The OSI Model & Encapsulation
September 21, 2026 • 8 min read

Table of contents
Part of the series:Networks Explained
The networks overview ended with a stack of layers and a promise: each layer adds one guarantee, from volts to web pages. But that drawing was a sketch. Somebody chose those layers, counted them, named them, and wrote them down. This post opens that document. The seven-layer model everyone half-remembers from school, what each floor is actually responsible for, and the single mechanism that makes layering work: wrapping data in headers on the way down and unwrapping it on the way up.
The model came before the network
In 1979, before the internet existed as a public network, the International Organization for Standardization published a reference model for how a network should be divided into layers: the OSI model1. Its authors were not describing the existing world. They were arguing about how it ought to be built, and they argued about it for years, mostly about how many floors a building should have.
OSI was a design document, not a description. The interesting part is not that it failed. It is that the diagram outlived every attempt to build it exactly.
The model’s purpose was to let two teams write different layers independently and still fit together, the same way a CPU ISA lets hardware teams and software teams work apart. It is a logical model: an agreed way to name responsibilities, not a list of products.
What a layer is
A layer is one job, with three obligations:
- Service. It offers a capability to the layer above. “I will deliver these bytes to a machine on my local network.”
- Interface. It tells the layer above how to request that service. Not “what I do inside”, just “how to ask”.
- Layer below. It gets its work done using the layer below, and stays ignorant of how.
The rule that makes this cheap: a layer never needs to know how the layer below works, and never needs to know why the layer above called it.
Think of an envelope inside an envelope inside an envelope. You write a letter, put it in an envelope addressed to a building, put that in a bag addressed to a city, and hand it to the postal service. Nobody in the chain needs to read the letter to move it one step.
The seven layers
7 Application what the program wants HTTP, DNS, SMTP
6 Presentation format, encrypt, compress TLS, JPEG, encoding
5 Session start, keep, end conversations sessions, RPC
4 Transport deliver to the right program TCP, UDP, ports
3 Network find a path across networks IP, ICMP, routers
2 Data link deliver to the neighbor Ethernet, MAC, switches
1 Physical move bits as signals cables, radio, fiber
The numbering counts from the bottom because layer 1 is closest to the wire. Here is each floor in one honest sentence, before this series opens them one by one.
7 Application. The layer your program actually talks to. You call a function like “send this HTTP request” and the network world takes it from there. No other layer is ever visible to your code.
6 Presentation. Translation between what the program means and what the wire can carry: character encodings, compression, and encryption. TLS usually lives here in textbooks, which is why TLS placement causes arguments. In practice encryption can sit in several places, and HTTP/3 puts it below the application inside QUIC.
5 Session. Opening, maintaining, and closing a conversation between two programs, plus the dialog rules that keep it orderly. Half of this layer was quietly absorbed into the transport layer, and authentication services moved here.
4 Transport. End-to-end delivery between two programs, identified by port numbers. This is where reliability, ordering, and flow control live, and where TCP and UDP sit.
3 Network. Addressing across the whole world and choosing a route, hop by hop, through machines you do not control. This is where IP and routers live.
2 Data link. Reliable delivery across a single hop, to the machine on the other end of this cable, using hardware addresses. This is where Ethernet frames and switches live.
1 Physical. Bits as electricity, light, or radio waves, plus the media that carry them and the noise they fight.
Real example: when your code calls an HTTP library, layers 7 down to 1 become one continuous pipeline. You never see them, but every byte you send passed through all seven, and every byte you receive passed back up through all seven.
Encapsulation: the wrapping
Here is the mechanism the whole model rests on. As data moves down the stack on the sending side, each layer adds its own small header, called a header2, and passes the result to the layer below. The payload of the layer above becomes the data of the layer below.
sending side, going down:
[ HTTP GET /index.html ] layer 7: data
[ TCP | port 443, seq 1 | HTTP GET ... ] layer 4: segment
[ IP | to 93.184.216.34 | TCP | ... ] layer 3: packet
[ Ethernet | to aa:bb:cc... | IP | ... ] layer 2: frame
1 0 1 1 0 0 1 0 0 1 1 0 0 0 0 0 0 layer 1: bits
Each header answers a question the layer below cannot ask the sender. The IP header says where the packet is going. The Ethernet header says which machine on this cable should take it. The TCP header says which program on that machine should get the bytes, and whether they arrived. That is encapsulation3.
On the receiving side the process runs in reverse. Each layer reads its own header, uses it, and strips it before handing the rest up, which is decapsulation. The application at the top never learns that a frame ever existed.
receiving side, going up:
1 0 1 1 0 ... layer 1: bits
[ Ethernet | IP | TCP | HTTP ] layer 2: read MAC, drop header
[ IP | TCP | HTTP ] layer 3: right host? drop header
[ TCP | HTTP ] layer 4: right port? reassemble, drop header
[ HTTP GET /index.html ] layer 7: the request, reassembled
Encapsulation is why you can swap Wi-Fi for a fiber link without changing a single line of your program: the layers above never looked inside.
PDUs: what each layer’s data is called
The data at each level has its own name, called a protocol data unit4 (PDU). The names are not important to memorize, but the pattern is: the more a layer knows about the journey, the more meaningful its unit becomes.
| Layer | PDU name | Carries |
|---|---|---|
| 7-6 | Data / message | what the program means |
| 5 | Data | an open conversation |
| 4 | Segment (TCP) | bytes for one program |
| 4 | Datagram (UDP) | one independent message |
| 3 | Packet | bytes for one host, across hops |
| 2 | Frame | bytes for one neighbor |
| 1 | Bits | 1s and 0s |
Why the model won even though the plan lost
No product ever implemented all seven layers as separate pieces of hardware and software. TCP/IP, which the next post opens, does the same job in four floors, folds session and presentation into the application layer, and never heard of the OSI model except to argue with it.
Yet nobody deletes the diagram. Three reasons:
- It names responsibilities. When something breaks, “is this a link problem or a transport problem?” is a real, useful question, and the model supplies the vocabulary to ask it.
- It keeps layers honest. Every layer must add something, or it should not exist. Applying that test is how you find designs that pretend to be layered.
- It travels. The model outlived every piece of 1980s networking hardware and is still the fastest shared vocabulary in the industry.
The layers in this series follow the real four-floor stack, because that is what your bytes actually travel through. Where OSI is useful, this series names it, and it does not spend a post on floors that turned out to be empty.
The big picture
A layer is one job with a service, an interface, and no curiosity about its neighbors. OSI proposed seven such layers, from moving bits to speaking a program’s language. Encapsulation is what holds them together: going down, each layer wraps the data above in a header answering one more question; coming up, each layer reads and removes its own header. Each layer’s output is the next layer’s input, which is why the layers can be built by different teams, replaced one at a time, and still fit.
program's data
↓ wrap ┌─ transport: for which program?
↓ wrap ┌─ network: for which host, across the world?
↓ wrap ┌─ link: for which machine on this cable?
↓ wrap └─ physical: as signals
bits → signals → frame → packet → segment → data
The model is a map. The next post opens the machine that actually runs the journey: the four layers of TCP/IP, the standard that won, and the philosophy that let a network of networks exist at all.
Footnotes
/sponsor
Enjoyed this post? You can sponsor me and this site.