Routelearn.net
Course menu

Unit 3: Network ModelsLesson 3.2 (2 of 3 in this unit)14 of 84 in the Network Fundamentals course

The TCP/IP Model

Learn the four-layer model that describes how the internet really works: what the Application, Transport, Internet and Network Access layers each do, which protocols work at each layer, and how the model lines up with the OSI model.

Beginner · 16 min read · Before this: The OSI model

The TCP/IP model is the four-layer model of the internet protocol suite: the Application, Transport, Internet and Network Access layers. Each layer has its own job and protocols, such as HTTP, TCP, IP and Ethernet, and provides a service to the layer above it.

In simple terms: It splits the job of sending data across a network into four layers. Each layer handles one part of the job, from the app you use down to the cable or Wi-Fi.

In The OSI Model, you learned about seven layers. OSI is a useful way to talk aboutnetworking, but it is not what your laptop actually runs. Your laptop, your phone, every web server and the whole internet run the TCP/IP protocol suite, which is described by a simpler model with just four layers. By the end of this lesson, you should be able to:

  • Name the four TCP/IP layers and say what each one does.
  • Place common protocols (HTTP, DNS, TCP, UDP, IP, Ethernet, Wi-Fi) in the right layer.
  • Map each TCP/IP layer to the OSI layers it covers.
  • Explain why TCP/IP, not OSI, is what really runs on networks.

💡 In simple terms: TCP/IP works like a postal service with four departments. One writes the letter (Application), one makes sure it reaches the right person in the house (Transport), one gets it to the right town and street (Internet), and one drives the van along each road (Network Access).

What is the TCP/IP model?

The TCP/IP model is a way of grouping the protocols of the internet into four layers. A protocol is a set of rules that two devices agree to follow, such as “ask for a web page like this” or “number each byte like this”. Each layer has one job and uses the services of the layer below it:

#TCP/IP layerIts job in one linePDUAddress used
4ApplicationProvide the service the user wantsDataNames, URLs
3TransportDeliver data to the right programSegment / datagramPorts
2InternetGet packets across networksPacketIP addresses
1Network AccessCross one link to the next deviceFrame / bitsMAC addresses

A PDU (protocol data unit) is the name for a piece of data at a given layer. Different books use different names for the bottom layer: Link (the name used in the internet's own standard, RFC 1122), Network Access or Network Interface. They all mean the same thing.

ApplicationOSI 5–7
PDU: Data / message · Address: Names, URLs
HTTPHTTPS/TLSDNSDHCPSMTPIMAPSSHFTPNTPSNMP
TransportOSI 4
PDU: Segment / datagram · Address: Port numbers
TCPUDPQUIC (over UDP)
InternetOSI 3
PDU: Packet · Address: IP addresses
IPv4IPv6ICMP
Network AccessOSI 1–2
PDU: Frame / bits · Address: MAC addresses
EthernetWi-FiARPFibreDSLCable4G/5G
The TCP/IP “hourglass”: many applications at the top and many kinds of link at the bottom, all joined by one narrow layer in the middle, IP.

Notice the shape. There are many applications at the top and many types of link at the bottom, but only one protocol in the middle that everyone shares: IP. That narrow middle is the key to TCP/IP's success, as you will see below.

Why TCP/IP exists

In the late 1960s and 1970s, the US Department of Defense funded a research network called the ARPANET. Researchers wanted to connect many different networks (radio, satellite, leased lines), each built in its own way, into one larger network. That raised some difficult problems:

Different networks, one internet

Each network had its own hardware and addressing. IP added one shared addressing system on top of them all.

Links that lose data

Radio and long-distance links lost data. TCP made delivery reliable from end to end, so the network itself could stay simple.

No single point of failure

Packets are routed hop by hop, so if one path breaks, routers can send traffic another way.

Many programs, one connection

Port numbers let email, web and file transfer use the same host and the same link at the same time.

Vint Cerf and Bob Kahn designed the first version of TCP and IP in 1974. On 1 January 1983, the ARPANET switched over to TCP/IP, and that day is often called the birthday of the internet. The layers were later documented in RFC 1122 (1989). You may also see it called the DoD model, after the Department of Defense.

The four layers in detail

Each card below shows the layer's job, its PDU, the address it uses, its main protocols, the devices that work at that layer, and what the layer does when you open https://routelearn.net.

4Application layer

Also called: Process layer · Covers OSI layers 5, 6 and 7

Gives programs the network services they need: fetching a web page, looking up a name, sending an email or logging in to a remote server. It also handles data formats, encryption and sessions, which OSI splits into separate layers.

PDU
Data (often called a message)
Address
Names and URLs, e.g. https://routelearn.net
Protocols
HTTP, HTTPS (with TLS), DNS, DHCP, SMTP, IMAP, POP3, SSH, FTP, NTP, SNMP
Devices
Hosts: PCs, phones, servers. Some firewalls and proxies also read this layer.
Real example
Your browser builds the request “GET / HTTP/1.1, Host: routelearn.net”.
Learn more
HTTP: how the web talks

3Transport layer

Also called: Host-to-host layer · Covers OSI layer 4

Carries data between two programs, one on each host. Port numbers identify which program the data belongs to. TCP adds reliability: it numbers the bytes, waits for acknowledgements and resends anything that is lost. UDP skips all of that to stay fast and simple.

PDU
Segment (TCP) or datagram (UDP)
Address
Port numbers, e.g. 443 for HTTPS, 53 for DNS
Protocols
TCP, UDP, and QUIC (which runs on top of UDP)
Devices
Hosts. Firewalls and NAT routers also read port numbers, and NAT routers sometimes change them.
Real example
TCP sends data from port 51524 on your laptop to port 443 on the server.
Learn more
What the transport layer does

2Internet layer

Also called: Network layer · Covers OSI layer 3

Moves packets from the source host to the destination host, even when the two hosts are on different networks far apart. Every packet carries a source and a destination IP address, and each router uses the destination address to choose the next hop.

PDU
Packet
Address
IP addresses, e.g. 192.168.1.20 and 203.0.113.20
Protocols
IPv4, IPv6, ICMP (used by ping and traceroute)
Devices
Routers, Layer 3 switches, firewalls and every host
Real example
The packet leaves with source 192.168.1.20 and destination 203.0.113.20.
Learn more
What is an IP address?

1Network Access layer

Also called: Link layer, or Network Interface layer · Covers OSI layers 1 and 2

Gets the packet across one physical link to the next device: from your laptop to the router, or from one router to the next. It puts the packet in a frame with hardware (MAC) addresses, then sends it as signals over copper, fibre or radio.

PDU
Frame, then bits on the wire
Address
MAC addresses, e.g. 02:00:00:00:00:aa
Protocols
Ethernet, Wi-Fi (802.11), ARP, PPP, DSL, cable, fibre, 4G/5G
Devices
Switches, wireless access points, network cards (NICs), cables, modems
Real example
Wi-Fi puts the packet in a frame addressed to the home router's MAC address.
Learn more
Ethernet fundamentals

Application layer: more than one OSI layer

In OSI, the Session (5), Presentation (6) and Application (7) layers are separate. TCP/IP combines all three into one Application layer, because in practice the same program does all three jobs. For example, a web browser formats the request (presentation), encrypts it with TLS (presentation and session) and sends it using HTTP (application), all by itself. There is no separate "session header" in the packet. HTTPS and DNS are two important application protocols to study next.

Learn more: HTTPS and TLSDNS

Transport layer: TCP or UDP

The application chooses which transport protocol to use. Both TCP and UDP use port numbers. The difference is how much care they take with delivery:

TCPUDP
ConnectionSets one up first (three-way handshake)None: it just sends
ReliabilityAcknowledges data and resends lost dataUDP itself does not resend anything
OrderDelivers bytes in orderDatagrams may arrive out of order
Header size20 bytes or more8 bytes
Used byWeb (HTTP/1.1, HTTP/2), email, SSH, file transferDNS queries, DHCP, NTP, voice and video, QUIC (HTTP/3)

Learn more: TCP vs. UDP ComparedPort Numbers and Sockets

Internet layer: the narrow waist

IP is the one protocol that every device on the internet must use. It gives every interface an IP address and moves packets hop by hop through routers. IP itself is best effort: it does its best to deliver each packet, but it does not guarantee delivery or order, and it does not prevent duplicates. Reliability is the job of TCP at the Transport layer. ICMP also works at this layer. It carries error and test messages, such as the replies to ping.

Network Access layer: one hop at a time

This layer only ever deals with one link: the cable or radio connection between two neighbouring devices. On Ethernet and Wi-Fi, it uses MAC addresses, and ARP finds the MAC address that belongs to a neighbour's IP address. Each router removes the frame and builds a new one, while the IP packet inside travels end to end. That idea is at the centre of the next lesson.

Learn more: Encapsulation and De-encapsulation

TCP/IP and OSI side by side

Both models describe the same journey, divided into a different number of layers. Use the toggle to switch between the four-layer model and the five-layer version that many courses use:

OSI ↔ TCP/IP (4-layer view)
7ApplicationHTTP, DNS, DHCP, SSH
6PresentationEncoding, compression, encryption
5SessionSetting up and ending sessions
4TransportTCP, UDP · ports
3NetworkIPv4, IPv6, ICMP · routers
2Data LinkEthernet, Wi-Fi · MAC · switches
1PhysicalCables, fibre, radio · bits
Application
Transport
Internet
Link / Network Access
The mapping is a teaching approximation, not an exact equivalence. Always check which model a diagram uses.
OSI layerTCP/IP layer (4-layer)5-layer versionExamples
7 ApplicationApplicationApplicationHTTP, DNS, SMTP, SSH
6 PresentationTLS encryption, UTF-8, JPEG
5 SessionOpening and resuming sessions
4 TransportTransportTransportTCP, UDP
3 NetworkInternetNetworkIPv4, IPv6, ICMP
2 Data LinkNetwork AccessData LinkEthernet frames, Wi-Fi, MAC addresses
1 PhysicalPhysicalCables, fibre, radio signals

Where the two models differ

OSI modelTCP/IP model
Number of layers74 (5 in some courses)
Where it came fromDesigned by a standards body (ISO) as a referenceDocumented after the protocols were built and working
Main use todayShared vocabulary and troubleshootingDescribing the protocols that actually run
Session and presentationSeparate layersPart of the application
Physical and data linkSeparate layersOne Network Access layer
Its own protocols?OSI protocols existed but are rarely used nowYes: IP, TCP, UDP and the rest run everywhere

Engineers mix the two models all the time. They say "layer 3" for IP and "layer 4" for TCP and UDP (OSI numbers), even when they are talking about TCP/IP protocols. When someone says "layer 7", they mean the application. You will rarely hear "TCP/IP layer 2".

Why TCP/IP is what really runs

In the 1980s, many people expected OSI's own protocols to replace TCP/IP. The opposite happened. Here's why:

  1. It already worked. TCP/IP was running on real networks while OSI protocols were still being designed on paper.
  2. It was free and open. Anyone could read the standards (the RFCs) for free, and a free implementation shipped with BSD Unix in 1983, so universities and companies could start using it immediately.
  3. It runs over any link. IP only asks the link below to "carry this packet to the next device", so TCP/IP runs over Ethernet, Wi-Fi, fibre, DSL, cable and mobile networks. New link types simply plug in at the bottom.
  4. Applications can change without changing the network. New applications (the web in 1991, video streaming, online games) only had to use TCP or UDP. The routers in the middle did not need to change at all.
  5. Simple core, smart edges. Routers only forward packets; the two end hosts handle reliability. This kept routers cheap and fast, so the network could grow.

💡 Today, every device on the internet runs a TCP/IP stack: the part of the operating system that implements IP, TCP, UDP and related protocols. Windows, macOS, Linux, Android and iOS all include one.

How the four layers work together

When you send data, it goes down the four layers on your device. Each layer adds its own information (a header) in front of the data from the layer above. This wrapping is called encapsulation. The receiver takes the data up through the same four layers, removing one header at each step.

Application
HTTPS request for routelearn.net
Transport (TCP)
+ ports: 51524 → 443 = segment
Internet (IP)
+ IPs: 192.168.1.20 → 203.0.113.20 = packet
Network Access (Wi-Fi/Ethernet)
+ MACs: laptop → home router = frame
Signals on the link
radio waves or electrical pulses (bits)
Down the stack on the sender. The receiver reverses the order.

Each layer only reads the header written by the same layer on the other side. TCP on your laptop communicates with TCP on the server; it never looks at MAC addresses. This is called peer-layer communication, and it is why a change at one layer (for example, moving from Wi-Fi to a cable) does not break the others.

Which layers each device uses

Hosts use all four layers. Devices in the middle only go as far up the stack as they need to make their forwarding decision:

Laptopall 4 layersSwitchNetwork AccessRouterup to InternetInternetmore routersWeb serverall 4 layers
  1. 1. Laptop: all four layers. HTTP data, then a TCP header (ports), an IP header (IP addresses) and an Ethernet header (MAC addresses). The frame goes out as bits.
  2. 2. Switch: Network Access only. It reads the destination MAC address and forwards the frame out of the right port. It never looks at the IP packet.
  3. 3. Router: up to the Internet layer. It removes the frame, reads the destination IP address 203.0.113.20, chooses the next hop and puts the same packet in a new frame.
  4. 4. Server: all four layers. It removes each header in turn. TCP passes the data to the program on port 443, and the web server reads the HTTP request.
Switches stop at the Network Access layer and routers at the Internet layer. Only the two hosts use the Transport and Application layers.

A real example: a DNS lookup through the layers

Your laptop (192.168.1.20) wants the IP address of routelearn.net. It asks a DNS server at 198.51.100.53. Here's what each layer adds to that one small question:

LayerProtocolWhat it addsValues in this example
ApplicationDNSThe question"What is the A record for routelearn.net?"
TransportUDPPortsSource port 50812 (random) → destination port 53
InternetIPv4IP addresses192.168.1.20 → 198.51.100.53, protocol 17 (UDP)
Network AccessWi-Fi / EthernetMAC addressesLaptop 02:00:00:00:00:aa → home router 02:00:00:00:00:01

The destination MAC address is the home router's, not the DNS server's, because the server is on another network. The frame only has to reach the default gateway; the IP header carries the final destination. Your home router also replaces the private source address with its public address (NAT) on the way out.

Learn more: Why NAT Exists

Step 1 of 4 · DNS query
Laptop
192.168.1.20
Home router
192.168.1.1
DNS server
198.51.100.53
One DNS question, four layers: DNS asks the question, UDP addresses the program, IP addresses the host, and the link carries it one hop at a time.

What happens when a layer fails

Each layer depends on the layer below it. If a lower layer fails, everything above it fails too. This is why the symptoms often look like an application problem, even when the cause is a cable.

Layer that failsExample causeWhat the user sees
Network AccessUnplugged cable, weak Wi-Fi, wrong Wi-Fi password"No internet", no IP address, nothing works at all
InternetWrong IP address, mask or default gateway; a router downLocal devices work, but other networks and the internet do not
TransportService not listening, port blocked by a firewallPing works, but the app says "connection refused" or times out
ApplicationDNS server down, expired certificate, wrong login"Server not found", certificate warnings, error pages

Troubleshooting with the TCP/IP layers

A simple method is to test from the bottom up: prove that the Network Access layer works, then the Internet layer, then the Transport layer, and finally the Application layer. These commands work on most Linux systems, and the table also shows the Windows equivalents:

LayerLinux commandWindowsWhat it shows
Network Accessip -br linkipconfig /allWhether the interface is up; its MAC address
Internetip -br addr, ip route, pingipconfig, route print, pingIP address, default gateway, reachability
Transportss -tn, nc -zv host 443netstat -n, Test-NetConnection -Port 443Open connections, ports, whether a service answers
Applicationdig, curl -Inslookup, the browserDNS answers, web server responses
Example output from a Linux laptop, written for this lesson
$ ip -br link
lo               UNKNOWN        00:00:00:00:00:00 <LOOPBACK,UP,LOWER_UP>
wlan0            UP             02:00:00:00:00:aa <BROADCAST,MULTICAST,UP,LOWER_UP>
Network Access layer. What to look for: wlan0 is UP, and LOWER_UP means the link itself is working (connected to Wi-Fi, or a cable with a link light). 02:00:00:00:00:aa is the MAC address the laptop puts in its frames as the source.
Example output from a Linux laptop, written for this lesson
$ ip route
default via 192.168.1.1 dev wlan0 proto dhcp src 192.168.1.20 metric 600
192.168.1.0/24 dev wlan0 proto kernel scope link src 192.168.1.20 metric 600
Internet layer. What to look for: the laptop's IP address is 192.168.1.20 on the local network 192.168.1.0/24. The default via line shows that traffic for every other network goes to the default gateway, 192.168.1.1. If there is no default line, the laptop can't reach the internet, even if the Wi-Fi link is fine.
Example output from a Linux laptop, written for this lesson (documentation addresses)
$ ss -tn
State   Recv-Q   Send-Q     Local Address:Port        Peer Address:Port   Process
ESTAB   0        0           192.168.1.20:51524       203.0.113.20:443
ESTAB   0        0           192.168.1.20:40312      198.51.100.25:22
Transport layer. What to look for: two open TCP connections in the ESTAB (established) state. The first is to a web server on port 443 (HTTPS), and the second is to an SSH server on port 22. The local ports 51524 and 40312 are temporary ports that the laptop chose. The IP address and port at each end together form a socket pair.

Learn more: Essential Linux Network CommandsEssential Windows Network CommandsBottom-Up, Top-Down, Divide and Conquer

Common mistakes

  • Thinking TCP/IP means only TCP and IP. It is a whole suite of protocols: UDP, ICMP, ARP, DNS, DHCP and HTTP are all part of it.
  • Mixing up the layer names. TCP/IP's "Internet" layer is OSI's "Network" layer. TCP/IP's "Network Access" layer is OSI layers 1 and 2, not OSI layer 3.
  • Using TCP/IP layer numbers when people expect OSI numbers. "Layer 3" almost always means IP (OSI numbering), not the TCP/IP Transport layer.
  • Putting DNS or DHCP at the Transport layer. They use UDP (and DNS also uses TCP), but they are Application-layer protocols.
  • Thinking IP guarantees delivery. IP is best effort. Reliability comes from TCP, or from the application when it uses UDP.
  • Forgetting that the bottom layer changes at every hop. Each router builds a new frame with new MAC addresses; the IP packet inside travels end to end.
✅ Key takeaways
  • The TCP/IP model has four layers: Application, Transport, Internet and Network Access (also called Link).
  • Application: the service (HTTP, DNS). Transport: the program, by port (TCP, UDP). Internet: the host, by IP address. Network Access: the next hop, by MAC address.
  • Application covers OSI layers 5 to 7, Network Access covers OSI layers 1 and 2, and Transport and Internet match OSI layers 4 and 3.
  • IP is the narrow waist: any application can run above it, and any link below it.
  • TCP/IP succeeded because it worked first, was free and open, and runs over any link.
  • Engineers usually describe TCP/IP protocols using OSI layer numbers.

Knowledge check

Predict · scenario 1

Your laptop is running a web browser and an email program at the same time. Which TCP/IP layer makes sure each reply reaches the right program?

Predict · scenario 2

A browser formats a request, encrypts it with TLS and sends it with HTTP. OSI calls these the Presentation, Session and Application jobs. Which TCP/IP layer covers all three?

Predict · scenario 3

A router receives a frame. What is the highest TCP/IP layer it needs to read to forward the packet?

Predict · scenario 4

Your laptop's Wi-Fi shows as connected, but the output of "ip route" has no default line. Which layer has the problem?

Predict · scenario 5

A colleague says: "If a packet is lost on the way, IP will send it again." Which statement about IP is actually true?

Where to go next

Next, watch every header being added and removed, with real addresses and ports. To study each layer in more detail, start with Ethernet (Network Access), IP addressing (Internet), the transport layer (Transport) and HTTP (Application).

Learn more: Encapsulation and De-encapsulationEthernet FundamentalsWhat Is an IP Address?What the Transport Layer DoesHTTP: How the Web Talks

FAQ

Is the TCP/IP model the same as the TCP/IP protocol suite?
Not quite. The protocol suite is the actual set of protocols (IP, TCP, UDP, DNS, HTTP and many more). The TCP/IP model is a four-layer way of grouping those protocols by the job they do.
Does TCP/IP only mean TCP and IP?
No. The name comes from its two best-known protocols, but the suite includes UDP, ICMP, ARP, DNS, DHCP, HTTP and hundreds of others. Traffic that uses UDP instead of TCP is still TCP/IP traffic.
Should I learn OSI or TCP/IP?
Both. Engineers use OSI layer numbers to talk about problems (“a layer 2 issue”), while TCP/IP describes the protocols that actually run. Knowing how the two line up lets you use either one.
Where does ARP fit in the TCP/IP model?
ARP is usually placed in the Network Access (Link) layer, because it never leaves the local network and is carried directly inside an Ethernet frame. It exists to serve the Internet layer, though, so you will also see it drawn on the line between the two.