Difficulty: Beginner
Explain the OSI model and the TCP/IP model. How do their layers map to each other, and at which layer do protocols like HTTP, TCP, IP, and Ethernet live?
Let's start with the question that opens almost every networking interview, because if you answer it cleanly, the interviewer relaxes and the rest of the round goes smoother. The core idea is layering: instead of one giant program that knows how to move bits over copper and also render a web page, we split the problem into layers. Each layer only talks to the layer directly above and below it, and to its peer on the other machine. Think of posting a parcel: you write a letter, put it in an envelope, the courier puts that in a box, the truck carries the box. Nobody in the truck cares about your letter.
The OSI model is a seven-layer reference model from ISO. From top to bottom: Application (7), Presentation (6), Session (5), Transport (4), Network (3), Data Link (2), and Physical (1). Application is what user-facing protocols like HTTP, SMTP, FTP and DNS belong to. Presentation deals with data format, encryption and compression, which is why people often place TLS here. Session manages dialogues between endpoints. Transport gives end-to-end delivery between processes, so TCP and UDP live here. Network handles logical addressing and routing, so IP, ICMP and routers live here. Data Link handles hop-to-hop delivery inside one network using MAC addresses, so Ethernet, Wi-Fi and switches live here. Physical is the raw bits: cables, signals, hubs.
The TCP/IP model is what the internet actually runs on, and it has four layers: Application, Transport, Internet, and Network Access (sometimes called Link). The mapping is simple. OSI layers 5, 6 and 7 collapse into the TCP/IP Application layer. OSI Transport equals TCP/IP Transport. OSI Network equals the Internet layer. OSI Data Link and Physical collapse into Network Access. Some textbooks draw TCP/IP with five layers by splitting the bottom one, and it is fine to mention that.
The key practical difference: OSI is a theoretical reference model that was designed first and protocols fitted later, while TCP/IP was built around working protocols and the model describes them afterwards. That is why real protocols do not fit OSI neatly. TLS is the classic example: it sits between TCP and HTTP, so it is arguably layer 5 or 6, but in practice it is just a library the application calls.
Now encapsulation, which interviewers love. When you send an HTTP request, the application data gets a TCP header and becomes a segment, the segment gets an IP header and becomes a packet, the packet gets an Ethernet header plus trailer and becomes a frame, and the frame goes on the wire as bits. The receiver reverses this, which is decapsulation. The unit names are worth memorising: data, segment (datagram for UDP), packet, frame, bits.
One edge case that impresses: devices operate at different layers. A hub is layer 1, a switch is layer 2, a router is layer 3, and a load balancer or firewall can be layer 4 or layer 7 depending on whether it looks at ports or at HTTP content. Also, when a router forwards a packet, it strips and rebuilds the layer 2 frame at each hop, but the layer 3 IP source and destination stay the same (ignoring NAT). That single point explains a huge amount of networking behaviour.
Application : GET /index.html HTTP/1.1 (data)
Transport : [TCP src 51000 -> dst 80] + data (segment)
Internet : [IP 10.0.0.5 -> 93.184.216.34] + seg (packet)
Link : [Eth src MAC -> gateway MAC] + pkt (frame)
Physical : 010101100101... (bits)
Each layer only adds its own header and treats everything above as opaque payload.
OSI Model, TCP/IP Model, Encapsulation, Layered Architecture, Protocols