OSI vs TCP/IP Model Overview
Understand abstraction layers in distributed networking: Layer 4 (Transport/TCP) vs Layer 7 (Application/HTTP), encapsulation, and debugging network boundaries.
OSI 7-Layer vs TCP/IP 4-Layer Mapping 📐
How protocols and load balancers map across network abstraction layers.
01.1. Why Network Layering Matters in System Design
Network layering allows higher-level software to operate without caring about underlying hardware physics. An application sending a JSON string over HTTP/2 does not need to know whether the packet travels over fiber-optic undersea cables, satellite links, or 5G cell towers. This abstraction enables the innovation at each layer to progress independently.
In system design interviews, layer awareness is critical because the choice of which layer to operate at defines capabilities and performance:
- Firewalls and DDoS protection typically operate at L3/L4 (inspecting IP and TCP headers)
- Load balancers can operate at L4 (TCP ports) or L7 (HTTP URLs and headers)
- CDNs operate at L7 to cache HTTP responses and inspect URL paths
- Service meshes (Istio, Linkerd) inject L7 proxies (Envoy) as sidecar containers to intercept all pod-to-pod traffic
02.2. Layer 4 vs Layer 7 (The Most Important Distinction)
- Layer 4 (Transport): Operates on raw TCP/UDP packets, source/destination IP, and port numbers. It cannot inspect HTTP headers, cookies, or JSON payloads. Extremely fast throughput (millions of packets/sec). Example: AWS NLB, HAProxy in
mode tcp. - Layer 7 (Application): Operates on full HTTP/HTTPS/gRPC requests, headers, cookies, and URLs. It can perform intelligent routing (e.g., route
/videoto Media Service, inspect auth tokens). More CPU intensive. Example: AWS ALB, Nginx inmode http, Envoy Proxy.
Practical consequences:
- SSL termination REQUIRES L7 — you cannot decrypt TLS without understanding the application protocol
- Rate limiting per user (inspecting JWT) requires L7 — L4 only sees IP addresses
- Path-based routing (microservice splitting) requires L7
- DDoS mitigation at scale often uses L4 (AWS Shield) to avoid the CPU cost of L7 inspection on flood traffic
03.3. Packet Encapsulation & De-encapsulation
As data moves down the stack to be transmitted, each layer wraps the payload in its own header (and sometimes trailer):
[ Ethernet Frame [IP Packet [TCP Segment [TLS Record [HTTP Body: JSON]]]]]
Overhead breakdown for a 1,000-byte HTTP/HTTPS payload:
- Ethernet frame header: 14 bytes + 4 byte FCS
- IPv4 header: 20 bytes minimum
- TCP header: 20 bytes minimum
- TLS record header: 5 bytes + MAC (16 bytes)
- Total protocol overhead: ~79 bytes on top of payload (~7% overhead)
As data moves up the stack at the receiver, each layer strips its header and passes the payload upward — this is de-encapsulation.
04.4. TCP/IP 4-Layer Model (Practical Condensation)
The real-world TCP/IP stack collapses the OSI 7 layers into 4 practical layers:
- Network Access (L1+L2): Ethernet, WiFi, fiber — physical transmission and MAC-level delivery
- Internet (L3): IP addressing and routing — BGP, OSPF route traffic across the global internet
- Transport (L4): TCP (reliable stream) and UDP (datagram) — multiplexing between processes via ports
- Application (L5-L7): HTTP, DNS, TLS, WebSocket — the actual protocols your code uses
The TCP/IP model is what operating systems and network stacks actually implement. OSI is a conceptual framework used for teaching and troubleshooting — you'll often see teams refer to "Layer 7 routing" even though the practical stack is TCP/IP.
⚖️Architectural Trade-offs & Production Realities
Architectural Advantages
- Strict decoupling of routing, transport, and application semantics
- Enables independent innovation at each layer
- Clear debugging boundaries (is this an L3 routing issue or an L7 application bug?)
Trade-offs & Constraints
- Each layer adds header overhead and encapsulation processing time
- Deep packet inspection across layers adds CPU cost
HAProxy can be configured in `mode tcp` (L4 proxying raw byte streams without decoding HTTP) for ultra-low-latency database routing, or `mode http` (L7) for microservice path rewriting.
🎯 Staff+ Engineering Takeaways
- L4 = Transport (TCP/UDP, Ports, raw throughput).
- L7 = Application (HTTP, Headers, URLs, intelligent routing).
- Higher layers offer richer inspection at the expense of higher CPU overhead.
- Encapsulation adds ~79 bytes of protocol headers per HTTP packet.
- Service meshes inject L7 proxies to enforce security and observability without application changes.
Topic Knowledge Assessment 🧠
Step through 1 scenario question to test your staff-level grasp.
Can a Layer 4 Load Balancer route requests to different backend clusters based on the HTTP request URL path (e.g. /api/users vs /api/orders)?
How clear and staff-actionable was this system breakdown?