In the OSI model, which layer do Ethernet, IP, TCP, UDP and HTTP each belong to, and what reasoning puts each one there?
answer
- what each protocol addresses
- one link, many networks, one process
- MAC address, IP address, port number
- classify by job, not by carrier
basics
~20 sEthernet and Wi-Fi sit at layer 2, IP at layer 3, TCP and UDP at layer 4, and HTTP at layer 7. Each sits where its job and address scope sit: one link, across networks, to a process, application meaning.
solid answer
~40 sI place a protocol by the job it does and the scope of the address it uses. **Ethernet** and **Wi-Fi** are layer 2: they deliver frames between interfaces on one link using MAC addresses. **IP** is layer 3: it carries datagrams host to host across many networks using IP addresses, and routers forward on it; **ICMP** sits beside it. **TCP** and **UDP** are layer 4: they add port numbers so data reaches a process, and TCP adds reliability, ordering and flow control. **HTTP**, **DNS** and **SMTP** are layer 7: they define what applications say to each other. What carries a protocol does not decide its layer: DNS rides in UDP and is still layer 7. RFC 1122 draws the same lines as the link, internet, transport and application layers of the TCP/IP model.
go deeper
Recall the four anchors without hesitating: Ethernet 2, IP 3, TCP and UDP 4, HTTP 7. Then say what each one addresses: MAC, IP address, port, application data.
Explain the rule rather than the list: address scope and job decide the layer, and the carrier does not. Show it with DNS over UDP staying at layer 7.
Volunteer a boundary case such as ARP, TLS or BGP and argue it both ways. Tie placement to what a middlebox can see, since that is where layers matter in production.
Treat the model as a vocabulary for design discussions, not a law. Know how RFC 1122 bends the model (ICMP, one combined application layer) and why RFC 3439 warns against strict layering.
## The rule behind every placement The OSI reference model splits communication into seven layers, each with one job. A protocol belongs to a layer because it does that layer's job, and the most reliable clue to the job is **the scope of the address the protocol uses**: - a **MAC address** names an interface on one link, so a protocol that uses it works at the **data link layer (layer 2)**; - an **IP address** names a host anywhere on an internetwork, so a protocol that uses it works at the **network layer (layer 3)**; - a **port number** names a process or service on a host, so a protocol that adds it works at the **transport layer (layer 4)**; - a URL, a mailbox or a domain name means something only to an application, so a protocol built around it works at the **application layer (layer 7)**. The second clue is **who acts on the header**. Switches read layer 2 headers, routers read layer 3 headers, and in the basic model only the two end hosts act on layer 4 and above; middleboxes such as firewalls and load balancers are the deliberate exceptions. ## The canonical list | OSI layer | Canonical protocols | Address it uses | Scope of delivery | |---|---|---|---| | 7 Application | HTTP, DNS, SMTP | names, URLs, mailboxes | application to application | | 4 Transport | TCP, UDP | port numbers | process to process | | 3 Network | IP (IPv4, IPv6), ICMP | IP addresses | host to host, across networks | | 2 Data link | Ethernet, Wi-Fi (IEEE 802.11) | MAC addresses | interface to interface, one link | Layers 5 and 6 are left empty on purpose: few Internet protocols map cleanly onto them, which is why TLS is argued about. ## Why each placement holds - **Ethernet and Wi-Fi (layer 2).** They frame data for one physical or radio link and address it with MAC addresses. The Ethernet standard also specifies cabling and signalling, so it spans layer 1 as well; its framing and MAC addressing are what make it the canonical layer 2 example. - **IP (layer 3).** RFC 1122 calls IP "a connectionless or datagram internetwork service, providing no end-to-end delivery guarantees". Its job is to get a datagram from source host to destination host through any number of routers. - **ICMP (layer 3).** RFC 1122 treats ICMP as "an integral part of IP", used for error reporting about IP delivery, even though ICMP messages ride inside IP. - **TCP and UDP (layer 4).** RFC 1122 names them the two primary transport protocols. Both add ports; **TCP** adds a reliable, ordered, flow-controlled byte stream, while **UDP** is a connectionless datagram service. - **HTTP, DNS, SMTP (layer 7).** They define messages that only applications interpret. RFC 1122 lists SMTP among application "user protocols" and DNS among application "support protocols". ## What carries a protocol does not decide its layer A frequent mistake is to place a protocol one layer above whatever carries it. Encapsulation nests headers, but layers are defined by function: 1. DNS normally travels over UDP port 53 and may use TCP port 53 (RFC 1035 §4.2). Either way it stays an application protocol. 2. HTTP rides on TCP, which rides on IP, yet nobody calls HTTP a layer 3 protocol because IP is somewhere below it. 3. Tunnels break the naive count completely: RFC 8200 lists IPv6 itself as something that can be "tunneled" over IPv6, so the same protocol can appear twice in one packet. ## Where the tidy list stops being tidy The canonical list is a teaching convention, not a ruling from a standards body. The interesting cases are the ones that do two jobs or ride on an unexpected carrier: **ARP** (carries layer 3 addresses inside layer 2 frames), **TLS** (layer 5, layer 6 or "between transport and application"), **BGP** (a routing protocol that runs over TCP), and **QUIC** (a transport protocol inside UDP). RFC 3439 goes further and warns that strict layering can itself be harmful. A strong answer gives the list briefly and then shows it can reason about a case the list does not settle. ## How to answer in an interview 1. Give the list in one breath: Ethernet 2, IP 3, TCP and UDP 4, HTTP 7. 2. State the rule: job and address scope, not carrier. 3. Offer one boundary case unprompted, with its reason, to show the rule is yours rather than memorised.
- HTTP runs over TCP and TCP runs over IP. Why is HTTP not described as running at layer 3?Encapsulation is not placement. Each layer treats everything above it as opaque payload, so IP carries HTTP bytes without understanding them. HTTP is placed at layer 7 because its job is application semantics such as requests, responses and URLs, not because of what is underneath it.
- Which protocols in the canonical list, or next to it, are genuinely disputed, and why?TLS, because it does session and presentation work that the TCP/IP model has no layer for; ARP, because it serves layer 3 but travels only in layer 2 frames; and routing protocols such as BGP, which serve layer 3 forwarding while running over TCP. In each case the answer depends on whether you classify by function or by carrier.
saying these in an interview costs you the question
- UDP belongs at layer 3 because it is connectionless like IP.
- DNS is a layer 4 protocol because it runs over UDP.
- HTTP is layer 4 because it has a well-known port number.
- Switches forward on IP addresses, so IP is a layer 2 protocol.
- Every protocol has exactly one official OSI layer set by the standard.