skip to content

Protocol Placement per Layer

Which layer Ethernet, IP, TCP, TLS and HTTP belong to, and the reasoning that puts them there. Interviewers pick awkward cases like TLS, ARP or BGP to see if you can justify a placement.

on this pageshow

questions

6

In the OSI model, which layer do Ethernet, IP, TCP, UDP and HTTP each belong to, and what reasoning puts each one there?

level: juniorimportance: must knowfreq 72%

answer

  1. what each protocol addresses
  2. one link, many networks, one process
  3. MAC address, IP address, port number
  4. classify by job, not by carrier

basics

~20 s

Ethernet and Wi-Fi sit at layer 2, IP at layer 3, TCP and UDP at layer 4, and HTTP at layer 7. Each sits where its job and address scope sit: one link, across networks, to a process, application meaning.

solid answer

~40 s

I place a protocol by the job it does and the scope of the address it uses. **Ethernet** and **Wi-Fi** are layer 2: they deliver frames between interfaces on one link using MAC addresses. **IP** is layer 3: it carries datagrams host to host across many networks using IP addresses, and routers forward on it; **ICMP** sits beside it. **TCP** and **UDP** are layer 4: they add port numbers so data reaches a process, and TCP adds reliability, ordering and flow control. **HTTP**, **DNS** and **SMTP** are layer 7: they define what applications say to each other. What carries a protocol does not decide its layer: DNS rides in UDP and is still layer 7. RFC 1122 draws the same lines as the link, internet, transport and application layers of the TCP/IP model.

go deeper

for a junior

Recall the four anchors without hesitating: Ethernet 2, IP 3, TCP and UDP 4, HTTP 7. Then say what each one addresses: MAC, IP address, port, application data.

for a middle

Explain the rule rather than the list: address scope and job decide the layer, and the carrier does not. Show it with DNS over UDP staying at layer 7.

for a senior

Volunteer a boundary case such as ARP, TLS or BGP and argue it both ways. Tie placement to what a middlebox can see, since that is where layers matter in production.

for a principal

Treat the model as a vocabulary for design discussions, not a law. Know how RFC 1122 bends the model (ICMP, one combined application layer) and why RFC 3439 warns against strict layering.

## The rule behind every placement The OSI reference model splits communication into seven layers, each with one job. A protocol belongs to a layer because it does that layer's job, and the most reliable clue to the job is **the scope of the address the protocol uses**: - a **MAC address** names an interface on one link, so a protocol that uses it works at the **data link layer (layer 2)**; - an **IP address** names a host anywhere on an internetwork, so a protocol that uses it works at the **network layer (layer 3)**; - a **port number** names a process or service on a host, so a protocol that adds it works at the **transport layer (layer 4)**; - a URL, a mailbox or a domain name means something only to an application, so a protocol built around it works at the **application layer (layer 7)**. The second clue is **who acts on the header**. Switches read layer 2 headers, routers read layer 3 headers, and in the basic model only the two end hosts act on layer 4 and above; middleboxes such as firewalls and load balancers are the deliberate exceptions. ## The canonical list | OSI layer | Canonical protocols | Address it uses | Scope of delivery | |---|---|---|---| | 7 Application | HTTP, DNS, SMTP | names, URLs, mailboxes | application to application | | 4 Transport | TCP, UDP | port numbers | process to process | | 3 Network | IP (IPv4, IPv6), ICMP | IP addresses | host to host, across networks | | 2 Data link | Ethernet, Wi-Fi (IEEE 802.11) | MAC addresses | interface to interface, one link | Layers 5 and 6 are left empty on purpose: few Internet protocols map cleanly onto them, which is why TLS is argued about. ## Why each placement holds - **Ethernet and Wi-Fi (layer 2).** They frame data for one physical or radio link and address it with MAC addresses. The Ethernet standard also specifies cabling and signalling, so it spans layer 1 as well; its framing and MAC addressing are what make it the canonical layer 2 example. - **IP (layer 3).** RFC 1122 calls IP "a connectionless or datagram internetwork service, providing no end-to-end delivery guarantees". Its job is to get a datagram from source host to destination host through any number of routers. - **ICMP (layer 3).** RFC 1122 treats ICMP as "an integral part of IP", used for error reporting about IP delivery, even though ICMP messages ride inside IP. - **TCP and UDP (layer 4).** RFC 1122 names them the two primary transport protocols. Both add ports; **TCP** adds a reliable, ordered, flow-controlled byte stream, while **UDP** is a connectionless datagram service. - **HTTP, DNS, SMTP (layer 7).** They define messages that only applications interpret. RFC 1122 lists SMTP among application "user protocols" and DNS among application "support protocols". ## What carries a protocol does not decide its layer A frequent mistake is to place a protocol one layer above whatever carries it. Encapsulation nests headers, but layers are defined by function: 1. DNS normally travels over UDP port 53 and may use TCP port 53 (RFC 1035 §4.2). Either way it stays an application protocol. 2. HTTP rides on TCP, which rides on IP, yet nobody calls HTTP a layer 3 protocol because IP is somewhere below it. 3. Tunnels break the naive count completely: RFC 8200 lists IPv6 itself as something that can be "tunneled" over IPv6, so the same protocol can appear twice in one packet. ## Where the tidy list stops being tidy The canonical list is a teaching convention, not a ruling from a standards body. The interesting cases are the ones that do two jobs or ride on an unexpected carrier: **ARP** (carries layer 3 addresses inside layer 2 frames), **TLS** (layer 5, layer 6 or "between transport and application"), **BGP** (a routing protocol that runs over TCP), and **QUIC** (a transport protocol inside UDP). RFC 3439 goes further and warns that strict layering can itself be harmful. A strong answer gives the list briefly and then shows it can reason about a case the list does not settle. ## How to answer in an interview 1. Give the list in one breath: Ethernet 2, IP 3, TCP and UDP 4, HTTP 7. 2. State the rule: job and address scope, not carrier. 3. Offer one boundary case unprompted, with its reason, to show the rule is yours rather than memorised.

  • HTTP runs over TCP and TCP runs over IP. Why is HTTP not described as running at layer 3?
    Encapsulation is not placement. Each layer treats everything above it as opaque payload, so IP carries HTTP bytes without understanding them. HTTP is placed at layer 7 because its job is application semantics such as requests, responses and URLs, not because of what is underneath it.
  • Which protocols in the canonical list, or next to it, are genuinely disputed, and why?
    TLS, because it does session and presentation work that the TCP/IP model has no layer for; ARP, because it serves layer 3 but travels only in layer 2 frames; and routing protocols such as BGP, which serve layer 3 forwarding while running over TCP. In each case the answer depends on whether you classify by function or by carrier.

saying these in an interview costs you the question

  • UDP belongs at layer 3 because it is connectionless like IP.
  • DNS is a layer 4 protocol because it runs over UDP.
  • HTTP is layer 4 because it has a well-known port number.
  • Switches forward on IP addresses, so IP is a layer 2 protocol.
  • Every protocol has exactly one official OSI layer set by the standard.
open as a page

ARP resolves IPv4 addresses to MAC addresses; is ARP an OSI layer 2 or layer 3 protocol, and how do you justify your answer?

level: middleimportance: should knowfreq 46%

basics

~20 s

ARP is usually placed at layer 2: its messages travel directly in link-layer frames with no IP header and never cross a router. It serves layer 3 by carrying IPv4 addresses, which is why some textbooks call it layer 2.5.

open as a page

ICMP messages ride inside IP packets just as TCP segments do, so why is ICMP placed at the network layer rather than the transport layer?

level: middleimportance: should knowfreq 42%

basics

~10 s

ICMP reports on IP delivery itself, is often generated by routers, and has no ports or process-to-process service. RFC 1122 calls it an integral part of IP even though it is carried inside IP.

open as a page

At which OSI layer does TLS belong, and how would you defend placing it at layer 5, layer 6, or between transport and application?

level: middleimportance: should knowfreq 50%

basics

~20 s

There is no single agreed layer. TLS runs over a reliable transport and below the application: encryption argues for layer 6, session state for layer 5, and the TCP/IP model simply treats it as part of the application layer.

open as a page

QUIC packets travel inside UDP datagrams, yet RFC 9000 calls QUIC a transport protocol; at which layer does QUIC belong, and why?

level: seniorimportance: should knowfreq 30%

basics

~10 s

QUIC belongs at the transport layer by function: it provides connections, streams, reliable delivery and congestion control to applications. UDP beneath it is a deployment shim that existing hosts and networks already carry.

open as a page

BGP exchanges routes over a TCP connection while OSPF runs directly over IP; at which OSI layer does each routing protocol belong, and why?

level: seniorimportance: nice to knowfreq 22%

basics

~20 s

By carrier, BGP is an application on TCP and OSPF is carried directly by IP; by purpose, both are layer 3 control-plane protocols. The strong answer separates the routing protocol from the layer 3 forwarding it feeds.

open as a page