OSI Model

This is a guide on the OSI model.

Check out Audible on Amazon and listen to the newest books!

Introduction to the OSI Model

The Open Systems Interconnection (OSI) model stands as one of the foundational frameworks in the world of networking and telecommunications. It serves as a conceptual blueprint that describes the functions of a networking system and characterizes the various computing functions that must occur for any two devices or systems to communicate effectively with one another. To understand this concept more intuitively, consider a regular conversation between two people. There are certain practices that we observe to ensure effective communication, such as ensuring that both parties speak the same language. Each person takes turns speaking rather than both trying to talk simultaneously. If one person misses something that was said, they might ask for repetition or verify their understanding. If someone is speaking too quickly, the listener might request that they slow down. The general principle is that there are rules and guidelines in place to ensure successful communication. The OSI model operates on essentially the same principle, providing a structured framework for network communications.

The Purpose and Benefits of the OSI Model

The OSI model functions as a set of rules and guidelines, but in the context of networking, one might reasonably ask: rules for whom? Users and consumers never need to concern themselves with these technical details. When composing and sending an email, for example, users generally know it will be received without understanding the complex processes involved. However, those who build actual systems and applications must concern themselves with these details. The OSI model guides vendors and developers to ensure that anything they build will be able to interoperate with anything that someone else might build. Without such a framework, if one entity were to build something in any manner they chose, and another entity were to do the same, those two devices or applications might not be compatible with each other at all. By following the rules of the OSI model, all entities can be assured of compatibility with everything else.

The implementation of this model and its associated guidelines provides numerous benefits. It enables all vendors and developers to recognize how data is transmitted over wide networks, up to and including the Internet and mobile device networks. It helps new technologies adapt as they emerge and grow. The model outlines how software and hardware work together, and it assists those who support these technologies in diagnosing and troubleshooting issues when they arise. Because the model can narrow down an issue to the most probable cause more quickly than guessing or using a process of elimination, it serves as an invaluable troubleshooting tool.

The Layered Approach

One of the key aspects of the OSI model is its use of a layered approach. This approach is useful because it helps deliver more effective and reliable communication by ensuring that developers adhere to the guidelines of the entire network protocol stack, which is another way of saying they focus on all layers, not just some of them. In total, the stack is divided into seven distinct layers, each with a particular job to do to ensure mutual communication.

At the two extreme ends of the stack, we find the Application Layer at the top and the Physical Layer at the bottom. When a user types information into an email, that information must eventually be converted into electrical impulses that can be sent over a physical medium such as a cable, or as electromagnetic waves through the air. All the layers in between have various jobs to do to ensure that this can happen in a consistent manner, so that it will work for all applications on all devices. The remaining layers, from the top down, are the Presentation Layer, Session Layer, Transport Layer, Network Layer, and Data Link Layer. Each layer has a specific function to perform so that information created at the top can be converted into the appropriate format for actual transmission over a physical network, regardless of the application or device being used.

Virtual Communication Between Layers

Another result of the layered approach is that the model is observed on every device or system. In terms of communication, each layer on one device only ever communicates with its counterpart on the other device. In other words, for whatever happens at, for example, the transport layer on Host A, the only layer that will be concerned with that is the transport layer on Host B. When sending an email, as the user hits send, the information travels down the stack until it reaches the physical cable of the network. Then it runs along the network until Host B is located. That information then travels up the stack on Host B, with each layer processing only the information that was applied by its corresponding layer on the originating system. This is referred to as virtual communication, and each layer packages its own information using specific formats so that it can be recognized by the other device.

The application layer, for example, uses what is known as an Application Protocol Data Unit. While the term "packet" is commonly heard and is particularly important to routers which operate at the network layer, the application layer does not concern itself with packets at all. Another characteristic of this layered approach is that on any given single system, any given layer is only aware of the layer above it and the layer below it. The Network Layer never talks to the Presentation Layer. The Transport Layer never talks to the Physical Layer. They simply do what they are supposed to do within their layer and then pass it to the next layer, either up or down, depending on whether they are sending or receiving.

Layer 1: The Physical Layer

The Physical Layer, designated as Layer 1 in the OSI model, is responsible for the actual transmission of data over physical media. To accomplish this, several hardware components are involved, including cables, connectors, Network Interface Cards (NICs), repeaters (which are devices that can amplify a signal if it starts to degrade), and hubs (which are devices that allow multiple computers to be connected together to form a basic network). One of the key distinctions of the components at this layer is that they do not contain anything that would be considered programming. A cable, for example, is not programmed.

There is, to a certain degree, functionality that must occur, which is referred to as encoding and signaling. This is the process of literally transforming data from bits, or what are commonly thought of as zeroes and ones, into electrical signals that are then sent over the network. While there is certainly functionality at this layer, from the perspective of a programmer, it is not something that is developed or programmed. It is all basically built into the device. With respect to some of that functionality, the Physical Layer deals with the physical transmission of data. This would also include wireless mediums along with physical cables. When wireless is involved, the layer must convert information into electromagnetic waves. It also needs to consider the topology or the physical network design because different types of networks transmit data differently.

To imagine what transmission looks like at this layer, consider information coming from the Data Link Layer on the system that is about to transmit it. The Physical Layer receives ones and zeroes from the Data Link Layer. It is then the job of the Physical Layer to translate that into electrical impulses that can literally travel across something like a cable. One does not actually see ones and zeroes running across a cable. They are electrical impulses that are simply translated from ones and zeroes. Those same ones and zeroes on the receiving side can then be translated back and sent to the Data Link Layer on the receiving side. For the most part, the Physical Layer consists of hardware with certain functionality built in, but really nothing that would be considered programming or intelligence. It is truly a matter of dealing with physical components.

Layer 2: The Data Link Layer

The Data Link Layer, designated as Layer 2, introduces more of the layer-to-layer communication as data comes down from the Network Layer on the sending side and then gets passed to the Physical Layer. This reiterates how any given layer is only able to communicate with the layer above it and the layer below it. The Data Link Layer is responsible for creating a frame which determines the structure of the data for the appropriate type of network. It has a physical address, which relates to the node-to-node communication mentioned earlier.

In terms of responsibilities, the Data Link Layer adds what is known as a physical address to the data being transmitted, which means that it is destined for a specific device on the network. This contrasts with the Physical Layer where there is no addressing at all. In addition to applying the address, the Data Link Layer is also responsible for framing the data, which among other things defines the correct structure for the specific type of network being used. Access control mechanisms are implemented at this layer to determine which node has control over the physical medium at any given time during communication. Flow control helps to manage how the data is transmitted and received, and error control helps to increase the reliability of the data transmissions.

Several methods of controlling the overall transmission exist at this layer:

  • Addressing: This allows for the establishment and termination of links between two nodes, similar to answering a phone call when it rings and hanging up when finished. Specific links are established before any data is transmitted, and that link is terminated when the transmission completes.

  • Media Access Management: This determines which node currently has the ability to use the physical medium so that both nodes do not try to send data at the same time.

  • Flow Control: This helps to prevent faster senders from overwhelming slower receivers.

  • Error Control: This provides a mechanism to detect when frames are damaged or lost so they can be retransmitted.

  • Access Control: This specifies which node has control over the medium when a single communication channel is being shared by multiple nodes.

The Data Link Layer is actually divided into two sublayers. In the upper portion, closer to the Network Layer, is the Logical Link Control (LLC) sublayer, which acts as the intermediary for the media access methods below it and the Network Layer protocols above it. A communication channel can be defined as connectionless or connection-oriented at the Logical Link Control sublayer, and the appropriate higher-level protocols can be used accordingly based on that definition. In the lower section of the Data Link Layer is the Medium Access Control (MAC) sublayer, also known as the media access layer. This could be the most important section of the entire OSI model because this is where the physical address, also known as the MAC address, is processed.

The MAC address is a 12-character value expressed in hexadecimal, and it is unique to every single network interface everywhere. In a standard Network Interface Card in a computer, this value is written directly into the card itself. Even if that card were to be moved to a different computer, the MAC address would still be the same on that card. Ultimately, this is the value that allows any given node to locate any other node to initiate communications. Without it, direct node-to-node communication would not be possible.

The most prevalent device at play at this level is the switch. Switches maintain tables of all the nodes that are connected to them and record the MAC addresses of each node. When one node wants to talk to another, it is the switch that establishes the direct link between those two nodes. This contrasts with a hub, which operates at the Physical Layer where there is no addressing. The only way any two nodes can communicate through a hub is by simply sending the data out to all nodes connected to the hub. There is no such thing as direct node-to-node communication when using just a hub. Everyone hears everything, so the network is much quieter when switches are used.

Layer 3: The Network Layer

The Network Layer, designated as Layer 3, receives data from the Transport Layer as it is being sent down the stack on the transmitting side. It processes the data accordingly and passes it on to the Data Link Layer below it. At this layer, processes such as packet addressing and address conversion are found. While addressing was discussed in the Data Link Layer, there is a very important distinction here in that the address at this level is referred to as a logical address. In the Data Link Layer, the address is a physical address, meaning that it is a built-in value of the interface itself and it does not change. By contrast, a logical address can be assigned to any interface and it can be changed. This is what allows for the definition of custom networks by the addresses that are chosen.

The conversion being referenced here is the conversion of the physical address to the logical address. To better understand what that involves, consider a mobile phone. If a user has ever changed service providers, there is a good chance they were assigned a new phone number, but it is still the same phone. Phone calls are received on the original device, but by using a different phone number. The phone number is logical; it can be changed and mapped to the physical address of the device itself. The same thing happens with computers and other networking devices. They can be assigned to different networks at any time by simply changing the logical address, despite the fact that the physical address remains the same. This also happens when a laptop travels from network to network. Each time it connects to a new network, it gets a different logical address. This address is the IP or Internet Protocol address.

At the Network Layer, with an IP address, source-to-destination delivery is provided, which was also seen in the Data Link Layer. However, it goes a step further at the Network Layer by also introducing routing, which allows for the source and destination to be on completely separate networks up to and including the Internet. Physical addresses cannot be used by any device or service to perform routing. They are only used when locating devices that reside within the same network.

The functions of the Network Layer include:

  • Routing: This is the process of connecting independent networks together to form larger networks. If there is only a single network that does not need any kind of connectivity to the rest of the world, such as a classroom or a lab, then a router would never be needed. All of the devices could simply be plugged into a switch and that would be sufficient. However, the moment that network needs to communicate with any other network including the Internet, a router is required. As networks begin to grow in size, multiple paths or routes between any given source and destination can exist. Routers also try to determine the best route to take in terms of efficiency, which is not always the shortest route. Just as with regular traffic on city streets, sometimes a destination can be reached faster by taking side streets because they are not as busy. The path might be physically longer but it is still faster. The same thing can happen with routing. Routers only pass data from router to router. The source and destination being discussed here do not refer to individual host systems such as computer one and computer two. Rather, they refer to the source and destination networks, so network one to network two. Routers are not concerned with getting the data directly to the specific host. Once the data arrives at the appropriate network, that data is now in the same network as the intended host system, and the Data Link Layer can take over from there to locate the desired recipient.

  • Internetworking: This is also provided by the Network Layer. While it might seem rather similar to just routing because it is the process of providing network-to-network or internetworking connections, it goes beyond that by providing the logical connections that can support connecting different types of networks. Even with a wired Ethernet network, a fiber optic network, and a WiFi network in an environment, internetworking allows them all to be connected to form larger networks and provide better connectivity. Perhaps the most common example of this is connecting an office local area network or even a home WiFi network to the Internet. Local area networks are a fundamentally different type of network than the Internet.

  • Logical Addressing: This is not just a matter of assigning the logical IP address. It also gives the ability to create a customized addressing scheme that allows for combining many smaller networks into a larger network for greater control and management over the amount of traffic that occurs both within a network and between or among the networks. There can be many smaller networks, fewer larger networks, or anywhere in between, entirely up to the user.

  • Packetizing: The structure applied to the data received from the upper layers is known as a packet, which is the process of encapsulating the data into discrete units. This is where IP or the Internet Protocol comes into play by ensuring that each packet is assigned to both an originating or a source IP address and a destination IP address, so that every packet knows where it came from and knows where it is going.

  • Fragmentation: This process also occurs at the Network Layer. While it might at first seem like it is not a good thing, when it comes to networking, there are many factors to consider when moving data from place to place. For example, the data might have to cross different types of networks that use different physical mediums. Fragmentation can break up the packet into smaller units and then label each one so they can more easily be sent out over the different type of medium that might not otherwise support the larger packet size. Since each fragment is labeled, even if they arrive out of sequence, they can be reassembled in the correct sequence once they arrive at their destination. This might slow things down a little bit, but it is better than the transmission failing outright. The Network Layer not only gives the ability to communicate with another host, but another host that can be virtually anywhere.

Layer 4: The Transport Layer

The fourth layer of the OSI model is the Transport Layer, which, in keeping with the communication model of the entire stack, accepts services from the Session Layer above as data moves down the stack on the sending side and passes it to the Network Layer below it. The term "transport" can be a little vague, so in terms of the responsibilities of the Transport Layer, it is primarily concerned with end-to-end message delivery and error checking along the way.

With respect to the end-to-end component, previous discussion has covered ensuring that one system can locate another system by using a combination of a logical IP address at the Network Layer and a physical or MAC address at the Data Link Layer. However, that is still not the end of it. Both types of addresses are assigned at the device level, but any given device can have many different applications and many different processes running. It is necessary to locate the device first to be able to communicate, but then the question becomes: to which application on that device is the data being sent? Using a computer as an example, a user can be using a browser and a local email application at the same time. If a webpage is loaded at the same time that an email arrives, packets for both of those applications will be arriving at the same address. The browser needs to know which packets are for the webpage, and the email application needs to know which packets contain the email content. This is where the end-to-end aspect of communication comes into play. It is not just the address. The primary protocols at this level define values to distinguish one type of application protocol from another, called ports. Within the packet definition, the Transport Layer will also add a port value that allows each system to know that not only is the packet destined for a particular address, it is also meant to be used by a particular application at that address.

Error checking is also implemented at the Transport Layer, which has been seen at the lower layers. However, any given layer on one system only ever communicates with its counterpart layer on the other system. The error checking at this level still deals with ensuring that packets are delivered without duplication or corruption and in the correct sequence, but it is more specific to the type of service or application being used, which is not something that the lower layers are aware of. Some other Transport Layer functions include message acknowledgement and traffic control, but that is dependent on the protocol being used. Session multiplexing can take several message streams or sessions and combine them into a single logical link while still keeping track of which message streams belong to which sessions. Service point addressing is the process of specifying and applying the port value just mentioned.

When it comes right down to the actual delivery of data, or the transport, it falls to two primary protocols. There are other protocols at this layer, but these are by far the most common. They are the User Datagram Protocol (UDP) and the Transmission Control Protocol (TCP). Each protocol is responsible for data delivery, but that in itself can be done in more than one way. For visualization purposes, UDP can be thought of as a package delivery service, whereby something is requested, but the sender does not really care how it gets there. It will go from place to place, ultimately arriving at the address, but the delivery person could then just leave it on the doorstep. It is up to the recipient to claim it whenever they get home. TCP, however, would be more like a registered letter, something that is important and something where the sender wants to know when it arrives safely. The sender might register it at the post office and might require a signature by the intended recipient to ensure that it did arrive safely. A similar process happens with these protocols, and it really comes down to the type of application being used with respect to which protocol will be used to transport the data.

This brings us back to the idea of connectionless versus connection-oriented communications. In a connectionless transmission, the receiver does not acknowledge receipt of the transmission. The sender simply assumes that it arrived. This is analogous to the package delivery service just mentioned, whereby the delivery person simply leaves it on the doorstep. While this might not be as reliable, the plus side is that it is fast. In terms of an actual application on a device, data can just be sent and sent, and as far as the sender is concerned, everything is arriving just fine. An actual example would be streaming a video, which is almost certainly using connectionless transmissions. UDP is the transport protocol being used because with streaming, speed is desired.

By contrast, connection-oriented transmissions establish a connection between the two endpoints before any data is transmitted. The two systems agree to various parameters such as how many bytes are sent in each segment. Most notably, they agree to use acknowledgments and synchronization to guarantee that every packet arrives safely. This is more like the registered mail mentioned earlier. A signature is required upon receipt, and this allows the sender to know that the letter was received. For each block of data that is sent, the sender must wait for an acknowledgment from the receiver before any more data will be sent when using a connection-oriented transmission. TCP is the transport protocol used for this type of communication. The tradeoff is that connection-oriented communications using TCP might be slower, but they are more reliable than connectionless communications that use UDP. An example of connection-oriented communication using TCP would be sending an email, which typically does not need to be particularly fast, but reliability is desired. It really comes down to the application being used, and ultimately, whether speed or reliability is preferred.

Layer 5: The Session Layer

The fifth layer of the OSI model is the Session Layer, which is responsible for the overall management of communication between two devices, including the establishment or the beginning of the session, its maintenance during communications, and termination of the session at the end. Overall, it regulates the flow of data between the devices. Session protocols at this layer are responsible for defining the parameters of the connection and managing the transfer of data by specifying who can transfer and for how long. As an example, the Session Layer can be thought of as the moderator of a debate, ensuring that everyone gets their turn to speak.

When a session is established, maintained, and terminated, several things occur. The Session Layer enables the two systems to establish the session between them. It is usually not just a matter of saying "let's communicate" without any other considerations. One of the more common support requirements of establishing a session is to address the security of the connection using features such as name recognition, or perhaps more commonly, a login. While a login and/or a secured connection is not always required, when it is, the Session Layer is responsible for this negotiation to ensure that all security considerations have been met.

Another aspect of communication that is managed by the Session Layer is what is known as dialog control, which determines which device will communicate first and how data will be sent by each device in terms of who can transmit and when. There are three main types of dialogue control:

  • Simplex: Communication occurs in one direction only. One device transmits while another device receives. A common example of simplex communication would be listening to the radio; the listener can receive but cannot transmit back.

  • Half Duplex: Traffic can occur in both directions, but only in one direction at a time. One device transmits while the other receives, then the roles can be reversed so that communication can occur in the opposite direction.

  • Full Duplex: Traffic can be two-way at the same time. Both parties could speak at the same time and still be understood. While people do not normally speak this way in conversation, computing devices can do this just fine. Full duplex is how most digital transmissions occur these days, but older devices or older applications might not support it.

Some of the protocols that work in the Session Layer include NetBIOS (Network Basic Input Output System) and DNS (Domain Name System), both of which are methods of communicating involving name recognition and resolution. RPC (Remote Procedure Call) is a client-server redirection method whereby requests are generated on clients but executed on servers. NFS (Network File System) allows client systems to access server-based resources such as folders and files. Ultimately, the Session Layer, as its name indicates, is responsible for negotiating and maintaining the overall flow of communication during the session.

Layer 6: The Presentation Layer

The Presentation Layer, designated as Layer 6, is responsible for presenting data to the Application Layer in a format that is understandable by the application itself. To envision what is actually going on at the Presentation Layer, it is useful to imagine the information going up the stack. In most earlier discussions, reference was made to how data moves down the stack on the sending side. However, it goes up the stack on the receiving side. The idea is to present the data to the Application Layer in a format that is understandable by the application itself.

The application might not understand the data because the sending system may not be entirely compatible with the receiving system. They may be using different operating systems or different applications. The data may simply have arrived in a format that is not natively understood by the application on the receiving side. The Presentation Layer is responsible for examining that data and determining what needs to be done to it so that the application will understand it.

One of the responsibilities of this layer is what is known as character code translation. This involves the fact that human beings use what are considered standard characters, but ultimately, any kind of digital device is using ones and zeroes. There needs to be a mechanism to convert the characters that are used into ones and zeroes. Two common methods include ASCII (American Standard Code for Information Interchange) and EBCDIC (Extended Binary Coded Decimal Interchange Code). These are two mechanisms to simply take the characters that are used and to code or translate them into digital information. Other components of the conversion process depend on features such as the bit order (quite literally the order by which the bits are received), how to interpret instances of carriage return and/or line feed (these are quite literally taken from the days of typewriters, whereby the carriage had to be slid over to get down to the next line), and integer and/or floating point numbers. Different operating systems and/or different applications may treat all of that character code translation and data conversion differently. The Presentation Layer is responsible for trying its best to make it all consistent so that one application can communicate with a completely different application and still understand the data.

There are two very common processes that also occur at this layer:

  • Data Compression: Most people are familiar with this. There are many applications that will compress data. The idea is to simply reduce the number of bits that are being transmitted on the network. A common method of compressing data is to use what is known as token conversion, whereby certain redundant strings of bits are replaced by something else that requires fewer bits. To imagine this, if one were to pick up a book and find every instance of the word "the" in that book, there would be a lot of them. Imagine replacing every instance of the word "the," which is three characters, with some kind of token character such as an asterisk. Now every single time there are three characters, they can be replaced with one. This reduces the number of bits that need to be transmitted on the network. However, it is the job of the Presentation Layer to look after that because the application does not expect to see token values; it expects the actual data. The Presentation Layer is responsible for compressing and decompressing that data to present it to the application in an uncompressed manner.

  • Data Encryption: This is similar to compression in that different characters are used. However, when it comes to encryption, the data needs to be scrambled and a variety of different characters used so that, as far as the user is concerned, the data is unreadable. The applications that are used do not present users with unreadable characters. Users see the data as it was intended for them. Once again, the job of the Presentation Layer is to handle that encryption and decryption so that the regular data that is supposed to be seen is what is presented, as opposed to all of those scrambled meaningless characters. Regardless of the application being used, or perhaps even the operating system on each device, communication can still be secure because the Presentation Layer is handling all of that behind the scenes.

Layer 7: The Application Layer

The seventh layer of the OSI model is the Application Layer. In OSI model terms, it is not really the application itself; rather, it is the collection of protocols that are required to support the functionality of the application. To clarify this, consider sending an email. Many email applications have several other capabilities beyond just sending and receiving mail. A user might book an appointment into a calendar, create a new contact, or leave a reminder. However, none of those operations require the system to communicate with any other system. They are just features of the application. The interface is used, but there is really nothing happening in terms of connectivity to another system. However, when an email actually needs to be sent to someone else, then a communication protocol is required to support that feature. One of the most common examples is the Simple Mail Transfer Protocol (SMTP). This is one of the most common messaging protocols. The application needs that protocol to allow it to perform the task that it needs to do.

Another very common example would be using a browser. In the address bar of the browser, the letters "http" are often seen, which stands for Hypertext Transfer Protocol. This is a standard mechanism for transporting data over the Internet. The browser application is informing the system on the other side which type of protocol is to be used to send the data. There are many Application Layer protocols that operate at Layer 7. A few examples include:

  • FTP (File Transfer Protocol): A means to simply transfer a file from one system to another, usually over the Internet.

  • DHCP (Dynamic Host Configuration Protocol): Responsible for assigning IP address configuration to client systems.

  • DNS (Domain Name System): Responsible for resolving names.

  • SMTP (Simple Mail Transfer Protocol): Responsible for sending mail.

  • HTTP (Hypertext Transfer Protocol): The protocol used by browsers and similar applications.

In terms of functionality, the Application Layer allows users to interact with the applications. The application needs to accept the user input and then pass that data down to the lower layers for processing. It allows for easier application compatibility and implementation because as long as the appropriate Application Layer protocol is being used, then the functionality of the application is really up to the developer. As long as the correct protocol is being used, it will be compatible with other applications. This means that they do not have to be rewritten for different types of networking environments.

The user on the sending side enters data, which is accepted by the Application Layer. It is then passed down to the Presentation Layer, and it keeps going all the way to the bottom of the stack. It then travels across the network and travels up the stack on the receiving side through the Presentation Layer into the Application Layer, and then it is ultimately consumed by the user on the other side. Some application examples include mail services. SMTP is a very common Application Layer protocol that supports mail services, but it is not the only one. There are several protocols that are responsible for what is generally referred to as file transfer, access, and management, whereby files are simply sent across the network, permissions are controlled in terms of who is able to get to those files, and they are simply handled appropriately. There are many protocols that are responsible for handling all of those processes, but they all work at the Application Layer.

Browsers provide the ability to access the Internet from just about any kind of networking environment. There is no need to be concerned if a browser is supported by the web server on the other side. As long as the browser is using the appropriate protocol, then the server does not really care what the browser is. There can be some inconsistencies with respect to formatting, but it is pretty rare that the web server would simply say, "I don't recognize that browser, therefore I'm not going to send you anything." Again, it is not really the application itself. It is the protocol that the application is using that determines whether or not these two systems, these two applications, can communicate effectively.

Ethernet/IP Headers

The Ethernet frame format operates at Layer 2 or the Data Link Layer. The IP header operates at Layer 3 or the Network Layer. The TCP and/or UDP header operates at Layer 4 or the Transport Layer. Beginning with the Ethernet frame format, it helps to back up a little bit and talk about the original format. It will be seen that this has been updated to reflect more modern networks, but it helps to see how things have changed over time.

In the original Ethernet frame format, information was added to the actual data to ensure that it could be formatted correctly to traverse an Ethernet network. To understand what it means to be using an Ethernet network, it helps to back up some more into the earlier days of networking and compare it to one of its competitors, the Token Ring network. Token Ring networks are virtually extinct these days when it comes to what would be thought of in terms of the network at an office. However, when networks were first emerging, they were commonplace. In a Token Ring network, every system was connected to a neighboring system in sequence, but in a closed loop, hence the term "ring." To visualize this, imagine a bus route. The bus arrives at a stop and passengers get on. It goes from stop to stop, some people get on, and others get off at the appropriate stop. The bus just keeps circling that route over and over again.

That is more or less what happens in a Token Ring network. One system will send data out to another system by placing a token on the network or the ring. The ring equates to the bus route. The token equates to the bus itself. It is the carrier. The token would be passed from system to system until it arrived at the intended recipient, which would then offload the data for processing. Other systems could then place data into the token and send to other systems accordingly.

Contrast this with an Ethernet network. There are no tokens in Ethernet. If data needs to be sent to another system, it is just placed onto the wire and off it goes. However, ultimately, this is just talking about electrical signals on a physical wire. If two systems both tried to send data at the same time on the same wire, those electrical signals would literally collide with each other and both would be destroyed. This is in fact referred to as a collision and can still be an issue to this day. With a single token on a ring, each system could just use the token when and if necessary, and pass it along. There are no collisions in a Token Ring. However, this method was not very fast. Token Ring networks never got faster than about ten megabits per second. They were easily eclipsed by the speed of Ethernet, which these days gets well into the gigabit per second range.

The frame format is the means by which the frame can access the network and find its way to the destination on this particular type of network, even if a collision or any other problem occurs. If still on a Token Ring network, then the system would not be looking to construct an Ethernet frame type. It would need to construct a Token Ring frame type. The Ethernet frame begins with the destination address, which is the 6-byte physical address or MAC address. At the Data Link Layer, logical addresses such as IP addresses are not used. The source address is the MAC address of the sender. This is always included so that if a problem occurs, the receiving system can inform the sending system that something went wrong and that a frame might need to be retransmitted. The length is a 2-byte value that indicates the entire length of the frame so that the receiver knows what to expect. The data is the actual information that the sender wants to send, such as the content of an email, and ranges from 46 to 1500 bytes in size. The CRC is a 4-byte cyclical redundancy check, which is a mathematical code generated from other values such as the destination and source addresses, the length, and the data.

To give a very simplistic example of what that looks like, imagine sending a letter with a street address as the destination, let's say it is five, and my street address as the source, let's say it is ten. If the letter itself simply contained the number 15, then the destination address plus the source address plus the value in the letter (so 5 plus 10 plus 15) should all add up to 30. If the letter is received and opened and it contains the number 5 instead of 15, then all three values will not add up to 30. This indicates that something went wrong. In other words, the data has become corrupted and that data should be discarded and retried.

Since the architecture of Ethernet networks has improved, there is now an extended Ethernet frame type, also referred to as Ethernet II. This specifies the logical address of the Network Layer entities that are sending and receiving the data. The control is a 1-byte value that indicates connectionless versus connection-oriented communications. The data is still a minimum of 46 bytes but can get slightly above its predecessor, up to 1,522 bytes in some cases. The FCS is a frame checksum which effectively still handles error checking. The CRC just mentioned is a type of checksum, but there are other ways to implement a checksum. Ultimately, they determine the validity of the data in the frame.

Moving up a layer to the Network Layer, the IP header is found, which in total is 20 bytes in length. It is made up of multiple sections, which designate similar values to what was just seen in the Ethernet frame. Most notably the source and the destination addresses, but now in the form of the logical IP address, not the physical or the MAC address. Among other components, it also includes information as to which version is being used, the length, a checksum, and a value known as the TTL, or Time To Live, which gives it a lifespan outside of which the packet should be deemed as unreliable and should be retransmitted. What is most notable here is the fact that the addresses used are the logical IP addresses, not the physical addresses.

Moving up a layer again, the Transport Layer is reached, where the transport protocols of TCP and UDP are seen. The TCP header ranges from 20 to 60 bytes in size and is used to specify which TCP port is being used. Since communications over TCP are connection-oriented and use acknowledgments to guarantee packet delivery, the TCP header is also used to monitor the state of the connection. If the communication is connectionless, then a UDP header is found. This specifies the UDP port being used at both the source and the destination, just like the TCP header. However, other than the data itself, there is only a checksum value that is typically only used to validate the structure of the header itself with respect to the source and destination port addresses. In most UDP transmissions, if the data is lost or corrupted, it is not retransmitted. In fact, in IP version 4, this field is optional.

With respect to the size of the data or what is also known as the payload, notice that it can be up to 65,000 plus bytes in size. That is also the case for a TCP header, but an Ethernet frame type only supports around 1,500 bytes. This is where fragmentation at the lower layers is required, breaking packets up into smaller units for transmission on the appropriate type of network. If a UDP or a TCP packet is up around its maximum size, it will have to be broken up into about 43 fragments to be transmittable over an Ethernet network. Each type of header is added to the original data to simply ensure that the data is sent and received appropriately. Relating this to sending a regular package through the mail or with a courier, there are many different ways to get that package from point A to point B. The headers in use at these layers work together to ensure success across all methods of delivery.

TCP Flags

TCP flags are used to more or less control the conversation between the two systems so that the data is transmitted as effectively and as efficiently as possible. The first flag is Synchronization (SYN), which is typically used in the first step of establishing the connection. It is also referred to as a three-way handshake between the hosts, whereby the initiating system will say "I would like to initiate communication." The receiving system will say "I'm ready to receive." Then the sender will say "okay, let's begin." That is the three-way process. Only the first packet from the sender will have this flag set. This indicates that it is the first packet, and then the receiving side essentially knows what to expect from there.

Next is the Acknowledgment flag (ACK), which is used to simply acknowledge receipt of that packet. The sender will send that very first packet with the Synchronization flag attached. The receiver will acknowledge the fact that it received the first packet, and along with the acknowledgement is its own synchronization. So it is not only sent from the sender. To recap, the sender will send out the very first packet with the Synchronization flag. The receiver receives that packet, sends back an acknowledgement. But this is also the first packet sent back by the receiver, so there would also be a Synchronization flag there as well. That would be the end of the Synchronization flags. The Acknowledgment flag from that point is simply used to say that yes, the packet was received, and more may now be sent.

The FIN, or Finish flag, is appropriately named because it is used to request connection termination. For instance, when there is no further data from the sender, the FIN flag will be the last packet sent by the sender, and this will gracefully terminate the connection between the two hosts. The Reset, or RST flag, is also used to terminate a connection, but it is not a graceful termination like the FIN flag is. This is issued when one system feels like something is wrong. Maybe the connection simply should not exist between the two hosts, or the receiver received a packet that it was not expecting. Reset terminates the connection, generally, when something just is not correct.

The Push flag, or PSH, is used in certain applications when buffering needs to be managed or controlled. The Transport Layer might wait for the higher-level layers to provide it with more data so that the packet is as full as possible before it is sent. In some cases, that is good because it means fewer packets on the network, so it is a little more efficient. In other types of applications, it is not so good. Anything that is a real-time application, such as video conferencing or maybe a chat, should not really buffer any data because it can slow things down. In those types of applications, the Push flag is used to move things along so that the real-time aspect of that application is maintained.

The Urgent flag, or URG, means that data is forwarded immediately upon receipt. This packet that was just received should take priority over other packets. Something happened in the application whereby this packet that was just generated is essentially more important than earlier ones. The receiver is notified that it should be processed first. It is also notified once all of the urgent packets are received so it knows when to revert back to normal processing. That is dependent on the application. Ultimately, TCP flags are used to more or less control the conversation between the two systems so that the data is transmitted as effectively and as efficiently as possible.

Fixed and Variable Payloads

When it comes to the payload, there are two different sizes or two different methods of constructing the payload. The first is what is known as a fixed payload, whereby the amount of data that is being sent is a fixed size, set to a particular value. The flag is seen, the header is seen, but then it is always the same size in terms of the payload. There might be a trailer, of course. When there is a fixed payload size, it can be a little more efficient because the system always knows what to expect. It is always going to be a certain amount of data for every frame that is being placed onto the wire.

The opposite of that is the variable length payload, whereby a pattern is used to determine the frame size. The flag and header are still seen, but then there is this variable length in terms of the payload, and still any trailers and flags that might be necessary. With a variable length, it means that there could be a certain amount of data in one frame and a different amount of data in the next frame. That might require a little more processing, but it can mean that more data can be put into a frame. It really comes down to the type of application being used. The type of payload that is going to be used is really up to the developer. They would determine what would be better for this particular type of application, a consistent or fixed size payload or a variable length payload. The goal is that the implementation of one type of payload over another will allow that application to perform at its highest level.

MTU vs. MSS

The Data Link Layer is responsible for constructing the appropriate frame type for the appropriate network being used. Although the MTU value is constructed at a higher layer, it is typically consistent with the frame size that is constructed at the Data Link Layer. This can be adjusted. Increasing the MTU size does have some advantages in that more data can be transmitted because more data is being packed into each frame. The overall data transfer rate will increase because this enables what is known as the use of jumbo frames. This is typically something that can be done within a local area network. However, there is no control over what happens at the Internet level. If everything on the network supports this, then jumbo frames can typically be as large as 9000 bytes, whereas the standard is usually around 1500.

There is a disadvantage to doing so because certain routers cannot handle the larger packets. This will result in errors in transmissions. If considering changing the size, the optimal size on a network can be found by using the ping command on Windows systems. This is also supported on Mac systems. Ping is simply a command that tests connectivity. A command prompt can be opened, the word "ping" typed in, and then either the URL or the name of a local server, or its IP address. Then "-f" is used, which means to not fragment the packet. Then "-l" allows for specifying the size. It is usually recommended to start with something in the neighborhood of 1500 because that is usually the default. It is also recommended to maybe subtract some of the headers and footers. Most documentation will suggest starting around 1472.

To put this in context, if the server that is to be tested is simply called "server one," then "ping server1 -f -l 1472" can be entered. The name can be replaced with the IP address or a URL. This can also be done on Mac systems. It is still the ping command, then the URL or the name or its IP address, but then it is "-d" and "-s," and then the size is entered. In terms of the results, whenever a system is pinged, replies are received. A normal reply is four responses that all just say successful. If that is what is received, then that size was fine. Then the size can simply be increased. As long as four successful replies keep coming back, then that size was acceptable. Once the maximum is exceeded, it will come back and indicate that the packet was fragmented. This allows for finding out what the optimal size should be.

In terms of actually adjusting the MTU size on Windows systems, the Netsh command, which stands for net shell, can be used. On Linux systems, the ifconfig command can be used. On Macs, this value can be changed manually using system preferences. Another value that should be mindful of is the Maximum Segment Size (MSS). This determines the largest amount of data that any given device can handle, not just the network itself. With the MSS, the data segment and any headers in total should be less than the MTU size. If it is larger, then this device is attempting to send out information that is too large for that network. Typically, it should be equal or less than the MTU.

Most devices, most operating systems, and even most networking equipment these days are able to negotiate these values automatically. There would be default values, of course. If for any reason a different value can be supported, then in many cases it can be adjusted automatically. These days there is not a lot of manual adjustment that is made to these values. Usually the default values are fine, or the ability for the devices to automatically adjust on the fly will be sufficient to make those changes if and when necessary.