OSI Model Layers and Encapsulation Explained for CompTIA Network+ (N10-008)

Why the OSI Model Matters in Network+

If you’re studying for CompTIA Network+, the OSI model can feel like pure memorization at first. That’s normal. For the exam, and honestly out in the real world too, it gives you a clean way to sort through protocols, devices, addresses, and failures without getting lost in the weeds. TCP/IP is what we actually use in production, but OSI still gives you a much clearer way to learn it and explain it to somebody else. It helps you narrow down the problem fast. Are you looking at a bad cable, a VLAN mismatch, a routing problem, a blocked port, or something odd up at the application layer?

For current study, think in terms of Network+ N10-009. If you’re using older materials labeled N10-008, most of the OSI concepts still apply, but the current exam version is N10-009. Also remember one big exam rule: OSI layer mapping is conceptual. Real protocols and devices often span multiple layers. Network+ usually wants the primary layer or function.

A simple memory aid for layer order from top to bottom is: All People Seem To Need Data Processing. Bottom to top: Please Do Not Throw Sausage Pizza Away. Really, use whatever mnemonic clicks for you and helps you recall the order quickly when the pressure’s on.

OSI Layers at a Glance

Layer # Layer name Primary function Examples Typical devices PDU
7 Application Network services that users interact with directly HTTP, HTTPS, DNS, DHCP, SMTP, IMAP, POP3, SSH, and SNMP — the usual suspects you’ll see in Network+ study Application servers, proxies, clients Data
6 Presentation Translation, encryption, compression, formatting TLS concepts, character encoding, format conversion Libraries, gateways, application components Data
5 Session Session setup, maintenance, teardown RPC, NetBIOS, session control concepts Session-aware applications Data
4 Transport End-to-end delivery, reliability, ports TCP, UDP Hosts, stateful firewalls, load balancers Segment / Datagram
3 Network Logical addressing and routing IPv4, IPv6, ICMP, IPsec Routers, Layer 3 switches Packet
2 Data Link Framing, MAC addressing, local delivery Ethernet, 802.11 MAC, PPP, 802.1Q, and STP, which are the big Layer 2 names you need to recognize Switches, bridges, access points, and NICs — basically the gear that lives in the Layer 2 world most of the time Frame
1 Physical Signals, media, connectors, bits on the medium Copper, fiber, RF, and transceivers Cables, repeaters, hubs, and SFPs, which are the physical pieces that make the signal actually move Bits

Getting Comfortable with the Layers Without Making This More Complicated Than It Needs to Be

Layer 7 – Application: This is where user-facing services live. HTTP loads web pages, DNS turns names into IP addresses, DHCP hands out IP settings, SMTP sends mail, and SSH gives you secure remote access — pretty much the everyday stuff people rely on without thinking about it. On the exam, remember that where a protocol belongs and where the problem shows up aren’t always the same thing. DNS is definitely an application-layer protocol, but a DNS problem can still end up being a Layer 3 reachability issue or a Layer 4 transport issue.

Layer 6 – Presentation: Think formatting, encryption, and translation. TLS often gets tied to this layer in OSI because it helps secure and transform the data, but in real TCP/IP conversations it usually gets grouped into the application side of things. For Network+, it’s better to focus on what TLS does than to get stuck debating exactly where it sits.

Layer 5 – Session: This layer manages the conversation state between systems. It can feel a little abstract, because a lot of modern apps manage session logic on their own, but the basic idea still matters. If a login session drops, a voice call loses state, or an app connects but can’t keep the conversation going, that’s the sort of problem Session is talking about.

Layer 4 – Transport: This is where ports, segmentation, reliability, and end-to-end host communication live. TCP is connection-oriented and uses sequencing, acknowledgments, retransmissions, and windowing. UDP is connectionless and lower overhead. Technically, TCP carries a segment and UDP carries a datagram, though many Network+ resources use “segment” as Layer 4 shorthand. Key exam anchor: ports = Layer 4.

Layer 3 – Network: This layer handles IP addressing and routing. Routers make forwarding decisions using Layer 3 information, which is exactly why IP matters so much here. ICMP also lives here and is used by tools like ping and tracert/traceroute. Important exam point: ICMP is not TCP or UDP and does not use ports. Key anchor: IP = Layer 3.

Layer 2 – Data Link: This is local delivery on the same network segment. Frames use MAC addresses, switches learn MAC-to-port mappings, VLANs split broadcast domains, and STP helps keep loops from taking the network down. Ethernet frames include an FCS field that commonly contains a CRC value for error detection. Key anchor: MAC = Layer 2.

Layer 1 – Physical: This is the actual transmission of bits over copper, fiber, or wireless media. Think bad cables, sloppy patching, dirty fiber, transceiver mismatches, EMI or RFI, or just a dead link light. If Layer 1 is down, nothing above it really matters yet, which is why I always start there when the link’s dead.

PDUs, Addressing, and Encapsulation Basics

The OSI model becomes useful when you connect each layer to its PDU and addressing method:

Layer PDU Identifier Example
7–5 Data Application/session context HTTP request, login session, encoded content
4 TCP segment / UDP datagram Port numbers Source 51544 → destination 443
3 Packet IP addresses 192.0.2.10 → 198.51.100.20
2 Frame MAC addresses Client MAC → default gateway MAC
1 Bits None Electrical, optical, or RF signals, depending on the medium you’re working with

Encapsulation means each lower layer wraps the data from the layer above with its own control information as the data moves down the stack.

Application data → TCP header + data = segment or UDP header + data = datagram → IP header + Layer 4 payload = packet → Ethernet header + packet + FCS trailer = frame → bits on the medium.

When the data arrives, the process just runs in reverse through de-encapsulation.

Here’s a subtle but really important point: some information is end-to-end, and some of it only matters hop by hop. MAC addresses only matter on the local link, so routers strip off the Layer 2 frame and build a new one at every hop. The Layer 3 source and destination usually stay the same end to end, but the IP packet isn’t completely untouched—routers decrement the IPv4 TTL or IPv6 Hop Limit, and IPv4 routers also update the header checksum. And in real environments, NAT, PAT, tunneling, proxies, and load balancers can definitely change what you see in practice.

ARP, NDP, and the Layer 2/3 Boundary

ARP is a common exam trap. In IPv4, ARP maps a Layer 3 IPv4 address to a Layer 2 MAC address on the local link. That’s why it is often taught at the Layer 2/Layer 3 boundary or simply associated with Layer 2 for exam purposes. Strictly speaking, it doesn’t fit neatly as a native OSI layer protocol the way IP or Ethernet does.

For example, a host wants to reach its default gateway at 192.168.1.1, but it doesn’t know the gateway’s MAC address yet. So it broadcasts an ARP request asking which device owns 192.168.1.1. The router replies with its MAC address, and the host saves that in its ARP cache.

For IPv6, there is no ARP. IPv6 uses Neighbor Discovery Protocol (NDP), which relies on ICMPv6 for neighbor solicitation, neighbor advertisement, and router advertisement. That is a favorite compare-and-contrast item: IPv4 uses ARP; IPv6 uses NDP.

HTTPS Example: Correct Order of Events

Here’s the clean sequence when someone opens an HTTPS website:

  1. DNS lookup: The client resolves the name to an IP address. DNS is an application-layer protocol, usually over UDP 53, although TCP 53 does show up in some cases.
  2. ARP or NDP for the next hop: If the destination is remote, the client resolves the local default gateway’s Layer 2 address.
  3. TCP three-way handshake: The client sends SYN to destination port 443, the server replies with SYN-ACK, and the client responds with ACK. The TCP connection really isn’t established until that handshake finishes.
  4. TLS handshake: After TCP is established, the client and server negotiate encryption settings and validate certificate information.
  5. Encrypted HTTP exchange: The browser sends the HTTP request inside TLS, and the server returns the encrypted response.
  6. Routing across the path: At each router hop, the Layer 2 frame is rebuilt, MAC addresses change, and TTL or hop limit is reduced. The Layer 3 path and Layer 4 conversation are still part of the same overall exchange unless something like translation or tunneling changes the picture.

This ordering matters. A lot of learners accidentally place TLS before TCP, but TCP has to come up first.

Transport, Routing, and Fragmentation Details You Really Need to Know for the Exam

At Layer 4, know the basic TCP lifecycle: SYN, SYN-ACK, ACK for connection setup; FIN/ACK for normal teardown; RST for abrupt reset. In packet analysis tools, those flags are often the fastest way to tell whether a connection is starting the way it should. If you see SYN packets going out but no SYN-ACK coming back, start thinking about reachability, filtering, or whether the service is actually available.

At Layer 3, understand default gateway logic: if the destination IP is outside the local subnet, the host sends the traffic to its configured gateway. That’s why a wrong subnet mask or a wrong default gateway can still let local traffic work while remote access falls apart completely.

Fragmentation also needs precision. IPv4 routers may fragment packets in transit unless the Don’t Fragment setting prevents it. IPv6 routers do not fragment packets in transit; IPv6 relies on Path MTU Discovery and endpoint behavior instead. MTU problems often appear as “small packets work, large transfers stall,” especially across VPNs and tunnels.

OSI vs TCP/IP Model

OSI is the conceptual reference model. TCP/IP is the practical implementation model. In TCP/IP, OSI Layers 7, 6, and 5 are generally folded into the Application layer; Layer 4 maps to Transport; Layer 3 maps to the Internet layer; and Layers 2 and 1 map to the Link or Network Access layer. Some resources teach TCP/IP as four layers and others as five, but the basic idea stays the same.

That’s why TLS might show up under Presentation in OSI discussions but under Application in TCP/IP discussions. The network didn’t change—the way we grouped the functions changed.

Common Devices, Controls, and Security by Layer

For exam questions, classify devices by their primary function:

  • Layer 1: hubs, repeaters, cables, transceivers
  • Layer 2: switches, bridges, wireless APs acting as bridges, VLANs, STP, port security, 802.1X access control
  • Layer 3: routers, Layer 3 switches, ACLs, IPsec
  • Layer 4: stateful firewalls, port filtering, some load balancers
  • Layer 7: proxies, web application firewalls, content filters, application gateways

Be careful with multilayer devices. Firewalls, load balancers, and next-generation firewalls can inspect Layers 3 through 7. Wireless APs are usually treated as Layer 2 bridging devices for exam purposes, even though they also handle Layer 1 RF functions.

Using the OSI Model to Troubleshoot in the Real World

The three classic approaches are bottom-up, top-down, and divide-and-conquer. Bottom-up is usually the best place to start when you suspect a physical or local connectivity issue. Top-down is really useful when the complaint starts with an application issue. Divide-and-conquer works well when you already know part of the path is working.

Layer Typical symptom First check
1 No link, intermittent drops Cable, port, SFP, RF signal, link light
2 VLAN mismatch, local LAN failure Switchport VLAN, MAC table, trunk/access mode, STP state
3 Local works, remote fails IP, mask, gateway, route, ping, tracert/traceroute
4 Specific port or app fails TCP handshake, firewall/ACL, listening service, port test
5 Session drops, call/login state lost Session timeout, app state, remote access behavior
6 Encryption/certificate/format issue TLS errors, certificate validation, encoding mismatch
7 Name resolution or service error DNS, service status, logs, application response

Useful commands by layer include ipconfig /all or ip addr, ping, tracert/traceroute, nslookup or dig, arp -a or ip neigh, and netstat or ss. On Linux, ss is generally preferred over netstat on modern systems.

Two quick scenarios: if a host can reach devices on its own subnet but not external networks, I’d first suspect Layer 3 configuration, especially the default gateway. If DNS resolves and ping works but HTTPS still fails, suspect a Layer 4 or Layer 7 policy issue like blocked TCP 443, a proxy problem, or a TLS or certificate issue.

Quick Mini-Lab: What to Look for in Wireshark

Capture one DNS query and one HTTPS connection, then compare them side by side. In the DNS packet, identify the Layer 2 source and destination MAC addresses, the Layer 3 IP addresses, and the Layer 4 UDP or TCP port 53 fields. In the HTTPS flow, look for the TCP SYN, SYN-ACK, ACK sequence first, then the TLS handshake, and then the encrypted application data. Honestly, this is one of the fastest ways to make encapsulation feel real instead of just theoretical.

If you inspect the packet details pane, map the fields back to the layers: Ethernet header and FCS at Layer 2, source and destination IP plus TTL or Hop Limit at Layer 3, source and destination ports plus TCP flags at Layer 4, and DNS, HTTP, or TLS details in the upper layers.

Common Exam Traps and Best-Answer Reminders

  • ARP vs NDP: ARP is IPv4 only; IPv6 uses NDP.
  • Segment vs datagram: TCP uses segments; UDP uses datagrams.
  • Packet vs frame: routers forward packets; switches forward frames.
  • ICMP has no ports: ping is Layer 3, not Layer 4.
  • TLS placement: Presentation by function in OSI, commonly grouped with Application in TCP/IP.
  • Segmentation vs fragmentation: segmentation is Layer 4; fragmentation is Layer 3.
  • DNS can use both UDP and TCP: don’t assume UDP only.
  • Multilayer devices exist: choose the best answer based on primary function in the question.

Watch for wording like “primary layer,” “best answer,” or “most likely cause.” CompTIA often wants the most direct symptom-to-layer match, not necessarily the most technically detailed explanation.

Final Review Cheat Sheet

Memorize: the seven layers in both directions, PDUs, and the anchors ports = Layer 4, IP = Layer 3, MAC = Layer 2.

Understand: encapsulation, what changes at each router hop, TCP handshake order, ARP vs NDP, IPv4 vs IPv6 fragmentation behavior, and OSI vs TCP/IP mapping.

Be able to explain out loud: what happens when a browser opens an HTTPS site from DNS lookup to TCP handshake to TLS to encrypted HTTP response.

Quick self-test: Can you identify the highest confirmed working layer and the lowest failing layer in a scenario? Can you tell whether the issue is physical, local switching, routing, port access, encryption, or an application problem? physical, local switching, routing, port access, encryption, or an application service problem? If you can do that, you’re using the OSI model the way Network+ expects—and the way real techs actually troubleshoot in the field.