Hermetic Networks Hermetic Networks

CompTIA Network+ (N10-009) - Session 01 - Learner Guide

OSI and TCP/IP Models

The two layer models, the two addresses every device carries, and how to drive any network fault down to the one layer it lives at.

1Why layers matter

This is your copy to keep. It assumes no networking background and starts at what a network address is. The gold Going deeper boxes go past what the session covers, for anyone sitting the CompTIA Network+ exam or who wants the fuller picture.

A network moves data from one machine to another in stages, and each stage has one job. The cable carries electrical or light signals. The switch gets a message to the right machine in the same office. The router gets it to a machine in a different building. The application at the far end does something with it. Those stages are called layers.

Almost every fault you will work happens at exactly one of those layers, and the layers sit in a fixed order. That gives you a test order instead of a guessing order. Check the cable, then the switch, then the address, then the port, then the application, and stop at the first check that fails. The layer that fails tells you which tool to pick up next.

There are two models in common use. The OSI model (Open Systems Interconnection) has seven layers and is the vocabulary people use to describe and troubleshoot networks. The TCP/IP model (Transmission Control Protocol / Internet Protocol) has four layers and is what operating systems and network gear are actually built on. You need both, because a colleague will say "that is a layer 2 problem" in OSI terms while Wireshark and ipconfig report in TCP/IP terms.

The example network

The addresses used throughout this page, 192.168.10.x and the name intranet.hermetic.local, come from the sample packet capture used in the session. They are an example network written for training, not a client's addressing.

2The devices on a network

Before the layers, the hardware. Each of these does its job at a particular layer, and the layer is the reason each one exists.

Common network devices and where they work
DeviceWhat it doesWorks at
Cable, patch panel, PoECarries the signal itself, over copper or fiber. Power over Ethernet (PoE) sends electrical power down the same cable so a phone or access point needs no separate power supply.L1
SwitchConnects the devices inside one office or one floor and forwards traffic between them by hardware address.L2
Access point (AP)A switch port delivered over radio. It puts wireless clients onto the same wired network the switch serves.L1 to L2
RouterConnects one network to another and forwards traffic between them by network address. The office router is how anything in the office reaches anything outside it.L3
FirewallPermits or blocks traffic against a rule list. Rules can match on addresses and port numbers, and on many firewalls on the application itself.L3 to L7

A single box in a small office often does several of these jobs at once. The firewall on the wall of most of our client sites is also the router, and often the wireless controller. It still does each job at its own layer, which is why a fault in one of those jobs does not take the others with it.

3Two addresses for every device

Every device on a network carries two addresses at the same time, and confusing them is the single most common reason a technician tests the wrong thing. They exist for different jobs.

The MAC address

A MAC address (media access control address) is a 48-bit number set in the network interface when it is manufactured, written as six pairs of hexadecimal digits, for example 00:1A:2B:3C:4D:5E. Hexadecimal is base 16, so each pair runs from 00 to FF and stands for one byte.

It identifies one network interface and nothing else. Move a laptop from Richmond to Charlottesville and its MAC address is the same MAC address. It is used only to deliver a message between two devices on the same local network.

The IP address

An IP address (internet protocol address) is a number the network hands the device, written as four numbers from 0 to 255 separated by dots, for example 192.168.10.20. That format is 32 bits in total and is called IPv4.

It says where the device currently sits. Move that same laptop to a different office and it gets a different IP address, because it is now in a different place. It is used to deliver a message across any number of networks, end to end.

Why both exist

Follow one message. A workstation at 192.168.10.15 in the office loads a website at 203.0.113.9 somewhere on the internet.

  1. The workstation compares the destination address 203.0.113.9 to its own network. It is not local, so the workstation cannot deliver it directly.
  2. The workstation builds the message with destination IP 203.0.113.9, the final destination, and destination MAC address of the office router, the only device locally that knows how to get any further.
  3. The router receives it, discards the local addressing, writes new local addressing for the next device on the path, and sends the same message on.
  4. Every device along the path does the same thing, perhaps fifteen times, until the message arrives.

Through all of it, the destination IP address 203.0.113.9 never changes, because the final destination never changed. The MAC addresses are rewritten at every single hop, because "who hands it to whom next" changes at every hop. IP is the address on the envelope. MAC is which pair of hands the envelope is in right now.

Two addressing systems means something has to join them. When a device knows an IP address on its own network but not the matching MAC address, it uses ARP (Address Resolution Protocol): it broadcasts "who has 192.168.10.10" to everything on the local network, and the device that owns that IP answers with its MAC address. Nothing else can happen until that answer comes back, which is why ARP is usually the first thing in any packet capture.

Going deeper

The source IP address does get rewritten once, at the office firewall, on the way out to the internet. The firewall replaces the private source address 192.168.10.15 with its own public address and remembers the swap so the reply comes back to the right workstation. That is network address translation (NAT), and it is the reason a whole office of machines can share one public address. Inside the office, and for the destination address, the statement above holds: the IP address identifies the endpoint and the MAC address identifies the hop.

4The OSI model

Seven layers. The bottom is closest to the wire, the top is closest to the person. Read it from the bottom, because bottom to top is the order you troubleshoot in.

The seven OSI layers
#LayerIts one jobUnitWhat that is in our stackWhat a break looks like
7ApplicationThe service the person is actually usingDataDNS, web, remote desktop, file shares, mailThe site or app fails while the connection to the machine is fine
6PresentationPuts data in an agreed format and encrypts itDataThe encryption behind HTTPS, file formatsCertificate warnings, garbled or unreadable content
5SessionOpens a conversation, keeps it, closes itDataA signed-in session, a remote desktop sessionRepeated drops and reconnects
4TransportDelivers to the right program on the machine, using port numbersSegmentTCP and UDP, port 443, port 53Right machine, wrong or blocked port
3NetworkAddresses and routes between networksPacketIP addresses, the router, the default gatewayNo route off the local network, wrong address
2Data LinkMoves data between devices on the same local network, by MAC addressFrameSwitch, MAC addresses, ARP, VLANsWrong VLAN, switch port problem, ARP problem
1PhysicalThe actual signal on copper, fiber or radioBitsCable, port, PoE, Wi-Fi signal strengthNothing works at all, no link light

A VLAN (virtual local area network) named at layer 2 above is one physical switch divided into separate networks by configuration. Ports 1 to 12 can be the staff network and ports 13 to 24 the guest network, on the same switch, with no traffic crossing between them. Nothing physical marks the difference, which is why a VLAN fault looks like a cabling fault and is not one.

A memory hook for the seven, bottom to top: Please Do Not Throw Sausage Pizza Away. Top to bottom: All People Seem To Need Data Processing.

Layers 5 to 7 on the job

In practice nobody separates Session, Presentation and Application while working a ticket. All three get called "the application layer" or "layer 7". When somebody says a fault is at layer 7 they mean the application or service itself rather than the network path underneath it. The seven layers matter as written on the exam, and as five layers on an actual ticket.

5The TCP/IP model

The TCP/IP model describes the same journey in four layers instead of seven. It groups the top three OSI layers into one and the bottom two into one. This is the model your operating system and your tools are built on, so it is the one whose names appear in output you read.

OSI, seven layers TCP/IP, four layers 7 Application 6 Presentation 5 Session 4 Transport 3 Network 2 Data Link 1 Physical ApplicationDNS, DHCP, HTTP and HTTPS,remote desktop, file sharing, mailCovers OSI layers 5, 6 and 7 TransportTCP, UDP, port numbers InternetIP addresses, routing, the gateway LinkSwitch, MAC, ARP, VLAN,cable, PoE, Wi-Fi
The two layers in the middle line up one to one, which is why Transport and Network keep their names in both models. The grouping at the top and bottom is the only real difference between them.
Going deeper

Why two models at all. OSI was published first as a vendor-neutral teaching and design standard, ISO/IEC 7498-1. TCP/IP is the model the internet was actually built on, defined for hosts in RFC 1122, so it is what your operating system implements. The Network+ exam asks in OSI terms while Wireshark and ipconfig report in TCP/IP terms. After a few weeks of saying both out loud, the translation stops costing you anything.

6Encapsulation

Data does not cross a network on its own. On the way down the stack, each layer puts what it received inside its own wrapper by adding a header, a short block of fields at the front holding that layer's addressing. Layer 2 also adds a trailer at the back, carrying a checksum the receiving device uses to detect a frame damaged in transit. The receiving device removes each wrapper on the way back up, in reverse order. Wrapping on the way down and unwrapping on the way up is called encapsulation.

The wrapped unit gets a different name at each layer. The general term for any of them is a PDU (protocol data unit), and the specific names are the ones you use out loud.

your data Layer 7, the web request itself TCP your data Layer 4, now a segment IP TCP your data Layer 3, now a packet MAC IP TCP your data check Layer 2, now a frame the whole frame, sent as ones and zeros Layer 1, now bits
Each layer adds its own addressing in front of everything it was handed. Nothing inside is altered, which is why a single captured frame contains every layer at once, in order.

That is why the unit name changes as you go down: data, segment, packet, frame, bits. When you open one frame in Wireshark and read it top to bottom on screen, you are reading the layers bottom to top: the frame and its MAC addresses first, then the IP header, then the TCP header, then the request itself.

7Protocols and ports

Layer 3 gets traffic to the right machine. Layer 4 gets it to the right program on that machine, using a port: a number from 0 to 65535 carried in the TCP or UDP header. One server at one IP address can run a web service and a remote desktop service at once, and the port number is the only thing keeping the two conversations apart.

A protocol is the agreed language two programs speak. A port is the numbered door that language is spoken through. The numbers below are assigned centrally, by IANA, so they mean the same thing on every network you will ever touch. Learn these six.

The ports to know from this session
ServicePortTCP or UDPWhat it doesLayer
DNS, domain name system53UDP mostly, TCP for large answersTurns a name like intranet.hermetic.local into an IP addressL7
DHCP, dynamic host configuration protocol67 and 68UDPHands a device its IP address, subnet mask, gateway and DNS servers when it joins a networkL7
HTTP, hypertext transfer protocol80TCPWeb traffic, not encryptedL7
HTTPS, HTTP over TLS443TCPWeb traffic, encrypted by TLS (transport layer security)L7
RDP, remote desktop protocol3389TCPRemote control of a Windows desktop or serverL7
SMB, server message block445TCPWindows file and printer sharing, so every mapped driveL7

DHCP uses two ports because the two ends are not symmetrical: the client sends from port 68 to the server on port 67, and the server answers back to port 68. A device asking for an address does not have one yet, so the request goes out to the whole local network and the server answers the MAC address that asked.

Going deeper

TCP against UDP. TCP opens a connection first, numbers everything it sends, and confirms each piece arrived, resending anything that did not. That costs time and is worth it where completeness matters: web pages, files, remote desktop. UDP sends without setting anything up and without confirming, which is faster and fine where a lost piece does not matter or there is no time to resend: name lookups, voice, video.

You can see the difference in any capture. A TCP conversation opens with three packets, called the three-way handshake: SYN from the client, SYN-ACK from the server, ACK from the client, and only then does the request itself go. A DNS lookup over UDP has no handshake at all. One question, one answer, two packets.

8Worked example: one web request, layer by layer

One everyday action, a workstation opening the intranet site, broken into the twelve packets it actually takes. This is the sample capture opened in the session. Work down it and watch each layer do its job in order.

01-sample-capture.pcap, in order
PacketsWhat happensLayer
1 to 2The workstation needs the DNS server's MAC address before it can send it anything. It broadcasts "who has 192.168.10.10" and gets the reply. That is ARP.L2
3 to 4The workstation asks the DNS server "what is the IP address for intranet.hermetic.local" and gets 192.168.10.20 back. Two packets, no handshake, because this is UDP.L7 over L4 over L3
5 to 6New destination, so a new MAC address is needed. The workstation ARPs for the web server this time.L2
7 to 9The TCP three-way handshake to port 80: SYN, SYN-ACK, ACK. The connection is now open and nothing has been requested yet.L4
10The request itself: GET / HTTP/1.1. This one packet carries the MAC addresses, the IP addresses, the port numbers and the request, stacked in that order.L7
11 to 12The server acknowledges and sends back 200 OK. The page loads.L7

Two things are worth taking from that sequence. The name lookup happened before any connection to the web server existed, which is why a broken DNS server makes every site fail while the network underneath is perfectly healthy. And four of the twelve packets were ARP, doing nothing but pairing an IP address with a MAC address, which is how much work the two addressing systems cost on every conversation.

9Troubleshooting by layer

This is what the model is for. Start at the bottom and work up, and stop at the first check that fails. Everything above a broken layer will also look broken, so testing downward from the top tells you nothing.

The bottom-up check
CheckLayerTool
Is it plugged in, and is there a link light at both ends?L1Eyes, cable tester
Is the switch port up, and is it on the right VLAN?L2Switch configuration, arp -a
Does it have an IP address, and can it reach its gateway?L3ipconfig /all, ping
Is the port open on the far machine?L4Test-NetConnection
Does the name resolve, and does the application answer?L7nslookup, a browser, the application itself

The same sequence, run once end to end

A user reports that the shared drive will not open. Here is the whole ladder, with the command at each rung and what its output settles.

  1. L1. Link light on at the workstation and at the switch port. It is on, so the physical path exists. Move up.
  2. L2. The workstation appears in the switch's address table on the port it is plugged into, on the staff VLAN. So the local network accepts it. Move up.
  3. L3. ipconfig /all returns IPv4 address 192.168.10.15, subnet mask 255.255.255.0, default gateway 192.168.10.1. ping 192.168.10.1 replies, and ping 192.168.10.30, the file server, replies too. So addressing works and the two machines can reach each other. Move up.
  4. L4. Test-NetConnection 192.168.10.30 -Port 445 returns TcpTestSucceeded : False. This is the first failing check, so stop here.

Read what that combination actually proves. The file server answers a ping, so the machine is powered, on the network and reachable, and layers 1 through 3 are healthy end to end. Port 445 does not answer, so the file sharing service on that server is stopped, or something between the two machines is blocking port 445. Nothing above layer 4 has been tested and nothing above layer 4 needs to be: the problem is found. Two commands separated the "the server is down" answer from the "one service on the server is down" answer, and they are different tickets with different fixes.

Three patterns to recognize

An address starting 169.254

A laptop shows an IP address of 169.254.14.9 and reaches nothing, while everyone else is fine. That range is APIPA (automatic private IP addressing), the address a Windows machine gives itself when it asked for a DHCP address and nothing answered.

The symptom is at layer 3. The cause is DHCP, at layer 7. Start with ipconfig /all on the machine, then the DHCP scope on the server.

A whole VLAN drops at once

Every phone loses service at the same moment. The switch is up, other VLANs on the same switch are fine, and nothing physical changed.

One VLAN failing while its neighbors on the same hardware keep working rules out the cable and the switch itself. That is layer 2, a VLAN or trunk configuration problem.

The name fails, the address works

One user cannot reach the intranet site by name, but ping 192.168.10.20 works, and other users load the site normally.

Reaching it by address proves layers 1 through 3 are healthy for that machine, and other users loading the site proves the service is up. The break is name resolution, DNS at layer 7, for that one client. Check its configured DNS servers with ipconfig /all, then nslookup.

Going deeper

The first and third patterns are the same trap from opposite directions. A symptom at one layer can be caused at another: no IP address looks like layer 3 and is caused by DHCP at layer 7, and a site that will not load looks like the application at layer 7 and is caused by name resolution for that one machine. The ladder protects you from both, because it makes you prove each layer rather than accept the layer the symptom sounds like.

One caution about what a successful ping actually proves. Ping uses ICMP (internet control message protocol), which lives at layer 3 and carries no port number at all. A reply therefore proves layers 1 through 3 and says nothing about layer 4. To test layer 4 you have to name a port: Test-NetConnection 192.168.10.30 -Port 445. "It pings, so the network is fine" is the most common wrong conclusion in the queue.

10Practice on your own machine

  1. Run ipconfig /all on Windows, or ip addr and ip route on Mac or Linux. Write down your IP address, your MAC address, your default gateway and your DNS server, and put the OSI layer number next to each one.
  2. Run arp -a. Every line pairs an IP address with a MAC address. Find your gateway's IP address in that list and note the MAC address sitting next to it.
  3. Run ping against your gateway, then nslookup against a name you use every day. The first tests layer 3, the second tests layer 7.
  4. Open 01-sample-capture.pcap in Wireshark, or capture ten seconds of your own traffic. Find one DNS query and one TCP handshake, and say which layer each lives at.
  5. Expand one packet fully. Point at the MAC address, then the IP address, then the port, then the data, and name the layer at each step.

11Check for understanding

  1. Put each of these at its layer: ARP, HTTPS, an IP address, a switch, a MAC address.

  2. Which layer does the default gateway belong to, and what does it do?

  3. Name one thing that uses TCP and one that uses UDP, and say why each one fits its job.

  4. A user cannot open a website by name, but pinging the web server's IP address works. Which layer is the fault at, and what proves the layers below it are healthy?

  5. Name the port for HTTPS, RDP and DNS.

  6. A laptop has an IP address of 169.254.14.9 and reaches nothing. Name the layer the symptom appears at, the layer the cause lives at, and the first command you run.

  7. A packet leaves a workstation in the office for a web server on the internet, fifteen hops away. How many times does its destination IP address change on the way, and how many times does its destination MAC address change?

12Before the next session

  • Memorize the six ports. 53, 67 and 68, 80, 443, 3389, 445. The next session opens by running through them.
  • Do the practice steps in section 10 on your own machine, and bring the four values you wrote down with their layer numbers.
  • Read the Network+ companion, chapter 2, the OSI and TCP/IP sections and "Common Protocols and Ports". About twenty minutes.
  • Sitting the exam: also work the chapter 2 review questions and Exam Tips 4, 5 and 6.

Next session. 02 - IP Addressing and Subnetting. Bring a laptop, it is worked on paper and on screen.

13Glossary

Layer
One stage of the journey data takes across a network, with one job and a fixed position relative to the others.
OSI model
Open Systems Interconnection. The seven-layer description of a network, used as the common vocabulary for describing faults.
TCP/IP model
The four-layer description the internet and your operating system are actually built on: Link, Internet, Transport, Application.
MAC address
A 48-bit hardware address set in a network interface at manufacture, written as six pairs of hexadecimal digits. Used to deliver between two devices on the same local network.
IP address
An address assigned by the network describing where a device sits, written in IPv4 as four numbers from 0 to 255. Used to deliver end to end across any number of networks.
Subnet mask
The value that tells a device which part of an IP address identifies the local network, and therefore which addresses it can reach directly.
Default gateway
The address of the router a device sends traffic to when the destination is not on its own network.
ARP
Address Resolution Protocol. Finds the MAC address that matches a known IP address on the local network.
VLAN
Virtual local area network. One physical switch divided into separate networks by configuration.
Port
A number from 0 to 65535 in the TCP or UDP header identifying which program on the machine the data is for.
Protocol
The agreed language two programs use to talk to each other.
TCP
Transmission Control Protocol. Sets up a connection, confirms delivery and resends what is lost.
UDP
User Datagram Protocol. Sends without setting up a connection and without confirming delivery.
Three-way handshake
The three packets, SYN, SYN-ACK and ACK, that open every TCP connection.
Header
The block of fields one layer adds in front of the data it was handed, holding that layer's addressing.
Trailer
The block layer 2 adds at the end of a frame, holding a checksum used to detect damage in transit.
Encapsulation
Wrapping data in a header at each layer on the way down, and removing them in reverse on the way up.
PDU
Protocol data unit. The general name for the wrapped unit at any layer. The specific names are data, segment, packet, frame and bits.
ICMP
Internet Control Message Protocol. The layer 3 protocol ping uses. It carries no port number, so a successful ping says nothing about layer 4.
DNS
Domain Name System. Turns a name into an IP address. Port 53.
DHCP
Dynamic Host Configuration Protocol. Hands a device its address, mask, gateway and DNS servers. Ports 67 and 68.
APIPA
Automatic Private IP Addressing. The 169.254 address a Windows machine gives itself when no DHCP server answers.
SMB
Server Message Block. Windows file and printer sharing. Port 445.
RDP
Remote Desktop Protocol. Remote control of a Windows desktop or server. Port 3389.
TLS
Transport Layer Security. The encryption that turns HTTP into HTTPS.
NAT
Network Address Translation. Rewriting a private source address to a public one at the network edge so a whole office can share one public address.
PoE
Power over Ethernet. Electrical power carried on the same cable as the data.

14Sources