skip to content

OSI

The seven-layer reference model and the four-layer TCP/IP model that actually shipped, plus the header each layer adds. Interviewers use it to check you can place a protocol, device or fault.

on this pageshow

questions

23

In OSI terms, what does a hub, a switch and a router each read from incoming traffic, and what does each forward on?

level: juniorimportance: must knowfreq 78%

answer

  1. one layer deeper each
  2. bits, frames, packets
  3. MAC table versus routing table
  4. who stops a broadcast

basics

~20 s

A hub reads no addresses and repeats bits out of every other port (layer 1). A switch forwards frames on the destination MAC address (layer 2). A router forwards packets on the destination IP address (layer 3).

solid answer

~50 s

A **hub** is a layer 1 repeater: it regenerates the signal and sends every bit out of all other ports, so every attached host sees every frame and they share one collision domain. A **switch** works at layer 2: it reads the Ethernet header, forwards on the destination MAC and learns hosts from the source MAC, so once it knows where a destination is, unicast frames go only toward that port. Broadcasts still reach every port in the same broadcast domain. A **router** works at layer 3: it strips the frame, reads the destination IP address, looks it up in its routing table, decrements the IPv4 TTL or IPv6 `Hop Limit` and builds a new frame for the next hop. Because it forwards on IP, a router does not pass layer 2 broadcasts, so it bounds a broadcast domain.

go deeper

for a junior

Recall the ladder cleanly: hub repeats bits at layer 1, switch forwards on MAC at layer 2, router forwards on IP at layer 3. Add the unit each handles and one consequence, such as routers stopping broadcasts.

for a middle

Explain what each device does to the traffic: the hub touches nothing, the switch reads the frame header and learns from source addresses, the router rebuilds the frame and decrements TTL or Hop Limit. Tie each to its collision or broadcast domain.

for a senior

Use the ladder to diagnose: reaching hosts in your own subnet but nothing beyond usually points at the default gateway or the path past it, not the switch. Point out that real boxes stack functions, so ask which header a given forwarding or filtering decision reads.

for a principal

Treat the ladder as a design boundary: where layer 3 sits decides broadcast domain size, fault blast radius and where filtering can happen. Be explicit that device labels come from a teaching model, not a product guarantee.

## Three devices, three layers The OSI model gives a compact way to describe network devices: name the **header a device reads to make its forwarding decision**. On that test the three classic LAN and internetwork devices land on three consecutive layers: - a **hub** reads no header at all, so it is a **layer 1** (physical) device; - a **switch** reads the Ethernet frame header, so it is a **layer 2** (data link) device; - a **router** reads the IP packet header, so it is a **layer 3** (network) device. The protocol data unit each one handles follows from that: bits for the hub, frames for the switch, packets for the router. ## Hub: layer 1, reads nothing A **hub** is a multiport repeater. Whatever electrical signal arrives on one port it regenerates and sends out of every other port. It never interprets the bits as a frame, so it has no idea what a MAC address or an IP address is. Two consequences follow: - **Every host sees every frame.** Unicast traffic between two hosts reaches all the others on the hub, and any of them can read it. - **One shared collision domain.** Only one host can transmit at a time; simultaneous transmissions collide, so hub links run half duplex and share their capacity. Hubs are essentially obsolete in modern wired networks, but they remain the reference point for what "layer 1 only" means. ## Switch: layer 2, reads the frame header A **switch** reads the **Ethernet header**. It uses the **destination MAC address** to decide which port a frame leaves on, and the **source MAC address** to learn which port each host sits behind. (How that learning, forwarding and flooding works is its own subject, covered under Ethernet switching.) Once a switch has learned where a destination lives, it sends unicast frames only toward that port. Each port is its own link, usually full duplex, so hosts no longer contend with each other. What a switch does **not** do is stop **broadcasts**: a frame sent to the broadcast address still reaches every port in the same **broadcast domain** (the same VLAN). A plain layer 2 switch never reads the IP header to forward, so it cannot tell one IP subnet from another. ## Router: layer 3, reads the packet header A **router** strips the incoming frame, reads the **destination IP address**, looks it up in its **routing table** and picks a next hop. It then builds a fresh frame for the next link (the per-hop rewrite of the link addresses is covered under encapsulation) and decrements the IPv4 **TTL** or the IPv6 **Hop Limit**; RFC 8200 defines Hop Limit as decremented by 1 by each node that forwards the packet. Because a router forwards on IP addresses, it does **not** forward layer 2 broadcasts from one interface to another. Each router interface is therefore the edge of a broadcast domain, which is why two IP subnets need a router (or a layer 3 switch doing the routing) between them. RFC 1122 records the naming history: the Internet community calls these packet-switching computers "gateways" or "IP routers", while the OSI world calls them "Intermediate Systems". ## Side by side | Device | OSI layer | Reads | Forwards on | Broadcasts | |---|---|---|---|---| | Hub | 1 | nothing (raw signal) | every other port | repeated everywhere | | Switch | 2 | Ethernet header | destination MAC | flooded within the broadcast domain | | Router | 3 | IP header | destination IP via routing table | not forwarded between interfaces | A useful way to remember the table: each step up the ladder reads **one more header** and makes a **narrower** delivery decision. The hub delivers to everyone, the switch to the right port on the LAN, the router to the right next network. ## A shorthand, not a law The layer label describes the **forwarding decision**, not everything a box can do: 1. A managed switch has its own IP address for management, so it is also an IP host, yet it still forwards user frames on MAC addresses. 2. Many devices add **filters** that read deeper than their forwarding decision, such as a router access list that matches TCP ports. Filtering and forwarding are separate questions. 3. A home "wireless router" is several devices in one case: an access point, a small switch, a router and usually NAT. So in an interview, give the classic ladder, then show you know it describes which header each forwarding decision reads, and that real products stack several of these functions.

  • Why does replacing a hub with a switch improve a LAN even when every host is in one IP subnet?
    A hub sends every frame to every port, so all hosts share one half-duplex collision domain and each can read the others' unicast traffic. A switch gives each port its own link, usually full duplex, and once it has learned a destination MAC it sends unicast frames only toward that port. Capacity per host rises and most unicast traffic is no longer visible to other hosts, but broadcasts still reach everyone: it is still one broadcast domain.
  • Two hosts on the same layer 2 switch are in different IP subnets. Why can they not talk without a router?
    A host sends a packet for another subnet to its default gateway, addressing the frame to the gateway's MAC rather than the destination host's. A plain layer 2 switch never reads the IP header, so it cannot route between subnets; it only forwards frames inside the broadcast domain. Without a router, or a layer 3 switch doing the routing, there is no gateway to hand the packet to.
  • Where does a plain wireless access point sit on this ladder?
    At layer 2. It bridges frames between the radio side and the wired Ethernet side, forwarding on MAC addresses without routing on IP. The home wireless router is a different box: an access point, a small switch, a router and usually NAT in one case, so it works at several layers at once.

saying these in an interview costs you the question

  • A hub is a slower switch that forwards frames by MAC address.
  • A plain layer 2 switch reads IP addresses to choose the output port.
  • A router forwards layer 2 broadcast frames between its networks.
  • A switch sends every unicast frame to every port, just as a hub does.
  • Routers and switches do the same job; a router is only a bigger switch.
open as a page

In the TCP/IP stack, what is encapsulation, and what is the data unit called at the transport, internet and link layers?

level: juniorimportance: must knowfreq 68%

basics

~20 s

Encapsulation is each layer wrapping what the layer above hands it in its own header (a link layer may add a trailer) on send, and removing it on receive. TCP sends segments, UDP and IP send datagrams, links send frames.

open as a page

In the OSI reference model, what are the seven layers from L1 to L7, and what is each one responsible for?

level: juniorimportance: must knowfreq 82%

basics

~20 s

The OSI model's seven layers, bottom up: Physical (bits on a medium), Data Link (frames between neighbours), Network (addressing and routing across networks), Transport (end-to-end delivery between processes), Session (dialogue control), Presentation (data representation), Application (network services to programs).

open as a page

In the OSI model, which layer do Ethernet, IP, TCP, UDP and HTTP each belong to, and what reasoning puts each one there?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Ethernet and Wi-Fi sit at layer 2, IP at layer 3, TCP and UDP at layer 4, and HTTP at layer 7. Each sits where its job and address scope sit: one link, across networks, to a process, application meaning.

open as a page

What are the four layers of the TCP/IP model, and which OSI layers does each one correspond to?

level: juniorimportance: must knowfreq 72%

basics

~10 s

RFC 1122 names four TCP/IP layers: link (OSI L1-L2, one directly connected network), internet (L3, IP across networks), transport (L4, TCP and UDP between applications) and application (conventionally L5-L7).

open as a page

When a laptop sends an IPv4 packet to a server through two routers, which addresses change at each hop and which stay the same?

level: middleimportance: must knowfreq 62%

basics

~20 s

The MAC addresses change on every link, because each router strips the incoming frame and builds a new one. The IP addresses and ports stay the same end to end (NAT aside), while the TTL drops at each router.

open as a page

In the OSI model, what is the protocol data unit called at each layer, and why does using the precise name matter?

level: juniorimportance: should knowfreq 56%

basics

~20 s

OSI protocol data units: bits at L1, frames at L2, packets at L3, segments at L4 for TCP (datagrams for UDP), and data or messages at L5-L7. The name tells a listener which layer's header and addressing is meant.

open as a page

What can a stateful firewall filter on that a stateless packet filter cannot, and why is UDP harder for it to track than TCP?

level: middleimportance: should knowfreq 44%

basics

~20 s

A stateless filter judges each packet alone on its IP and transport headers; a stateful firewall keeps a flow table, so it can admit replies to flows it saw start and drop unsolicited ones. TCP marks start and end with flags; UDP has neither, so state expires when idle.

open as a page

In TCP/IP encapsulation, how does a receiving host know which protocol's header comes next after it strips each layer?

level: middleimportance: should knowfreq 32%

basics

~20 s

Each header carries a selector for its payload: the Ethernet type field names IPv4 or IPv6, the IP Protocol or Next Header value names TCP (6) or UDP (17), and the transport ports pick the receiving application socket.

open as a page

Over IPv4, what share of a packet is header when TCP carries a 20-byte message versus a full 1,500-byte packet?

level: middleimportance: should knowfreq 26%

basics

~20 s

With minimum 20-byte IPv4 and 20-byte TCP headers, a 20-byte message becomes a 60-byte packet that is two-thirds header. A full packet on a 1,500-byte MTU carries 1,460 bytes of data, so the same 40 bytes are under 3%.

open as a page

In the OSI model, if the data link layer already detects corrupted frames, why does the transport layer check data for errors again?

level: middleimportance: should knowfreq 38%

basics

~20 s

A data link layer check protects one link and is rebuilt on every hop, so corruption inside a router or host escapes it. Only the endpoints can verify data end to end, so the transport layer checks again.

open as a page

ARP resolves IPv4 addresses to MAC addresses; is ARP an OSI layer 2 or layer 3 protocol, and how do you justify your answer?

level: middleimportance: should knowfreq 46%

basics

~20 s

ARP is usually placed at layer 2: its messages travel directly in link-layer frames with no IP header and never cross a router. It serves layer 3 by carrying IPv4 addresses, which is why some textbooks call it layer 2.5.

open as a page

ICMP messages ride inside IP packets just as TCP segments do, so why is ICMP placed at the network layer rather than the transport layer?

level: middleimportance: should knowfreq 42%

basics

~10 s

ICMP reports on IP delivery itself, is often generated by routers, and has no ports or process-to-process service. RFC 1122 calls it an integral part of IP even though it is carried inside IP.

open as a page

At which OSI layer does TLS belong, and how would you defend placing it at layer 5, layer 6, or between transport and application?

level: middleimportance: should knowfreq 50%

basics

~20 s

There is no single agreed layer. TLS runs over a reliable transport and below the application: encryption argues for layer 6, session state for layer 5, and the TCP/IP model simply treats it as part of the application layer.

open as a page

Why does the TCP/IP model have no separate session or presentation layer, and where do those OSI functions live in practice?

level: middleimportance: should knowfreq 42%

basics

~20 s

The internet suite never split the application layer because session and presentation needs differ per application. A TCP connection supplies the conversation; each application protocol, or a library it links, handles checkpoints, data representation and encryption itself.

open as a page

The same HTTPS request crosses a hub, a switch, a router, a stateful firewall, a layer 4 load balancer and a layer 7 proxy; what can each read, and why can only the proxy route on the URL path?

level: seniorimportance: should knowfreq 47%

basics

~20 s

They read progressively deeper: hub nothing, switch the MAC, router the IP, firewall and layer 4 balancer the IP and TCP headers. The path is encrypted HTTP inside TLS, so only a proxy that terminates TCP and TLS can read it.

open as a page

Using the OSI layers bottom-up, how do you localise why a client can no longer reach a service on another subnet, and what evidence clears each layer?

level: seniorimportance: should knowfreq 36%

basics

~20 s

Bottom-up OSI triage checks the link (L1), then reachability of local neighbours (L2), then a route to the remote host (L3), then an open port (L4), then a correct response (L5-L7). The first layer whose evidence fails is where to dig.

open as a page

QUIC packets travel inside UDP datagrams, yet RFC 9000 calls QUIC a transport protocol; at which layer does QUIC belong, and why?

level: seniorimportance: should knowfreq 30%

basics

~10 s

QUIC belongs at the transport layer by function: it provides connections, streams, reliable delivery and congestion control to applications. UDP beneath it is a deployment shim that existing hosts and networks already carry.

open as a page

The internet runs TCP/IP rather than the OSI protocol suite; why do engineers still use OSI layer numbers, and where does the seven-layer model mislead?

level: seniorimportance: should knowfreq 24%

basics

~20 s

OSI numbers survive as shared vocabulary for where a function sits. The shipped TCP/IP stack is not strictly layered, though: TCP's checksum covers IP addresses, tunnels carry link frames inside IP, and QUIC builds a transport over UDP.

open as a page

In OSI terms, how does a bridge differ from a switch, and how does a layer 3 switch differ from a router?

level: middleimportance: nice to knowfreq 28%

basics

~20 s

A switch is a multiport bridge: both forward frames on MAC addresses at layer 2. A layer 3 switch also routes on IP, so for routed traffic it is a router; hardware and feature set differ, not the layer.

open as a page

Many textbooks teach a five-layer network model; how does it relate to RFC 1122's four TCP/IP layers and to OSI's seven?

level: middleimportance: nice to knowfreq 28%

basics

~20 s

The five-layer model is a textbook hybrid: it keeps TCP/IP's application, transport and internet (called network) layers and splits the link layer into OSI's physical and data link layers. No RFC defines it; RFC 1122 names four layers.

open as a page

Why does TCP's checksum cover IP addresses that live in the IP header, and what does that cross-layer coupling force on devices that rewrite addresses and on IPv6?

level: seniorimportance: nice to knowfreq 18%

basics

~20 s

TCP and UDP checksums include a pseudo-header of the IP source and destination addresses, protocol number and length, so a misdelivered segment fails verification. Anything rewriting IP addresses must fix transport checksums, and IPv6 needed new pseudo-headers.

open as a page

BGP exchanges routes over a TCP connection while OSPF runs directly over IP; at which OSI layer does each routing protocol belong, and why?

level: seniorimportance: nice to knowfreq 22%

basics

~20 s

By carrier, BGP is an application on TCP and OSPF is carried directly by IP; by purpose, both are layer 3 control-plane protocols. The strong answer separates the routing protocol from the layer 3 forwarding it feeds.

open as a page