Packets & layers
Sending a web page across the internet is a big job, so it's split into layers. Each layer does one thing and trusts the layer below for the rest, like a letter going into an envelope, the envelope into a mailbag, the mailbag into a truck. This lesson is the map for the whole path: once you know the layers, you know where to look when something breaks.
You will learn
- The layers (OSI and TCP/IP), and which tool looks at which
- Encapsulation: how a request gets wrapped on the way out
- MAC addresses, ARP, and switches vs routers
- What the MTU is, and the symptom when it's wrong
The layers
There are two famous versions. The OSI model has 7 layers and is what people say ("that's a layer 7 problem"). The TCP/IP model has 4 and is what the internet actually runs. They line up like this:
| OSI layer | TCP/IP | Does | Example | Look with |
|---|---|---|---|---|
| 7 Application 6 Presentation 5 Session | Application | What the program means | HTTP, DNS, SSH, TLS | curl -v, dig |
| 4 Transport | Transport | Which program, reliably or not | TCP, UDP, ports | ss, nc |
| 3 Network | Internet | Which machine, across networks | IP addresses, routing | ip addr, ip route, ping, tracepath |
| 2 Data link | Link | Which device on this cable or Wi-Fi | Ethernet, MAC addresses, ARP | ip link, ip neigh |
| 1 Physical | Signals on a wire or radio | Cables, link lights, speed | ethtool |
The rest of this path goes up the stack: lesson 2 and lesson 3 are layer 3, lesson 5 is layer 4, and DNS, HTTP and TLS live at the top.
Encapsulation
On the way out, each layer wraps what it gets from the layer above in its own header:
Read from the right: the HTTP request is wrapped in TCP, then IP, then Ethernet. The receiver unwraps it in the opposite order.
Each router on the way takes off the Ethernet header, reads the IP header to decide where next, and wraps it in a new Ethernet header for the next hop. The IP addresses stay the same from end to end (NAT aside); the MAC addresses change at every hop. tcpdump -e shows you the outside of the envelope too.
MAC addresses, ARP, switches and routers
- A MAC address (like
08:00:27:4c:1a:7e) is burned into each network card. It only matters on the local network. - To send to
192.168.1.80on the same network, your machine needs its MAC. It shouts "who has 192.168.1.80?" to everyone (an ARP request) and the printer answers. The answers are kept in the neighbour table:ip neigh. (IPv6 does the same with "neighbour discovery".) - For an address on another network, your machine only needs the router's MAC. The router handles the rest.
- A switch works at layer 2: it forwards frames by MAC address inside one network. A router works at layer 3: it moves packets between networks by IP address. Your home "router" is both, plus Wi-Fi, plus NAT.
REACHABLE/STALE with a MAC: it's there. FAILED or INCOMPLETE: nobody answered the ARP request, so nothing at that address is on your network (wrong address, or the device is off). That's what "Destination Host Unreachable" means for a local address.
MTU: how big a packet can be
Every link has a maximum transmission unit, normally 1500 bytes on Ethernet. Bigger packets have to be split (fragmented) or are refused. Tunnels and VPNs add their own headers, which makes the space left smaller. The classic symptom of an MTU problem is strange: small things work (ping, SSH login, small pages), but big transfers or some HTTPS sites hang. Test it with "don't fragment" pings:
ping -c 1 -M do -s 1472 192.168.1.1 # 1472 + 8 (ICMP) + 20 (IP) = 1500: fits ping -c 1 -M do -s 1473 192.168.1.1 # 1501: too big
These layer tools work the same on both families. What's different is where you'd change the MTU permanently:
| Task | Rocky / RHEL | Ubuntu / Debian |
|---|---|---|
| See it | ip link show enp0s3 same on both | |
| Change it until reboot | sudo ip link set enp0s3 mtu 1400 same on both | |
| Change it for good | sudo nmcli con mod enp0s3 802-3-ethernet.mtu 1400 | mtu: 1400 under the interface in netplan |
| Install tcpdump | sudo dnf install tcpdump | preinstalled |
Try it: from the cable up 🧱
Start at the bottom of the club server's network stack and work your way up, one layer at a time.
Quick check
1. A packet travels from your server, through three routers, to a website. What changes at every hop?
✓ Each router unwraps and rewraps the frame for the next link. IP addresses stay end to end (unless NAT rewrites them).
2. ping 192.168.1.99 says "Destination Host Unreachable", and ip neigh shows 192.168.1.99 … FAILED. What does that mean?
✓ Wrong address, or the device is off or on another network.
3. Through a new VPN, SSH logins work but copying big files hangs. A good first suspect?
✓ Small packets fit, big ones don't. Test with ping -M do -s ….