Limited Offer

30% OFF Lifetime Access ($139) with code SYSTEM30

TOPIC #11Beginner 7 min read

OSI vs TCP/IP Model Overview

💡
Core Architecture Summary

Understand abstraction layers in distributed networking: Layer 4 (Transport/TCP) vs Layer 7 (Application/HTTP), encapsulation, and debugging network boundaries.

Key Glossary Concepts in this TopicAll Glossary Terms

OSI 7-Layer vs TCP/IP 4-Layer Mapping 📐

How protocols and load balancers map across network abstraction layers.

OSI 7-Layer vs TCP/IP 4-Layer Mapping 📐
100%
Rendering visual architecture flowchart...

01.1. Why Network Layering Matters in System Design

Network layering allows higher-level software to operate without caring about underlying hardware physics. An application sending a JSON string over HTTP/2 does not need to know whether the packet travels over fiber-optic undersea cables, satellite links, or 5G cell towers. This abstraction enables the innovation at each layer to progress independently.

In system design interviews, layer awareness is critical because the choice of which layer to operate at defines capabilities and performance:

  • Firewalls and DDoS protection typically operate at L3/L4 (inspecting IP and TCP headers)
  • Load balancers can operate at L4 (TCP ports) or L7 (HTTP URLs and headers)
  • CDNs operate at L7 to cache HTTP responses and inspect URL paths
  • Service meshes (Istio, Linkerd) inject L7 proxies (Envoy) as sidecar containers to intercept all pod-to-pod traffic

02.2. Layer 4 vs Layer 7 (The Most Important Distinction)

  • Layer 4 (Transport): Operates on raw TCP/UDP packets, source/destination IP, and port numbers. It cannot inspect HTTP headers, cookies, or JSON payloads. Extremely fast throughput (millions of packets/sec). Example: AWS NLB, HAProxy in mode tcp.
  • Layer 7 (Application): Operates on full HTTP/HTTPS/gRPC requests, headers, cookies, and URLs. It can perform intelligent routing (e.g., route /video to Media Service, inspect auth tokens). More CPU intensive. Example: AWS ALB, Nginx in mode http, Envoy Proxy.

Practical consequences:

  • SSL termination REQUIRES L7 — you cannot decrypt TLS without understanding the application protocol
  • Rate limiting per user (inspecting JWT) requires L7 — L4 only sees IP addresses
  • Path-based routing (microservice splitting) requires L7
  • DDoS mitigation at scale often uses L4 (AWS Shield) to avoid the CPU cost of L7 inspection on flood traffic

03.3. Packet Encapsulation & De-encapsulation

As data moves down the stack to be transmitted, each layer wraps the payload in its own header (and sometimes trailer):

[ Ethernet Frame [IP Packet [TCP Segment [TLS Record [HTTP Body: JSON]]]]] 

Overhead breakdown for a 1,000-byte HTTP/HTTPS payload:

  • Ethernet frame header: 14 bytes + 4 byte FCS
  • IPv4 header: 20 bytes minimum
  • TCP header: 20 bytes minimum
  • TLS record header: 5 bytes + MAC (16 bytes)
  • Total protocol overhead: ~79 bytes on top of payload (~7% overhead)

As data moves up the stack at the receiver, each layer strips its header and passes the payload upward — this is de-encapsulation.

04.4. TCP/IP 4-Layer Model (Practical Condensation)

The real-world TCP/IP stack collapses the OSI 7 layers into 4 practical layers:

  1. Network Access (L1+L2): Ethernet, WiFi, fiber — physical transmission and MAC-level delivery
  2. Internet (L3): IP addressing and routing — BGP, OSPF route traffic across the global internet
  3. Transport (L4): TCP (reliable stream) and UDP (datagram) — multiplexing between processes via ports
  4. Application (L5-L7): HTTP, DNS, TLS, WebSocket — the actual protocols your code uses

The TCP/IP model is what operating systems and network stacks actually implement. OSI is a conceptual framework used for teaching and troubleshooting — you'll often see teams refer to "Layer 7 routing" even though the practical stack is TCP/IP.

⚖️Architectural Trade-offs & Production Realities

Architectural Advantages

  • Strict decoupling of routing, transport, and application semantics
  • Enables independent innovation at each layer
  • Clear debugging boundaries (is this an L3 routing issue or an L7 application bug?)

Trade-offs & Constraints

  • Each layer adds header overhead and encapsulation processing time
  • Deep packet inspection across layers adds CPU cost
Production Implementation in Big Tech
HAProxy Technologies• L4 vs L7 Load Balancing Modes

HAProxy can be configured in `mode tcp` (L4 proxying raw byte streams without decoding HTTP) for ultra-low-latency database routing, or `mode http` (L7) for microservice path rewriting.

🎯 Staff+ Engineering Takeaways

  • L4 = Transport (TCP/UDP, Ports, raw throughput).
  • L7 = Application (HTTP, Headers, URLs, intelligent routing).
  • Higher layers offer richer inspection at the expense of higher CPU overhead.
  • Encapsulation adds ~79 bytes of protocol headers per HTTP packet.
  • Service meshes inject L7 proxies to enforce security and observability without application changes.

Topic Knowledge Assessment 🧠

Step through 1 scenario question to test your staff-level grasp.

Question 1 of 10 answered
#1

Can a Layer 4 Load Balancer route requests to different backend clusters based on the HTTP request URL path (e.g. /api/users vs /api/orders)?

Rate This Architecture Chapter4.9 / 5.0 (38 ratings)

How clear and staff-actionable was this system breakdown?