A situation
You are on a video call. In another tab, a web page is loading, and your mail app is checking for new messages. All of this traffic arrives at the same laptop, with the same IP address. How does the laptop know which bytes belong to the call, which to the browser and which to the mail app?
IP cannot answer that question, because an IP address only identifies a device. The answer comes from the layer above IP: the transport layer, Layer 4 of the OSI model.
What it is
The transport layer moves data between two applications, not just two devices. It has two main protocols:
- TCP (Transmission Control Protocol): careful and reliable. It sets up a connection first, numbers every byte and resends anything that gets lost.
- UDP (User Datagram Protocol): simple and lightweight. It sends each message on its own and does not check whether it arrived.
A chunk of data plus a TCP header is called a segment. A chunk of data plus a UDP header is called a datagram. Either one then goes inside an IP packet, which goes inside a frame, such as an Ethernet frame. This wrapping is called encapsulation.
- 1. Web page data arrives for the browser. Its destination port tells the laptop to pass it to the browser.
- 2. Mail data arrives with a different destination port, so it goes to the mail app.
- 3. Video call audio arrives over UDP, with its own port. One IP address, three separate conversations.
The jobs of Layer 4
| Job | What it means | TCP | UDP |
|---|---|---|---|
| Multiplexing | Many applications share one IP address; port numbers keep them apart | Yes | Yes |
| Segmentation | Large data is split into pieces that fit in packets | Yes | No (the application keeps its messages small enough) |
| Connection setup | Both sides agree to communicate before data is sent | Yes (handshake) | No |
| Reliable delivery | Lost data is noticed and sent again | Yes | No |
| Ordering | Data is passed to the application in the order it was sent | Yes | No |
| Flow control | The sender slows down when the receiver cannot keep up | Yes (windowing) | No |
Multiplexing means many conversations share one path. The sending side combines them; the receiving side uses the port numbers to separate them again (demultiplexing).
Why it works this way
IP is best effort: it tries to deliver each packet, but it makes no promises. Packets can be lost, arrive twice or arrive in the wrong order, and IP does not resend them. Some applications cannot accept that: a downloaded file with one missing byte is broken. So TCP adds reliability on top of IP.
Other applications care more about speed than about every byte. In a voice call, sound that arrives half a second late is useless, so it is better to skip it and carry on. For these applications, the extra work of TCP only gets in the way, so they use UDP. Having both protocols lets each application pick the trade-off it needs.
💡 In simple terms: TCP is like a phone call. You both confirm that you are connected, and you ask the other person to repeat anything you missed. UDP is like a postcard: you send it and move on.
How to see it
You can see the transport layer at work on any computer. The netstat and ss commands list your open connections. Each line shows a protocol (TCP or UDP), a local address and port, and a remote address and port. On a Cisco router, show control-plane host open-ports lists the TCP and UDP ports the router itself is listening on.
Learn more: Viewing Connections on Your Computer
Check yourself
Your laptop receives two packets with the same destination IP address: one for the browser and one for the mail app. How does it know which application each belongs to?
In a packet capture, you look at a piece of application data with a TCP header in front of it. What is this unit called?
A DNS client and a voice app on the same PC both use UDP at the same time. Which transport layer job does UDP still do for them?