Layers are a division of labour
Everyone can chant "Physical, Data Link, Network, Transport, Session, Presentation, Application". Almost nobody can say why the list exists. Here is why.
Sending data over a network involves a pile of unrelated problems: turning bits into voltages, deciding who transmits when two machines share a cable, finding a path across the world, recovering lost packets, and agreeing on what the bytes mean. If one program had to solve all of them, changing anything would mean changing everything.
Layering says: each layer solves one problem, uses only the layer below, and offers a clean service to the layer above. Then you can swap Wi-Fi for Ethernet without touching your web browser, and switch from HTTP to SMTP without touching TCP.
That independence is the entire point. The seven-item list is the consequence, not the idea.
The stack that actually runs
The OSI model has seven layers and is a teaching model. The internet runs the TCP/IP model, which has four. Both appear in exams, so keep this mapping:
| TCP/IP layer | OSI layers | Job | Address used | Examples |
|---|---|---|---|---|
| Application | 5, 6, 7 | what the bytes mean | none | HTTP, DNS, SMTP |
| Transport | 4 | process to process, reliability | port number | TCP, UDP |
| Internet | 3 | host to host across networks | IP address | IP, ICMP |
| Link | 1, 2 | across one physical hop | MAC address | Ethernet, Wi-Fi |
The address column is the most useful part of that table. Each layer has its own kind of address because each layer answers a different question. MAC says "which device on this cable". IP says "which host on the planet". Port says "which program on that host".
Encapsulation: what actually happens to your bytes
Say your browser wants to send 20 bytes of HTTP request. Follow them down.
Application hands 20 bytes to the transport layer.
Transport (TCP) puts a 20-byte header in front. That header contains the source port (say 51322), the destination port (443), a sequence number, an acknowledgement number, flags and a checksum. Total is now 40 bytes. This unit is called a segment.
Internet (IP) puts a 20-byte header in front of that: source IP, destination IP, TTL, protocol number (6 for TCP). Total 60 bytes. This unit is a packet.
Link (Ethernet) puts a 14-byte header in front and a 4-byte checksum behind: source MAC, destination MAC, type field. Total 78 bytes. This unit is a frame.
So 20 bytes of payload travel as 78 bytes on the wire. The 58 bytes of headers are the cost of the service. On tiny messages the overhead is enormous, which is one reason protocols batch data.
At the far end the process reverses. The receiving network card checks the Ethernet checksum, strips the Ethernet header, and hands the rest up. IP checks its header, sees protocol 6, strips itself and hands up to TCP. TCP checks the checksum and sequence number, strips itself, and delivers 20 bytes to whichever program has port 443 open. Every layer strips exactly what its counterpart added and nothing else.
Each layer talks logically to the same layer on the other machine. Your TCP believes it is speaking to the server's TCP. Physically the bytes went down your stack, across many links, and up theirs. This is called peer-to-peer communication between layers, and it is what "abstraction" means in practice.
Devices belong to layers
- A hub works at layer 1. It copies electrical signals to every port. It understands nothing. Obsolete.
- A switch works at layer 2. It reads MAC addresses and learns which device is on which port, so it forwards a frame only to the right port.
- A router works at layer 3. It reads IP addresses and decides which network to forward towards. It is the only one of the three that joins different networks together.
Knowing which layer a device works at tells you what it can and cannot do. A switch cannot connect your home network to the internet, because it has no idea what an IP address is.
The MTU on Ethernet is 1500 bytes of payload. If IP needs to send more, the packet is fragmented into pieces and reassembled at the destination. Fragmentation is slow and fragile — lose one fragment and the whole original packet is lost — so modern systems avoid it by discovering the smallest MTU along the path first. Do not describe fragmentation as a normal, healthy thing in an exam answer; it is a fallback.
Where OSI's extra layers went
OSI's session layer (managing conversations) and presentation layer (encoding, compression, encryption) do not exist as separate layers on the internet. Their jobs got absorbed. TLS encryption sits between TCP and HTTP, which is roughly presentation-layer work. Session management lives inside application protocols, as cookies in HTTP.
That is why the honest answer to "how many layers are there" is: seven in the model you must memorise, four in the stack that actually runs your traffic. Say both and you look like you understand rather than recite.
Install Wireshark, capture traffic while loading a page, and click one packet. The pane shows the frame, then the IP packet inside it, then the TCP segment inside that, then the HTTP data. Encapsulation stops being abstract in about ten seconds.