Networking models split the job of moving data into layers, so each layer only has to solve one problem and can rely on the layer below it. The two models you need are the OSI (Open Systems Interconnection) reference model, which has seven layers, and the TCP/IP model, which is the model the internet actually runs on. Technicians use layer numbers as shorthand every day: 'it is a Layer 1 problem' means a cable, port or signal issue, not a software setting.
The OSI layers from bottom to top are: 1 Physical (bits as electrical, light or radio signals; cables, connectors, hubs), 2 Data Link (frames and MAC addresses on the local network; switches and network interface cards), 3 Network (packets and IP addresses, choosing paths between networks; routers), 4 Transport (segments, ports and end-to-end delivery; TCP and UDP), 5 Session (setting up and tearing down conversations), 6 Presentation (formatting, encoding, compression and encryption), and 7 Application (the network services programs use, such as HTTP, DNS and SMTP). A common memory aid from Layer 1 upward is 'Please Do Not Throw Sausage Pizza Away'.
The TCP/IP model groups these into four layers: Link (also called Network Access, covering OSI 1 and 2), Internet (OSI 3, where IP and ICMP live), Transport (OSI 4, TCP and UDP) and Application (OSI 5 to 7 combined). Some textbooks, including Cisco material, show an updated five-layer TCP/IP model that splits Link back into Physical and Data Link. Either way, the ideas line up: the numbers people say out loud almost always refer to OSI layers.
Knowing where devices sit is heavily tested. A hub or repeater only regenerates signals, so it is Layer 1. A switch reads destination MAC addresses to forward frames, so it is Layer 2. A router reads destination IP addresses to forward packets between networks, so it is Layer 3. A multilayer (Layer 3) switch does both. Firewalls commonly work at Layers 3 and 4, and next-generation firewalls can inspect up to Layer 7. Protocols fit the same way: Ethernet and Wi-Fi at 1 and 2, IP at 3, TCP and UDP at 4, and HTTP, DNS, DHCP, FTP and SSH at the application layer.
In a lab, open any packet in Wireshark and you will see the layers stacked in the details pane: a Frame line, then Ethernet II (Layer 2), Internet Protocol (Layer 3), Transmission Control Protocol or User Datagram Protocol (Layer 4) and finally the application data such as HTTP or TLS. Troubleshooting also follows the layers: check the link light and cable first, then addressing, then ports and services.
Key terms
- OSI model
- A seven-layer reference model (Physical, Data Link, Network, Transport, Session, Presentation, Application) used to describe and troubleshoot networking.
- TCP/IP model
- The four-layer model (Link, Internet, Transport, Application) that describes how internet protocols are actually organized.
- Layer 2 device
- A device, such as a switch, that forwards frames based on MAC addresses within a local network.
- Layer 3 device
- A device, such as a router, that forwards packets between networks based on IP addresses.
A user reports no network access. You notice the port light on the wall jack's switch port is off, so you tell your team it looks like a Layer 1 problem and replace the patch cable before touching any IP settings. The link light comes on and the user is back online.
Check yourself
At which OSI layer do routers make forwarding decisions, and what address do they use?
Layer 3, the Network layer, using the destination IP address.
Which OSI layers does the TCP/IP Application layer combine?
Session (5), Presentation (6) and Application (7).
Where do TCP and UDP sit in both models?
At the Transport layer, which is Layer 4 in OSI and also called Transport in the TCP/IP model.