The Open Systems Interconnection (OSI) model is a seven-layer reference model that splits the job of moving data between two computers into separate responsibilities. Nobody implements the OSI model exactly as written (the internet actually runs on the simpler TCP/IP model), but every network professional uses OSI as a shared vocabulary. When a colleague says 'it is a Layer 2 problem' they mean the fault is in switching, MAC addresses or VLANs, not in routing or the application. Network+ uses the model constantly, both directly (which layer does X work at?) and indirectly, because troubleshooting questions expect you to reason layer by layer.
From the bottom up the layers are: 1 Physical, 2 Data Link, 3 Network, 4 Transport, 5 Session, 6 Presentation and 7 Application. A common memory aid bottom-up is 'Please Do Not Throw Sausage Pizza Away'; top-down, 'All People Seem To Need Data Processing'. Layer 1 moves raw bits as electrical, light or radio signals over cables, connectors and airwaves. Layer 2 frames those bits for delivery on the local segment using MAC (Media Access Control) addresses, and it detects corruption with a frame check sequence (FCS). Layer 3 gives logical, routable addresses (IPv4 and IPv6) and chooses paths between networks. Layer 4 provides end-to-end delivery between applications using port numbers, with TCP (Transmission Control Protocol) for reliable, ordered delivery or UDP (User Datagram Protocol) for lightweight, connectionless delivery.
The upper layers are often blurred together in practice, and the TCP/IP model merges them into a single Application layer. Layer 5, Session, sets up, maintains and tears down conversations between applications, such as keeping track of which request belongs to which dialogue. Layer 6, Presentation, handles data formatting, character encoding, compression and encryption, which is why TLS is sometimes placed here. Layer 7, Application, is the network-facing interface that programs use: HTTP, DNS, SMTP, SSH and similar protocols. Layer 7 does not mean the application itself, such as the web browser; it means the protocol the browser speaks.
As data travels down the stack on the sender, each layer adds its own header (and Layer 2 also adds a trailer, the FCS). This is encapsulation; the receiver strips headers in reverse order, which is de-encapsulation. The name for the chunk of data at each layer is its protocol data unit (PDU). Layers 5 to 7 simply call it data. Layer 4 produces a segment for TCP (a UDP unit is usually called a datagram). Layer 3 produces a packet. Layer 2 produces a frame. Layer 1 transmits bits. A useful detail: as a packet crosses routers, the Layer 2 frame is rebuilt on every hop with new source and destination MAC addresses, while the Layer 3 source and destination IP addresses stay the same end to end (unless NAT changes them).
Walk through a real request to see it. You type a web address and press Enter. The browser builds an HTTP request (Layer 7 data), TLS encrypts it (Layer 6), and TCP wraps it in a segment with source port 51544 and destination port 443 (Layer 4). IP adds a packet header with your address and the server's address (Layer 3). Ethernet adds a frame header with your MAC and your default gateway's MAC, plus the FCS trailer (Layer 2). The network card turns the frame into electrical signals on the cable (Layer 1). The switch reads only the frame header; the router reads the packet header, picks the next hop and builds a new frame; the server unwraps everything in reverse. In Wireshark each captured packet shows exactly these sections stacked: Ethernet II, Internet Protocol, Transmission Control Protocol and then the application protocol.
Devices map to layers, and the exam likes these pairings. Hubs, repeaters, cables, patch panels and media converters are Layer 1: they just pass signals. Switches and bridges forward frames by MAC address at Layer 2; wireless access points also operate largely at Layer 2, bridging wireless frames onto the wired LAN. Routers forward packets by IP address at Layer 3, and a multilayer (Layer 3) switch can do both switching and routing. Load balancers, proxies and next-generation firewalls can inspect all the way up to Layer 7. A basic stateless packet filter works at Layers 3 and 4 because it reads addresses and ports.
Common mistakes: learners mix up segment and packet (segment is Layer 4, packet is Layer 3), assume a switch uses IP addresses (a plain switch does not), or think Layer 7 means the browser program. Another trap is putting ARP neatly in one layer; it resolves Layer 3 addresses to Layer 2 addresses, so it is usually described as working between Layers 2 and 3. The model is also your troubleshooting map. A bottom-up approach starts with link lights and cables, then MAC and VLAN, then IP addressing and routing, then ports and services. A top-down approach starts at the application.
Exam questions frame this topic in a few predictable ways. They name a device or protocol and ask its layer, name a PDU and ask the layer, or describe a symptom and ask which layer to investigate. Clue words help: 'bits', 'signal', 'cable', 'attenuation' point to Layer 1; 'MAC', 'frame', 'VLAN', 'switch' to Layer 2; 'IP', 'packet', 'route', 'subnet' to Layer 3; 'port', 'segment', 'reliable', 'connectionless' to Layer 4; 'encryption', 'encoding', 'compression' to Layer 6; and named application protocols such as HTTP or DNS to Layer 7.
Key terms
- PDU
- Protocol data unit: the name for the chunk of data at a given layer (bits, frame, packet, segment or datagram, data).
- Encapsulation
- The process of each layer adding its header (and at Layer 2, a trailer) to the data it receives from the layer above.
- De-encapsulation
- The receiver removing each layer's header in reverse order to recover the original data.
- MAC address
- A 48-bit hardware address used at Layer 2 to deliver frames on the local network segment.
- Frame check sequence
- The Layer 2 trailer field containing a CRC value that the receiver uses to detect corrupted frames.
- TCP/IP model
- The four-layer model the internet actually uses (Link, Internet, Transport, Application), which merges OSI Layers 5 to 7 into one.
A user cannot reach an internal web site. You check the switch port and see the link light on and no interface errors, so Layer 1 looks fine. You confirm the PC is in the correct VLAN and its MAC address appears on the right port (Layer 2), then ping the server's IP successfully (Layer 3). Finally you run a port test and find nothing is listening on TCP 443, so the fault is the web service itself at Layers 4 to 7. Working methodically through the layers took you straight to the server team instead of wasting time on cables.
Check yourself
As a packet crosses three routers to reach a server, which addresses change at each hop and which stay the same?
The Layer 2 source and destination MAC addresses change on every hop because each router builds a new frame; the Layer 3 source and destination IP addresses stay the same (unless NAT is involved).
A technician finds that CRC errors are climbing on a switch port. Which OSI layer is most likely at fault and why?
Layers 1 and 2. The CRC is checked against the Layer 2 frame check sequence, and failures usually come from physical problems such as a damaged cable, interference or a duplex mismatch.
A firewall blocks traffic based only on source IP and destination port. Up to which OSI layer is it inspecting?
Layer 4. IP addresses are Layer 3 and port numbers are Layer 4; it is not reading application content at Layer 7.
Why is TLS sometimes described as a Layer 6 function even though it runs over TCP?
Because it encrypts and formats data for the application, which is the Presentation layer's job in the OSI model; the model is a reference, so real protocols do not always fit one layer.