In The OSI Model, you learned about seven layers. OSI is a useful way to talk aboutnetworking, but it is not what your laptop actually runs. Your laptop, your phone, every web server and the whole internet run the TCP/IP protocol suite, which is described by a simpler model with just four layers. By the end of this lesson, you should be able to:
- Name the four TCP/IP layers and say what each one does.
- Place common protocols (HTTP, DNS, TCP, UDP, IP, Ethernet, Wi-Fi) in the right layer.
- Map each TCP/IP layer to the OSI layers it covers.
- Explain why TCP/IP, not OSI, is what really runs on networks.
💡 In simple terms: TCP/IP works like a postal service with four departments. One writes the letter (Application), one makes sure it reaches the right person in the house (Transport), one gets it to the right town and street (Internet), and one drives the van along each road (Network Access).
What is the TCP/IP model?
The TCP/IP model is a way of grouping the protocols of the internet into four layers. A protocol is a set of rules that two devices agree to follow, such as “ask for a web page like this” or “number each byte like this”. Each layer has one job and uses the services of the layer below it:
| # | TCP/IP layer | Its job in one line | PDU | Address used |
|---|---|---|---|---|
| 4 | Application | Provide the service the user wants | Data | Names, URLs |
| 3 | Transport | Deliver data to the right program | Segment / datagram | Ports |
| 2 | Internet | Get packets across networks | Packet | IP addresses |
| 1 | Network Access | Cross one link to the next device | Frame / bits | MAC addresses |
A PDU (protocol data unit) is the name for a piece of data at a given layer. Different books use different names for the bottom layer: Link (the name used in the internet's own standard, RFC 1122), Network Access or Network Interface. They all mean the same thing.
Notice the shape. There are many applications at the top and many types of link at the bottom, but only one protocol in the middle that everyone shares: IP. That narrow middle is the key to TCP/IP's success, as you will see below.
Why TCP/IP exists
In the late 1960s and 1970s, the US Department of Defense funded a research network called the ARPANET. Researchers wanted to connect many different networks (radio, satellite, leased lines), each built in its own way, into one larger network. That raised some difficult problems:
Different networks, one internet
Each network had its own hardware and addressing. IP added one shared addressing system on top of them all.
Links that lose data
Radio and long-distance links lost data. TCP made delivery reliable from end to end, so the network itself could stay simple.
No single point of failure
Packets are routed hop by hop, so if one path breaks, routers can send traffic another way.
Many programs, one connection
Port numbers let email, web and file transfer use the same host and the same link at the same time.
Vint Cerf and Bob Kahn designed the first version of TCP and IP in 1974. On 1 January 1983, the ARPANET switched over to TCP/IP, and that day is often called the birthday of the internet. The layers were later documented in RFC 1122 (1989). You may also see it called the DoD model, after the Department of Defense.
The four layers in detail
Each card below shows the layer's job, its PDU, the address it uses, its main protocols, the devices that work at that layer, and what the layer does when you open https://routelearn.net.
4Application layer
Also called: Process layer · Covers OSI layers 5, 6 and 7
Gives programs the network services they need: fetching a web page, looking up a name, sending an email or logging in to a remote server. It also handles data formats, encryption and sessions, which OSI splits into separate layers.
- PDU
- Data (often called a message)
- Address
- Names and URLs, e.g. https://routelearn.net
- Protocols
- HTTP, HTTPS (with TLS), DNS, DHCP, SMTP, IMAP, POP3, SSH, FTP, NTP, SNMP
- Devices
- Hosts: PCs, phones, servers. Some firewalls and proxies also read this layer.
- Real example
- Your browser builds the request “GET / HTTP/1.1, Host: routelearn.net”.
- Learn more
- HTTP: how the web talks
3Transport layer
Also called: Host-to-host layer · Covers OSI layer 4
Carries data between two programs, one on each host. Port numbers identify which program the data belongs to. TCP adds reliability: it numbers the bytes, waits for acknowledgements and resends anything that is lost. UDP skips all of that to stay fast and simple.
- PDU
- Segment (TCP) or datagram (UDP)
- Address
- Port numbers, e.g. 443 for HTTPS, 53 for DNS
- Protocols
- TCP, UDP, and QUIC (which runs on top of UDP)
- Devices
- Hosts. Firewalls and NAT routers also read port numbers, and NAT routers sometimes change them.
- Real example
- TCP sends data from port 51524 on your laptop to port 443 on the server.
- Learn more
- What the transport layer does
2Internet layer
Also called: Network layer · Covers OSI layer 3
Moves packets from the source host to the destination host, even when the two hosts are on different networks far apart. Every packet carries a source and a destination IP address, and each router uses the destination address to choose the next hop.
- PDU
- Packet
- Address
- IP addresses, e.g. 192.168.1.20 and 203.0.113.20
- Protocols
- IPv4, IPv6, ICMP (used by ping and traceroute)
- Devices
- Routers, Layer 3 switches, firewalls and every host
- Real example
- The packet leaves with source 192.168.1.20 and destination 203.0.113.20.
- Learn more
- What is an IP address?
1Network Access layer
Also called: Link layer, or Network Interface layer · Covers OSI layers 1 and 2
Gets the packet across one physical link to the next device: from your laptop to the router, or from one router to the next. It puts the packet in a frame with hardware (MAC) addresses, then sends it as signals over copper, fibre or radio.
- PDU
- Frame, then bits on the wire
- Address
- MAC addresses, e.g. 02:00:00:00:00:aa
- Protocols
- Ethernet, Wi-Fi (802.11), ARP, PPP, DSL, cable, fibre, 4G/5G
- Devices
- Switches, wireless access points, network cards (NICs), cables, modems
- Real example
- Wi-Fi puts the packet in a frame addressed to the home router's MAC address.
- Learn more
- Ethernet fundamentals
Application layer: more than one OSI layer
In OSI, the Session (5), Presentation (6) and Application (7) layers are separate. TCP/IP combines all three into one Application layer, because in practice the same program does all three jobs. For example, a web browser formats the request (presentation), encrypts it with TLS (presentation and session) and sends it using HTTP (application), all by itself. There is no separate "session header" in the packet. HTTPS and DNS are two important application protocols to study next.
Learn more: HTTPS and TLSDNS
Transport layer: TCP or UDP
The application chooses which transport protocol to use. Both TCP and UDP use port numbers. The difference is how much care they take with delivery:
| TCP | UDP | |
|---|---|---|
| Connection | Sets one up first (three-way handshake) | None: it just sends |
| Reliability | Acknowledges data and resends lost data | UDP itself does not resend anything |
| Order | Delivers bytes in order | Datagrams may arrive out of order |
| Header size | 20 bytes or more | 8 bytes |
| Used by | Web (HTTP/1.1, HTTP/2), email, SSH, file transfer | DNS queries, DHCP, NTP, voice and video, QUIC (HTTP/3) |
Learn more: TCP vs. UDP ComparedPort Numbers and Sockets
Internet layer: the narrow waist
IP is the one protocol that every device on the internet must use. It gives every interface an IP address and moves packets hop by hop through routers. IP itself is best effort: it does its best to deliver each packet, but it does not guarantee delivery or order, and it does not prevent duplicates. Reliability is the job of TCP at the Transport layer. ICMP also works at this layer. It carries error and test messages, such as the replies to ping.
Network Access layer: one hop at a time
This layer only ever deals with one link: the cable or radio connection between two neighbouring devices. On Ethernet and Wi-Fi, it uses MAC addresses, and ARP finds the MAC address that belongs to a neighbour's IP address. Each router removes the frame and builds a new one, while the IP packet inside travels end to end. That idea is at the centre of the next lesson.
Learn more: Encapsulation and De-encapsulation
TCP/IP and OSI side by side
Both models describe the same journey, divided into a different number of layers. Use the toggle to switch between the four-layer model and the five-layer version that many courses use:
| OSI layer | TCP/IP layer (4-layer) | 5-layer version | Examples |
|---|---|---|---|
| 7 Application | Application | Application | HTTP, DNS, SMTP, SSH |
| 6 Presentation | TLS encryption, UTF-8, JPEG | ||
| 5 Session | Opening and resuming sessions | ||
| 4 Transport | Transport | Transport | TCP, UDP |
| 3 Network | Internet | Network | IPv4, IPv6, ICMP |
| 2 Data Link | Network Access | Data Link | Ethernet frames, Wi-Fi, MAC addresses |
| 1 Physical | Physical | Cables, fibre, radio signals |
Where the two models differ
| OSI model | TCP/IP model | |
|---|---|---|
| Number of layers | 7 | 4 (5 in some courses) |
| Where it came from | Designed by a standards body (ISO) as a reference | Documented after the protocols were built and working |
| Main use today | Shared vocabulary and troubleshooting | Describing the protocols that actually run |
| Session and presentation | Separate layers | Part of the application |
| Physical and data link | Separate layers | One Network Access layer |
| Its own protocols? | OSI protocols existed but are rarely used now | Yes: IP, TCP, UDP and the rest run everywhere |
Engineers mix the two models all the time. They say "layer 3" for IP and "layer 4" for TCP and UDP (OSI numbers), even when they are talking about TCP/IP protocols. When someone says "layer 7", they mean the application. You will rarely hear "TCP/IP layer 2".
Why TCP/IP is what really runs
In the 1980s, many people expected OSI's own protocols to replace TCP/IP. The opposite happened. Here's why:
- It already worked. TCP/IP was running on real networks while OSI protocols were still being designed on paper.
- It was free and open. Anyone could read the standards (the RFCs) for free, and a free implementation shipped with BSD Unix in 1983, so universities and companies could start using it immediately.
- It runs over any link. IP only asks the link below to "carry this packet to the next device", so TCP/IP runs over Ethernet, Wi-Fi, fibre, DSL, cable and mobile networks. New link types simply plug in at the bottom.
- Applications can change without changing the network. New applications (the web in 1991, video streaming, online games) only had to use TCP or UDP. The routers in the middle did not need to change at all.
- Simple core, smart edges. Routers only forward packets; the two end hosts handle reliability. This kept routers cheap and fast, so the network could grow.
💡 Today, every device on the internet runs a TCP/IP stack: the part of the operating system that implements IP, TCP, UDP and related protocols. Windows, macOS, Linux, Android and iOS all include one.
How the four layers work together
When you send data, it goes down the four layers on your device. Each layer adds its own information (a header) in front of the data from the layer above. This wrapping is called encapsulation. The receiver takes the data up through the same four layers, removing one header at each step.
Each layer only reads the header written by the same layer on the other side. TCP on your laptop communicates with TCP on the server; it never looks at MAC addresses. This is called peer-layer communication, and it is why a change at one layer (for example, moving from Wi-Fi to a cable) does not break the others.
Which layers each device uses
Hosts use all four layers. Devices in the middle only go as far up the stack as they need to make their forwarding decision:
- 1. Laptop: all four layers. HTTP data, then a TCP header (ports), an IP header (IP addresses) and an Ethernet header (MAC addresses). The frame goes out as bits.
- 2. Switch: Network Access only. It reads the destination MAC address and forwards the frame out of the right port. It never looks at the IP packet.
- 3. Router: up to the Internet layer. It removes the frame, reads the destination IP address 203.0.113.20, chooses the next hop and puts the same packet in a new frame.
- 4. Server: all four layers. It removes each header in turn. TCP passes the data to the program on port 443, and the web server reads the HTTP request.
A real example: a DNS lookup through the layers
Your laptop (192.168.1.20) wants the IP address of routelearn.net. It asks a DNS server at 198.51.100.53. Here's what each layer adds to that one small question:
| Layer | Protocol | What it adds | Values in this example |
|---|---|---|---|
| Application | DNS | The question | "What is the A record for routelearn.net?" |
| Transport | UDP | Ports | Source port 50812 (random) → destination port 53 |
| Internet | IPv4 | IP addresses | 192.168.1.20 → 198.51.100.53, protocol 17 (UDP) |
| Network Access | Wi-Fi / Ethernet | MAC addresses | Laptop 02:00:00:00:00:aa → home router 02:00:00:00:00:01 |
The destination MAC address is the home router's, not the DNS server's, because the server is on another network. The frame only has to reach the default gateway; the IP header carries the final destination. Your home router also replaces the private source address with its public address (NAT) on the way out.
Learn more: Why NAT Exists
What happens when a layer fails
Each layer depends on the layer below it. If a lower layer fails, everything above it fails too. This is why the symptoms often look like an application problem, even when the cause is a cable.
| Layer that fails | Example cause | What the user sees |
|---|---|---|
| Network Access | Unplugged cable, weak Wi-Fi, wrong Wi-Fi password | "No internet", no IP address, nothing works at all |
| Internet | Wrong IP address, mask or default gateway; a router down | Local devices work, but other networks and the internet do not |
| Transport | Service not listening, port blocked by a firewall | Ping works, but the app says "connection refused" or times out |
| Application | DNS server down, expired certificate, wrong login | "Server not found", certificate warnings, error pages |
Troubleshooting with the TCP/IP layers
A simple method is to test from the bottom up: prove that the Network Access layer works, then the Internet layer, then the Transport layer, and finally the Application layer. These commands work on most Linux systems, and the table also shows the Windows equivalents:
| Layer | Linux command | Windows | What it shows |
|---|---|---|---|
| Network Access | ip -br link | ipconfig /all | Whether the interface is up; its MAC address |
| Internet | ip -br addr, ip route, ping | ipconfig, route print, ping | IP address, default gateway, reachability |
| Transport | ss -tn, nc -zv host 443 | netstat -n, Test-NetConnection -Port 443 | Open connections, ports, whether a service answers |
| Application | dig, curl -I | nslookup, the browser | DNS answers, web server responses |
$ ip -br link lo UNKNOWN 00:00:00:00:00:00 <LOOPBACK,UP,LOWER_UP> wlan0 UP 02:00:00:00:00:aa <BROADCAST,MULTICAST,UP,LOWER_UP>
wlan0 is UP, and LOWER_UP means the link itself is working (connected to Wi-Fi, or a cable with a link light). 02:00:00:00:00:aa is the MAC address the laptop puts in its frames as the source.$ ip route default via 192.168.1.1 dev wlan0 proto dhcp src 192.168.1.20 metric 600 192.168.1.0/24 dev wlan0 proto kernel scope link src 192.168.1.20 metric 600
192.168.1.20 on the local network 192.168.1.0/24. The default via line shows that traffic for every other network goes to the default gateway, 192.168.1.1. If there is no default line, the laptop can't reach the internet, even if the Wi-Fi link is fine.$ ss -tn State Recv-Q Send-Q Local Address:Port Peer Address:Port Process ESTAB 0 0 192.168.1.20:51524 203.0.113.20:443 ESTAB 0 0 192.168.1.20:40312 198.51.100.25:22
ESTAB (established) state. The first is to a web server on port 443 (HTTPS), and the second is to an SSH server on port 22. The local ports 51524 and 40312 are temporary ports that the laptop chose. The IP address and port at each end together form a socket pair.Learn more: Essential Linux Network CommandsEssential Windows Network CommandsBottom-Up, Top-Down, Divide and Conquer
Common mistakes
- Thinking TCP/IP means only TCP and IP. It is a whole suite of protocols: UDP, ICMP, ARP, DNS, DHCP and HTTP are all part of it.
- Mixing up the layer names. TCP/IP's "Internet" layer is OSI's "Network" layer. TCP/IP's "Network Access" layer is OSI layers 1 and 2, not OSI layer 3.
- Using TCP/IP layer numbers when people expect OSI numbers. "Layer 3" almost always means IP (OSI numbering), not the TCP/IP Transport layer.
- Putting DNS or DHCP at the Transport layer. They use UDP (and DNS also uses TCP), but they are Application-layer protocols.
- Thinking IP guarantees delivery. IP is best effort. Reliability comes from TCP, or from the application when it uses UDP.
- Forgetting that the bottom layer changes at every hop. Each router builds a new frame with new MAC addresses; the IP packet inside travels end to end.
- The TCP/IP model has four layers: Application, Transport, Internet and Network Access (also called Link).
- Application: the service (HTTP, DNS). Transport: the program, by port (TCP, UDP). Internet: the host, by IP address. Network Access: the next hop, by MAC address.
- Application covers OSI layers 5 to 7, Network Access covers OSI layers 1 and 2, and Transport and Internet match OSI layers 4 and 3.
- IP is the narrow waist: any application can run above it, and any link below it.
- TCP/IP succeeded because it worked first, was free and open, and runs over any link.
- Engineers usually describe TCP/IP protocols using OSI layer numbers.
Knowledge check
Your laptop is running a web browser and an email program at the same time. Which TCP/IP layer makes sure each reply reaches the right program?
A browser formats a request, encrypts it with TLS and sends it with HTTP. OSI calls these the Presentation, Session and Application jobs. Which TCP/IP layer covers all three?
A router receives a frame. What is the highest TCP/IP layer it needs to read to forward the packet?
Your laptop's Wi-Fi shows as connected, but the output of "ip route" has no default line. Which layer has the problem?
A colleague says: "If a packet is lost on the way, IP will send it again." Which statement about IP is actually true?
Where to go next
Next, watch every header being added and removed, with real addresses and ports. To study each layer in more detail, start with Ethernet (Network Access), IP addressing (Internet), the transport layer (Transport) and HTTP (Application).
Learn more: Encapsulation and De-encapsulationEthernet FundamentalsWhat Is an IP Address?What the Transport Layer DoesHTTP: How the Web Talks