How the internet works · Lesson 1 · 25 min

Packets & layers

Sending a web page across the internet is a big job, so it's split into layers. Each layer does one thing and trusts the layer below for the rest, like a letter going into an envelope, the envelope into a mailbag, the mailbag into a truck. This lesson is the map for the whole path: once you know the layers, you know where to look when something breaks.

You will learn

  • The layers (OSI and TCP/IP), and which tool looks at which
  • Encapsulation: how a request gets wrapped on the way out
  • MAC addresses, ARP, and switches vs routers
  • What the MTU is, and the symptom when it's wrong

The layers

There are two famous versions. The OSI model has 7 layers and is what people say ("that's a layer 7 problem"). The TCP/IP model has 4 and is what the internet actually runs. They line up like this:

OSI layerTCP/IPDoesExampleLook with
7 Application
6 Presentation
5 Session
ApplicationWhat the program meansHTTP, DNS, SSH, TLScurl -v, dig
4 TransportTransportWhich program, reliably or notTCP, UDP, portsss, nc
3 NetworkInternetWhich machine, across networksIP addresses, routingip addr, ip route, ping, tracepath
2 Data linkLinkWhich device on this cable or Wi-FiEthernet, MAC addresses, ARPip link, ip neigh
1 PhysicalSignals on a wire or radioCables, link lights, speedethtool

The rest of this path goes up the stack: lesson 2 and lesson 3 are layer 3, lesson 5 is layer 4, and DNS, HTTP and TLS live at the top.

Encapsulation

On the way out, each layer wraps what it gets from the layer above in its own header:

Ethernet headerMAC → MAClayer 2 IP headerIP → IPlayer 3 TCP headerport → portlayer 4 GET / HTTP/1.1the actual messagelayer 7

Read from the right: the HTTP request is wrapped in TCP, then IP, then Ethernet. The receiver unwraps it in the opposite order.

Each router on the way takes off the Ethernet header, reads the IP header to decide where next, and wraps it in a new Ethernet header for the next hop. The IP addresses stay the same from end to end (NAT aside); the MAC addresses change at every hop. tcpdump -e shows you the outside of the envelope too.

MAC addresses, ARP, switches and routers

Reading the neighbour table

REACHABLE/STALE with a MAC: it's there. FAILED or INCOMPLETE: nobody answered the ARP request, so nothing at that address is on your network (wrong address, or the device is off). That's what "Destination Host Unreachable" means for a local address.

MTU: how big a packet can be

Every link has a maximum transmission unit, normally 1500 bytes on Ethernet. Bigger packets have to be split (fragmented) or are refused. Tunnels and VPNs add their own headers, which makes the space left smaller. The classic symptom of an MTU problem is strange: small things work (ping, SSH login, small pages), but big transfers or some HTTPS sites hang. Test it with "don't fragment" pings:

ping -c 1 -M do -s 1472 192.168.1.1   # 1472 + 8 (ICMP) + 20 (IP) = 1500: fits
ping -c 1 -M do -s 1473 192.168.1.1   # 1501: too big

These layer tools work the same on both families. What's different is where you'd change the MTU permanently:

TaskRocky / RHELUbuntu / Debian
See itip link show enp0s3 same on both
Change it until rebootsudo ip link set enp0s3 mtu 1400 same on both
Change it for goodsudo nmcli con mod enp0s3 802-3-ethernet.mtu 1400mtu: 1400 under the interface in netplan
Install tcpdumpsudo dnf install tcpdumppreinstalled

Try it: from the cable up 🧱

Start at the bottom of the club server's network stack and work your way up, one layer at a time.

Quick check

1. A packet travels from your server, through three routers, to a website. What changes at every hop?

2. ping 192.168.1.99 says "Destination Host Unreachable", and ip neigh shows 192.168.1.99 … FAILED. What does that mean?

3. Through a new VPN, SSH logins work but copying big files hangs. A good first suspect?

Finished the missions and the quiz? Mark it done to track your progress.