In the TCP/IP stack, what is encapsulation, and what is the data unit called at the transport, internet and link layers?
answer
- wrap on the way down
- strip on the way up
- each layer treats the rest as payload
- segment, datagram, frame
basics
~20 sEncapsulation is each layer wrapping what the layer above hands it in its own header (a link layer may add a trailer) on send, and removing it on receive. TCP sends segments, UDP and IP send datagrams, links send frames.
solid answer
~40 sEncapsulation is how the layers cooperate without knowing each other's formats. On send, TCP prepends its header to the application bytes to make a **segment** (UDP makes a **datagram**); IP prepends its header to make an **IP datagram**; the link layer prepends a link header, and on Ethernet appends a frame check sequence, to make a **frame**, which goes out as bits. Each layer treats everything it was handed as opaque payload. On receive the order reverses: each layer checks and strips its own header, then uses a type field in it to pick the protocol above. The result is nesting: the ports sit in the transport header, inside the IP datagram that carries the IP addresses, inside a frame that carries the MAC addresses.
go deeper
Recall the order of wrapping on send (transport, then IP, then link) and the unit names: segment or UDP datagram, IP datagram or packet, frame, bits.
Explain that each layer treats the upper unit as opaque payload, and name which address lives in which header: ports, IP addresses, MAC addresses.
Use the nesting to reason about symptoms: which header a router rebuilds per hop, which a middlebox must parse to act, and where overhead comes from.
Be ready to argue where strict layering leaks, such as the TCP pseudo-header or tunnels, and what that costs designers of middleboxes and new transports.
## What encapsulation means **Encapsulation** is the rule that lets independent protocols stack: every layer takes the unit handed down by the layer above, treats it as an opaque **payload**, and wraps it in its own **header** (and sometimes a **trailer**). The layer never edits the payload; it only adds the control information *it* needs — addresses, ports, lengths, checksums, a type field. On the receiving side, **decapsulation** runs the same steps in reverse. The value is independence. TCP does not care whether the link is Ethernet or Wi-Fi, and Ethernet does not care whether the payload is TCP, UDP or something else. Each layer talks only to its **peer** layer on the far end, through the header it added. ## Walking down the stack on send Take an application that writes a few bytes to a TCP connection over IPv4 on Ethernet: 1. **Application layer** — produces the bytes: an HTTP request, a DNS query, a line of a chat protocol. 2. **Transport layer** — TCP prepends a TCP header carrying the source and destination **ports**, sequence and acknowledgment numbers, flags and a checksum. The result is a **segment**. With UDP instead, an 8-octet UDP header (ports, length, checksum) makes a **UDP datagram**. 3. **Internet layer** — IP prepends an IP header carrying the source and destination **IP addresses**, the TTL (the Hop Limit in IPv6) and a protocol number that says "TCP follows". The result is an **IP datagram**. 4. **Link layer** — the network interface prepends a link header carrying the source and destination **link-layer (MAC) addresses** and a type field that says "IPv4 follows"; Ethernet also appends a **frame check sequence** trailer so the receiver can detect corruption. The result is a **frame**. 5. **Physical layer** — the frame is sent as **bits** (signals on copper, light or radio). ## The names of the units RFC 1122 §1.3.3 gives the Internet suite's own vocabulary, which differs slightly from OSI's: | Layer (TCP/IP) | Unit | What its header adds | |---|---|---| | Application | data / message | application protocol fields | | Transport | TCP **segment**, UDP **datagram** | ports, checksum (TCP: sequence numbers, flags, window) | | Internet | IP **datagram**; **packet** at the IP/link interface | IP addresses, TTL / Hop Limit, protocol number | | Link | **frame** | MAC addresses, type field; Ethernet adds a trailer | | (Physical, OSI L1) | bits | — | Two subtleties interviewers like: - RFC 1122 calls the transport unit generically a **message** ("a TCP segment is a message"), and defines a **packet** as what crosses the interface between the internet and link layers: a whole IP datagram or a fragment of one. - In everyday OSI talk the L3 unit is simply a "packet". Both are accepted; the point is to use one name per layer consistently and not to call a frame a packet. ## Walking back up on receive The receiver undoes the wrapping one layer at a time: 1. The link layer checks the trailer, confirms the destination MAC is its own (or broadcast/multicast), reads the type field and hands the payload to IPv4. 2. IPv4 verifies its header checksum (RFC 1122 §3.2.1.2 makes a host silently discard a bad one), confirms the destination address is its own, reads the protocol number and hands the payload to TCP. 3. TCP verifies its checksum, finds the connection by addresses and ports, and delivers the bytes in order to the application. At every step the header is **consumed by its peer and removed**; the layer above never sees it. ## What the nesting implies - **Which address lives where** follows directly: ports in the transport header, IP addresses in the IP header, MAC addresses in the frame. This is why a router can rebuild the frame at each hop while leaving the IP datagram inside mostly intact. - **Only some layers add trailers.** TCP, UDP and IP add headers only; the trailer is typical of link layers. - **Every layer costs bytes.** A small payload can end up mostly header, which is why chatty protocols batch. - **The layering is a guide, not a law.** TCP's checksum already reaches down into IP addresses through a pseudo-header, and RFC 3439 argues that strict layering can hide information lower layers need. ## Common mistakes - Thinking encapsulation means encryption. It is only wrapping; confidentiality is a separate job (TLS, IPsec). - Believing lower layers read or edit upper headers. A plain IP host treats the TCP header as payload bytes. - Getting the nesting inside-out: the link header is the **outermost**, the transport header the innermost of the protocol headers.
- In TCP/IP, does every layer add a trailer as well as a header?No. TCP, UDP and IP add only headers. A trailer is typical of the link layer: Ethernet appends a frame check sequence after the payload so the receiving interface can detect a corrupted frame and drop it before any higher layer sees it.
- Why does RFC 1122 distinguish an IP datagram from a packet?RFC 1122 defines the IP datagram as IP's end-to-end unit and the packet as whatever is handed to the link layer. The two are the same unless the datagram was fragmented, in which case each fragment is a separate packet carrying part of one datagram.
- On a receiving host, what does each layer do before handing the payload up?It checks its own header: integrity (the Ethernet trailer, the IPv4 header checksum, the TCP or UDP checksum), then addressing (is this for me?), then reads the field naming the next protocol, removes its header and passes the rest up. A failure at any step drops the unit at that layer.
A letter goes into an envelope addressed to a person (the port), that envelope goes into a mailbag addressed to a city's sorting office (the IP address), and the bag rides a specific truck to the next depot (the frame). Each depot moves the bag onto a new truck, but never opens the envelope.
saying these in an interview costs you the question
- Encapsulation means each layer encrypts the data it receives.
- The IP layer reads and rewrites the TCP header while wrapping it.
- The TCP header is outermost because it is added first.
- Segment, packet and frame are just three names for the same bytes.
- Every layer adds both a header and a trailer.