The OSI model splits the job of sending data between two computers into seven layers, each with one responsibility. Engineers and cloud docs use its layer numbers to say where something happens, so knowing them explains a lot of networking vocabulary.
Why networking is split into layers
Sending 'Bring tuna' from your laptop to a friend's phone involves a lot of separate problems. The app has to produce the message. Something has to agree on a format both ends understand. Something has to make sure nothing gets lost, something has to find a route across the internet, and something has to move electrical signals or radio waves from one device to the next.
Putting all of that in one piece of software would make every part hard to change. Layering solves this by giving each problem to one layer, which only talks to the layer directly above and below it. Each layer relies on the one below to do its job and doesn't care how it does it.
That is why your browser works the same over Wi-Fi, Ethernet or 5G. The browser lives at the top. The way bits physically move lives at the bottom, and it can be swapped without the browser noticing.
The OSI (Open Systems Interconnection) model is a reference model, published as a standard by ISO and the ITU. It describes what each layer is responsible for. It doesn't say which protocols you must use.
The seven layers
The layers are numbered from the bottom, but people usually walk through them from the top, because that is where your message starts.
| Layer | What it does | Examples |
|---|---|---|
| 7 Application | What the user's software speaks | HTTP, DNS, SMTP |
| 6 Presentation | Formats, encrypts, compresses | Character encodings, TLS |
| 5 Session | Opens, manages and closes conversations | Session setup and teardown |
| 4 Transport | End-to-end delivery between programs | TCP, UDP, ports |
| 3 Network | Addressing and routing between networks | IP, routers |
| 2 Data link | Delivery to the next device on the same network | Ethernet, Wi-Fi frames, MAC addresses, switches |
| 1 Physical | Signals on a medium | Copper, fibre, radio |
Layer 7: application
This is the layer your code touches. A browser speaks HTTP, a mail client speaks SMTP and IMAP, and nearly everything speaks DNS. 'Application layer' means the protocol the application uses, not the application itself: Chrome isn't layer 7, but the HTTP request it sends is.
Layer 6: presentation
Presentation makes data readable at the other end. It covers character encoding (so text sent as UTF-8 is read as UTF-8), compression and encryption. TLS, the encryption behind HTTPS, is usually placed here, though in practice it doesn't sit neatly in any one layer.
Layer 5: session
A session is a conversation with a start and an end. This layer opens and closes it, and controls whose turn it is to talk so that two sides don't trip over each other. In modern stacks this work is mostly done inside the application or by TLS rather than by a separate protocol.
Layer 4: transport
Transport gets data from a program on one machine to a program on another. Port numbers decide which program: 443 for HTTPS, 53 for DNS. The two big protocols here make different trade-offs:
- TCP is the careful one. It numbers every segment, resends anything lost and delivers data in order. Web pages and APIs use it.
- UDP is the fast one. It sends and forgets, with no handshake and no resends. Video calls and online games use it, because a late packet is often worse than a missing one, and so do most DNS lookups.
Layer 3: network
The network layer gets data across many networks to the right machine. It uses IP addresses, which identify a device's place on the internet, and routers, which read the destination IP address and pick the next hop. On most home and office networks your device gets its IP address from DHCP.
Layer 2: data link
The data link layer moves data one hop: from your laptop to your router, or from one router to the next. It wraps data in frames addressed with MAC addresses, the hardware addresses of network cards. Switches work at this layer. It also checks each frame for corruption and drops a damaged one.
Layer 1: physical
The physical layer is the actual movement: voltages on copper, pulses of light in fibre, or radio waves for Wi-Fi. It deals in raw bits, with no idea what they mean. Cable and connector standards belong here too.
How a message moves through the layers
On the way out, each layer wraps what it gets from the layer above in its own header. This is called encapsulation. Transport adds a header with ports and the data becomes a segment. Network adds a header with IP addresses and it becomes a packet. Data link adds a header with MAC addresses and it becomes a frame. The physical layer sends the frame as bits.
The receiving machine does the same in reverse. Each layer reads the header its partner layer added, removes it and passes the rest up. Here is the trip, with layers 5 to 7 shown as one box and layers 1 and 2 as another:
A message going down one stack and up another
Step 1 of 9: The sending app has a message, Bring tuna, and the top layers turn it into data ready to send.
Devices in the middle only go as far up as they need. A switch reads the layer 2 header and forwards the frame. A router goes up to layer 3: it removes the frame, reads the destination IP address, picks the next hop and wraps the packet in a new frame with new MAC addresses. So the MAC addresses change at every hop, while the IP addresses stay the same from end to end (unless something like NAT on a home router rewrites them).
A worked example: loading a web page
Say you open https://example.com on your laptop over Wi-Fi. Roughly, from top to bottom:
- Application: the browser asks DNS for the IP address of
example.com, then builds an HTTPGET /request. - Presentation and session: TLS sets up an encrypted session with the server and encrypts the request.
- Transport: TCP opens a connection to port 443 on the server, splits the data into segments and keeps track of what has been acknowledged.
- Network: IP puts the server's IP address on every packet. Your laptop sees the server isn't on the local network, so it sends the packets to the router.
- Data link: each packet goes into a Wi-Fi frame addressed to the router's MAC address.
- Physical: the Wi-Fi card sends the frames as radio signals.
The router then passes each packet along a chain of other routers until it reaches the server, where it climbs back up the layers to the web server software. The response makes the same trip in the other direction.
OSI and TCP/IP
The internet doesn't run on OSI protocols. It runs on the TCP/IP suite, which is usually described with four layers:
| TCP/IP layer | OSI layers |
|---|---|
| Application | 5, 6 and 7 |
| Transport | 4 |
| Internet | 3 |
| Link | 1 and 2 |
The OSI model survives because its numbering became the shared vocabulary. When someone says 'layer 7 load balancer', they mean one that reads HTTP and can route by URL or header. A 'layer 4 load balancer' only sees IP addresses and ports. 'Layer 2 switch', 'layer 3 DDoS attack' and 'that is a layer 1 problem' (someone unplugged the cable) all use the OSI numbers, even though the protocols involved are TCP/IP.
Using it to troubleshoot
The layers give you an order for debugging. When a site won't load, work from the bottom up:
- Layer 1-2: is the cable plugged in, is Wi-Fi connected?
- Layer 3: does the machine have an IP address, and can you
pingthe server? - Layer 4: is anything listening on the port, or is a firewall blocking it?
- Layer 7: does DNS resolve, and what status code does the server return?
A tool such as Wireshark shows each captured packet as a stack of these headers, one per layer, which is a good way to see encapsulation for real.
Common mistakes
- Treating the layers as strict: real protocols blur them. TLS spans presentation and session, and ARP, which finds the MAC address for an IP address, sits between layers 2 and 3.
- Thinking each layer is a separate program: several layers are often handled by one piece of code. The operating system usually handles transport and network together, and the network card handles data link and physical.
- Mixing up MAC and IP addresses: a MAC address gets a frame to the next device on the same network. An IP address gets a packet to the final machine across many networks.
- Assuming HTTPS is its own layer: HTTPS is HTTP (layer 7) sent over TLS, which encrypts the whole request, headers included, before TCP carries it.
If you want to test yourself on more networking basics, try the CCNA quiz.
Key takeaways
- The OSI model splits networking into seven layers: application, presentation, session, transport, network, data link and physical.
- Each layer does one job and only talks to the layers next to it, so any layer can change without breaking the others.
- On the way out, each layer adds a header (encapsulation); on the way in, each layer removes the one its partner added.
- The internet runs on TCP/IP's four layers, but the OSI numbers are the vocabulary most engineers use.
- Working up the layers from the bottom is a reliable way to troubleshoot a network problem.