCP. In OSI vocabulary it performs presentation (encryption) and session (handshake, session resumption) tasks; in the TCP/IP model it belongs to the application layer. It is not a transport-layer protocol because it relies on TCP (or QUIC builds its own encryption into its transport).
Q11. Explain service versus protocol in a layered model.
A service is what a layer offers the layer above it on the same machine, through an interface. A protocol is the set of rules the layer uses to talk to its peer layer on another machine. You can change a protocol without affecting users of the service, as long as the service stays the same.
Q12. What are the downsides of layering?
Every layer adds header overhead, which hurts small messages. Strict separation hides information that could help: for example, TCP interprets all loss as congestion even when it is wireless corruption. Some systems cross layers deliberately (path MTU discovery, QUIC merging transport and encryption) for performance.
Q13. How many collision and broadcast domains does a 16-port switch with all ports in use create?
Sixteen collision domains (one per port) and one broadcast domain, assuming no VLANs. With VLANs configured, each VLAN is its own broadcast domain.
Q14. A user can ping 8.8.8.8 but cannot open google.com. Which layer is at fault?
IP connectivity (layer 3) works, so the likely fault is DNS, an application-layer service. Check the configured resolver with nslookup or dig. If DNS resolves but the page still fails, check whether the port is reachable (layer 4) and then the HTTP response (layer 7).
Key takeaways
- Layering splits networking into independent jobs; each layer offers a service upward and speaks a protocol to its peer.
- OSI has seven layers (Physical, Data link, Network, Transport, Session, Presentation, Application); TCP/IP has four (Link, Internet, Transport, Application), often taught as five.
- PDUs: bits, frame, packet, segment or datagram, data.
- Layer 2 is hop to hop (MAC), layer 3 host to host (IP), layer 4 process to process (ports).
- Encapsulation adds a header per layer; EtherType, IP protocol and port fields drive demultiplexing on the way up.
- MAC addresses change every hop; IP addresses stay end to end unless NAT intervenes.
- Hubs are layer 1, switches and bridges layer 2, routers layer 3, protocol gateways layers 4 to 7. Switches split collision domains; routers split broadcast domains.
- Know the traps: ARP is layer 2/2.5, ICMP is layer 3, TLS sits between application and TCP, RIP and BGP ride on UDP and TCP.
Next lesson
Continue with The data link layer.

