Skip to main content
AD Academy
CCNA — Cisco Networking Fundamentals
Beginner12 minLast updated: Topic 1 of 12

OSI and TCP/IP Model

The seven layers, what happens in each layer, and how it helps troubleshoot problems.

Not read

What you will learn here

  • The Seven Layers
  • TCP vs. UDP
  • The seven layers, what happens in each layer, and how it helps troubleshoot problems.

The OSI model divides network communication into seven layers. Each layer is responsible for something different, and when there's a problem — you go layer by layer from bottom to top to locate the issue.

The Seven Layers

Seven layers bottom-up: Physical (cables and signals), Data Link (MAC addresses and frames), Network (IP and routing), Transport (ports, TCP vs UDP), Session (conversation management), Presentation (encoding and encryption), Application (what the user sees). On the right, the four-layer TCP/IP model: Network Access covers 1 and 2, Internet maps to 3, Transport to 4, and Application to 5, 6 and 7. Troubleshooting works bottom-up.

Short and clear

  • OSI is 7 layers describing how data travels from the app down to the physical cable.
  • TCP/IP is the same idea compressed into 4 layers — that is what actually runs.
  • Each layer adds its own wrapper (encapsulation) and the far side strips it off.
  • When something breaks, test layer by layer bottom-up: cable, IP, port, application.

Real-life exampleA site will not load: ping works (layer 3 is fine) but connecting to port 443 fails — the problem is layer 4 (a firewall blocks the port), not DNS and not the cable.

  • 1. Physical — Cables, fibers, electrical signals.
  • 2. Data Link — MAC Address, Ethernet Frames, Switching.
  • 3. Network — IP Address, Routing.
  • 4. Transport — TCP (reliable) and UDP (fast), Port Numbers.
  • 5. Session — Managing a conversation between two parties.
  • 6. Presentation — Encryption, encoding, compression.
  • 7. Application — HTTP, DNS, SMB, — what the user sees.

TCP vs. UDP

  • TCP — Three-Way Handshake (SYN, SYN-ACK, ACK), ensures delivery and order. Examples: HTTP/443, SSH/22, /389.
  • UDP — Connectionless and without acknowledgment, faster. Examples: DNS/53, DHCP/67-68, VoIP.
Architecture and Theory — Under the Hood

Each layer wraps the information of the layer above it with its own header — this process is called Encapsulation. The data changes names at each layer: Data → Segment (L4) → Packet (L3) → Frame (L2) → Bits (L1). The reverse process (De-encapsulation) occurs on the receiving side.

+---------------------------------------------------+
| Ethernet Header | IP Header | TCP Header | Data  |  <-- Frame
|  DST/SRC MAC    | DST/SRC IP| DST/SRC Port|      |
+---------------------------------------------------+
   L2 (Switch)      L3 (Router)  L4 (Firewall)  L7
text
  • Ethernet Frame: DST MAC (6B) + SRC MAC (6B) + Type/Length (2B) + Payload + FCS (4B). Standard MTU 1500 bytes.
  • IPv4 Header: 20 basic bytes — Version, TTL, Protocol (6=TCP, 17=UDP, 1=ICMP), SRC/DST IP.
  • TCP Header: Ports, Sequence/Ack Numbers, Flags (SYN, ACK, FIN, RST, PSH, URG), Window Size.
  • UDP Header: Only 8 bytes — Ports, Length, Checksum. No reliability and no order.
Practical Definition (CLI)
! What passes through each layer - layer by layer check
Router# show interfaces gi0/1        ! L1/L2: status, errors, MTU
Router# show mac address-table       ! L2
Router# show ip interface brief      ! L3
Router# show ip route                ! L3
Router# show tcp brief               ! L4
Router# show ip nat translations     ! L3/L4
bash
Real-world Scenarios in the Organization
  • Help Desk: Before escalating a problem — determine which layer it's on. This saves hours.
  • Firewall Policy: Policy rules are written according to L3 (IP) and L4 (Port) — understanding headers is essential.
  • Wireshark: Filters are written by layers — eth.addr, ip.addr, tcp.port, http.request.
Troubleshooting and Problem Solving
  • 1. L1 — Is the interface up/up? Are there CRC errors (faulty cable/fiber)?
  • 2. L2 — Is the MAC learned on the correct port? Does the VLAN match?
  • 3. L3 — ping to Gateway, then show ip route to destination.
  • 4. L4 — telnet <ip> <port> or Test-NetConnection: Is the port open?
  • 5. L7 — Only now check the application, DNS, certificates.
ping 8.8.8.8            # L3 working?
traceroute 8.8.8.8      # where does it stop?
telnet 10.0.0.5 445     # L4: is the port listening?
nslookup dc01.lab.local # L7/DNS
bash
Glossary and Quick Command Line
  • PDU: Bits → Frame → Packet → Segment → Data
  • Switch = L2 (MAC) | Router = L3 (IP) | Firewall = L3-L7
  • TCP Handshake: SYN → SYN/ACK → ACK
  • Ports: 20/21 FTP, 22 SSH, 23 Telnet, 25 SMTP, 53 DNS, 67/68 DHCP, 80 HTTP, 88 , 123 NTP, 161 SNMP, 389 , 443 HTTPS, 445 SMB, 636 LDAPS, 3389 RDP

Check yourself

On which layer does a regular Switch operate?

Which transport protocol does DNS use for most queries?

Was this page helpful?