The OSI Model and TCP/IP: What Layers Actually Mean
Enterprise Network Engineer · Module 1: Networking Fundamentals
Lesson 5 of 8
Prerequisites: What Is a Network, Really?, How Computers Talk: Packets, Frames, and Addresses, Your First Lab: Ping, Traceroute, and Reading Output
What you'll be able to do: Point at any network problem and name the exact layer to investigate first — and prove it from the evidence.
Imagine a seven-story mail-sorting building. Every parcel that arrives climbs to the top floor, and each floor does exactly one job: one floor checks the street address, another decides which truck it rides, another opens the box and checks nothing broke in transit, another hands the letter to the right person at the right desk. Nobody on any floor does anyone else's job — and that division is the whole secret of how big systems get fixed fast. When a package goes missing, you don't search the entire building. You ask which floor handles the step where it vanished — and you walk straight there. Computer networks work the same way, and the floors have names you will use for the rest of your career.
Here's the puzzle.
Scenario. You're the on-call tech at a small company on a Monday morning. Three users report three different problems within thirty minutes, and the help desk hands you three exhibits — a light report, an address listing, and a short capture. The boss wants one thing: for each symptom, which floor of the building is broken, and what single line proves it.
Given artifacts. The office network (hover any device for details):
The three exhibits:
Exhibit A — Monday 8:02 AM, Alice's desk (PC-A)
Alice's screen: "Network cable unplugged."
SW-1 link lights: Port 1 (PC-A): OFF · Port 2 (PC-B): ON · Port 3 (PC-C): ON · Port 24 (uplink): ON
Exhibit B — Monday 8:15 AM, Bob's desk (PC-B)
PC-B: address 192.168.2.50, mask 255.255.255.0, gateway 192.168.1.1
PC-C: address 192.168.1.75, mask 255.255.255.0, gateway 192.168.1.1
R-1 LAN: address 192.168.1.1, mask 255.255.255.0
Bob: "My cable is plugged in and the light is on, but I can't reach anyone — not even the printer."
Exhibit C — Monday 8:31 AM, Carol's desk (PC-C), short capture on the office LAN
1 0.000 192.168.1.75 → 192.168.1.10 TCP [SYN] Seq=0 (Carol knocks)
2 0.001 192.168.1.10 → 192.168.1.75 TCP [RST, ACK] (server slams the door)
Carol: "The server answers my knock by slamming the door."
Your task: For each of the three symptoms (A, B, C), write down (1) the layer number (1–7) where the fault lives, and (2) the single exhibit line that proves it. Three symptoms → three layer numbers + three quoted lines.
Workspace: Analyze-and-answer — type your three answers below (e.g. A → Layer __, proof: "..."), then check the commitment box to reveal the worked answer.
Hint 1 — where to look
Each symptom leaves its footprint in a different kind of place — a light, a number, a packet. Before thinking about layer numbers, sort the three exhibits by what kind of thing is broken in each.Hint 2 — what to compare
Alice's problem shows up before addresses are even involved. Bob's cable and lights are fine — compare his numbers against Carol's and the router's, digit by digit. Carol's numbers are fine — so watch what the server does with her knock instead of what she sent.Hint 3 — the mechanism
Troubleshooting climbs a ladder from the bottom: first the physical path, then the addresses, then the conversations between programs. The three symptoms sit on three different rungs of that ladder — the challenge wants the rung number for each.☐ I've attempted this challenge and thought it through. (Checking reveals the worked answer in S7 — honor system: the page hides it until you commit.)
Checking the box reveals the worked answer in S7 below. Returning learners stay unlocked.
The seven floors, one job each
The OSI model (a standard map that splits all of networking into seven stacked jobs, so engineers everywhere mean the same thing by "layer 3") reads top to bottom like this — each floor does exactly one job and trusts the floors below it:
- Layer 7 — Application: the program's own data. A web page, an email, a file. This floor belongs to the software, not the network.
- Layer 6 — Presentation: translating and protecting the data — turning it into an agreed format, scrambling it so snoopers can't read it.
- Layer 5 — Session: managing the conversation itself — who talks when, and how to resume if it drops.
- Layer 4 — Transport: chopping data into pieces, numbering them, and making sure every piece arrives (or admitting it didn't). This is also where the port lives — the number that says which program on the computer should get the data (you met ports in Lesson 1.2; think of them as apartment numbers inside one street address).
- Layer 3 — Network: addressing and finding paths between networks. The IP address lives here, and so does the decision of which road a packet takes.
- Layer 2 — Data Link: delivering between machines that are directly connected — same cable, same switch. The hardware (MAC) address lives here, and so does the frame (the envelope that carries a packet across one hop, from Lesson 1.2).
- Layer 1 — Physical: raw bits as signals — electricity on copper, light in fiber, radio waves in the air. Cables, plugs, and link lights.
Why this matters for the challenge: the three Monday-morning symptoms each break on a different floor. You'll match them in the worked answer — for now, just notice how different a dead light looks from a wrong number.
The four-floor version engineers actually use
Nobody troubleshoots with all seven floors every day. Working engineers use the simpler TCP/IP model (the practical four-layer map the real internet was built on), which merges some floors:
| TCP/IP layer | Covers OSI layers | One-job summary |
|---|---|---|
| Application | 5, 6, 7 | The program's data and conversations |
| Transport | 4 | Pieces, numbering, ports, reliability |
| Internet | 3 | Addresses and paths between networks |
| Link | 1, 2 | Signals on the wire + neighbor delivery |
When someone says "that's a layer 3 problem," they mean the Internet layer — addressing and paths. When they say "layer 2," they mean the local link — the switch, the cable, the hardware addresses. You'll hear both models; they describe the same building, one with seven floors and one with four.
Why this matters for the challenge: your answers only need the seven-floor numbers, but the four-floor map is what you'll actually use on the job — learn to translate between them now.
Down the stack: wrapping. Up the stack: unwrapping.
Encapsulation (wrapping each message in layer after layer of envelopes, which you built by hand in Lesson 1.2) is the floors doing their jobs in order. On the sending computer, the message starts at the top and travels down: the Transport floor adds its header (ports, piece numbers) making a segment (a chopped-up piece of the conversation with a transport header); the Network floor adds its header (source and destination IP addresses) making a packet; the Data Link floor adds its header (hardware addresses) making a frame; the Physical floor turns it all into signals.
On the receiving computer the journey runs in reverse — up the stack. Each floor reads only its own header, strips it off, and hands what's left upward. The Transport floor never looks at IP addresses; the Network floor never looks at ports. That strict "read only your own envelope" rule is what makes the whole system debuggable: any header in a capture belongs to exactly one floor.
Why this matters for the challenge: when you read a capture line, the field names tell you which floor you're standing on — IP addresses mean floor 3, port numbers mean floor 4.
The troubleshooting ladder: always start at the bottom
Here's the working rule that turns the model into a tool: check from the bottom up, and never blame a high floor until the low floors are proven healthy. The intuition, floor by floor:
- Floor 1 broken (cable unplugged, dead port, no light): nothing can work, and no address or program setting will fix it. Symptom: total silence.
- Floor 2 broken (wrong cable type, switch port misbehaving): neighbors can't reach each other even though everything is plugged in.
- Floor 3 broken (wrong IP address, wrong subnet, missing gateway): the machine is on the wire but has the wrong "street address" — it can't be found, or it can't find the way out. Routing (choosing the path a packet takes between networks) lives here too.
- Floor 4 broken (the conversation itself rejected): addresses are correct and the path works, but the two programs can't agree — a refused connection, a reset.
- Floors 5–7 broken: the network delivered everything perfectly and the program itself is misbehaving — a login failure, a corrupt file.
Notice the pattern: each floor's symptoms assume the floors below it work. That's what makes the ladder powerful — you climb until the symptoms stop matching, and the fault is on the rung where they start.
Why this matters for the challenge: you'll climb this exact ladder three times in the worked answer (S7) — once per symptom.
Layers vs. protocols: the table
A protocol (an agreed set of rules for doing one specific job — like the rules of a handshake) lives on exactly one floor. That's why "which protocol?" and "which layer?" are nearly the same question:
| Floor | Job | Example protocols |
|---|---|---|
| 7–5 | The program's business | Web pages, file sharing, login systems |
| 4 | Conversations between programs | TCP, UDP |
| 3 | Addresses and paths | IP, ICMP (ping's messenger, from Lesson 1.4) |
| 2 | Neighbor delivery | Ethernet, Wi-Fi |
| 1 | Signals | Copper, fiber, radio |
So "TCP" isn't a layer — it's a protocol that lives on layer 4. "IP" isn't a layer — it's a protocol on layer 3. Keeping that straight is half the battle: layers are the floors, protocols are the workers on each floor.
Why this matters for the challenge: the proof lines in the exhibits name protocols and fields (TCP, RST, addresses) — this table converts those names into floor numbers.
- Step 1 of 5: The message starts at the sender's top floor (Layer 7) — raw data, no wrappers yet.
- Step 2 of 5: Each floor down adds its own header (blue, green, amber, red bars). By Layer 1 the message wears four wrappers.
- Step 3 of 5: The fully wrapped frame crosses the wire as signals — the dashed line flows underneath it.
- Step 4 of 5: The receiver climbs back up; each floor strips only the header it understands.
- Step 5 of 5: The original message arrives at the top, wrappers gone — no floor ever read another floor's envelope.
One ping, seen at three layers
green = healthy/expected · red = problem packet(s) · amber = noteworthy, not faulty · untinted = context
| No | Time | Source | Destination | Protocol | Length | Info |
|---|---|---|---|---|---|---|
| 1 | 0.000 | 00:1a:2b:3c:4d:5e | ff:ff:ff:ff:ff:ff | ARP | 42 | Who has 192.168.1.20? Tell 192.168.1.10 |
| 2 | 0.001 | 00:9c:8d:7e:6f:5a | 00:1a:2b:3c:4d:5e | ARP | 42 | 192.168.1.20 is at 00:9c:8d:7e:6f:5a |
| 3 | 0.002 | 192.168.1.10 | 192.168.1.20 | ICMP | 74 | Echo request id=1 seq=1 |
| 4 | 0.003 | 192.168.1.20 | 192.168.1.10 | ICMP | 74 | Echo reply id=1 seq=1 |
| 5 | 0.010 | 192.168.1.10 | 192.168.1.20 | TCP | 66 | [SYN] Seq=0 Win=64240 |
Step 1 of 3 · packets 1, 2: Before any ping can fly, the sender must find its neighbor's hardware address. Packet 1 shouts the question to the whole LAN; packet 2 answers. Both live entirely on layer 2.
Step 2 of 3 · packets 3, 4: Now the echo request and reply. Look past the hardware addresses — the IP source and destination fields are the layer-3 wrappers doing their job.
Step 3 of 3 · packets 5: A new conversation knocks. The port numbers in this packet's header belong to layer 4 — the floor that manages conversations between programs.
| No | Time | Source | Destination | Protocol | Length | Info |
|---|---|---|---|---|---|---|
| 1 | 0.000 | 00:1a:2b:3c:4d:5e | ff:ff:ff:ff:ff:ff | ARP | 42 | Who has 192.168.1.20? Tell 192.168.1.10 |
| 2 | 0.001 | 00:9c:8d:7e:6f:5a | 00:1a:2b:3c:4d:5e | ARP | 42 | 192.168.1.20 is at 00:9c:8d:7e:6f:5a |
| 3 | 0.002 | 192.168.1.10 | 192.168.1.20 | ICMP | 74 | Echo request id=1 seq=1 |
| 4 | 0.003 | 192.168.1.20 | 192.168.1.10 | ICMP | 74 | Echo reply id=1 seq=1 |
| 5 | 0.010 | 192.168.1.10 | 192.168.1.20 | TCP | 66 | [SYN] Seq=0 Win=64240 |
Fixture: hand-authored to show how a single exchange touches layers 2, 3, and 4; no production data
🔒 Revealed after the commitment ritual in S2 — attempt the challenge first. (Honor system: the page hides this until you check the box.)
Climb the ladder once per symptom, bottom rung first.
Symptom A — Alice. Answer: Layer 1. Proof line: Port 1 (PC-A): OFF. The reasoning: her screen says "cable unplugged" and the switch agrees — the link light for her port is dark while every other port is lit. Nothing was ever transmitted, so no address or program setting is even in play yet. The fault is the physical path: a cut or unplugged cable, a dead wall jack, or a dead port.
Symptom B — Bob. Answer: Layer 3. Proof line: PC-B: address 192.168.2.50, mask 255.255.255.0. The reasoning: his cable and light are fine (floor 1 healthy, floor 2 presumably fine), so climb one rung. Compare the numbers digit by digit: Carol is 192.168.1.75, the router is 192.168.1.1, but Bob is 192.168.2.50 — he's in a different neighborhood (.2.x vs .1.x) while wearing a mask that says his neighborhood is .2.x. His packets leave with the wrong return address, so nothing routes back. The fault is addressing — floor 3.
Symptom C — Carol. Answer: Layer 4. Proof line: 2 0.001 192.168.1.10 → 192.168.1.75 TCP [RST, ACK]. The reasoning: her address is correct (floor 3 healthy — the knock reached the server, which proves the path works), but the server answers her SYN with RST — a reset, the network's way of saying "I hear you, and no." The path and addresses did their jobs; the conversation was refused. The fault is the program-to-program handshake — floor 4.
Wrong turns, named. You might have put Bob at layer 1 ("he can't reach anyone — must be the cable") — but his link light is ON, which rules the physical floor out; always trust the light over the symptom. You might have put Carol at layer 7 ("the app is broken") — tempting, but the refusal came from the transport handshake before any application data moved; a dead app wouldn't answer at all, while a reset is an active refusal at floor 4. You might have blamed the router for Bob — but the router's own numbers are correct; the wrong number lives on Bob's machine.
The fixes. A: re-seat or replace Alice's cable (try another switch port to rule out a dead port). B: change Bob's address to 192.168.1.50 (same neighborhood as everyone else). C: start (or allow) the file-sharing service on 192.168.1.10 — nothing is wrong with Carol's machine.
Verify it worked: Alice's link light turns green and her "cable unplugged" message clears; Bob can ping 192.168.1.1 and the printer; Carol's SYN gets a SYN-ACK instead of a RST and her file share opens.
Check yourself — nothing here is graded. Wrong answers are the useful ones; each explains why.
Question 1. A technician says 'that's a layer 3 problem.' What is she claiming?
Question 2. A user can open every shared folder on the office LAN but cannot reach any website. The cable is plugged in, the link light is on, and the IP address looks correct. What do you check first?
Question 3. Put these troubleshooting steps in bottom-up layer order:
Question 4. Which statement about encapsulation is true?
Question 5. Two PCs on the same switch cannot talk to each other. Link lights are on. PC-1 is 10.0.0.5, PC-2 is 10.0.1.9, both with mask 255.255.255.0. What is wrong?
- Troubleshoot bottom-up: prove the physical path before suspecting addresses, and addresses before suspecting conversations.
- Each layer wraps on the way down and strips only its own wrapper on the way up — so every header field in a capture belongs to exactly one layer.
- Layer 3 moves packets between networks with IP addresses; layer 2 moves frames between direct neighbors with hardware addresses.
- A refused connection (a reset answering a knock) means the path and addresses worked and the conversation itself was rejected — that's layer 4, not a dead cable.
- The 4-layer TCP/IP map is the working tool; the 7-layer OSI map is the shared vocabulary — both describe the same journey.
Next: TCP vs UDP and the Three-Way Handshake — You now know which floor every problem lives on; next you'll step onto floor 4 and watch two computers shake hands — agreeing on the rules — before they trust each other with a single byte.