Home/Labs/OSI Encapsulation Bench
All 280 Labs
INTERACTIVE LAB📦

OSI vs TCP/IP Model Lab (Interactive)

Wrap a payload down seven layers, count real header bytes, and choose L4 or L7 for your load balancer. Interactive encapsulation stack showing per-layer headers, segment math against the 1460-byte MSS, and L4 versus L7 capabilities.

OSI Layers & Packet Encapsulation Bench

Wrap a payload down the 7-layer stack, count real header bytes, and pick where your load balancer lives.

What the L7 balancer can see:

TLS termination (needs to parse records)

Path-based routing /api → orders fleet

Per-user rate limiting (reads JWT/headers)

Canary/Blue-Green header rewrites

Encapsulated view looking down from L7 (send direction ↓)
[ | PAYLOAD 1024 B ]
Headers per segment
79 B
TCP segments (MTU 1460)
1
On-wire overhead
7.7%

~79 bytes of headers ride on every small HTTPS segment — which is why 50-byte Protobuf frames over gRPC beat verbose JSON-over-REST for chatty inter-service calls.

How It Works Under the Hood

Network layering lets software ignore physics: an HTTP/2 client sending JSON does not care whether bytes ride fiber, satellite, or 5G. Going down the stack, each layer wraps the payload in its header — TLS records (21 bytes), TCP (20), IPv4 (20), Ethernet (14 plus FCS) — about 79 bytes of overhead on a small HTTPS segment, roughly 7%. The L4-versus-L7 choice is the most interview-relevant axis: L4 balancers (AWS NLB) proxy raw IP+port at line rate but cannot read URLs or JWTs; L7 balancers (ALB, Envoy, CDNs) decrypt and parse HTTP for path routing, per-user rate limiting, and SSL termination at higher CPU cost.

Core Architectural Principles

  • Encapsulation: each layer adds its header; de-encapsulation strips them going up at the receiver.
  • L4 operates on IP+port only; path-based routing, JWT rate limiting, and TLS termination require L7.
  • The TCP/IP model condenses OSI into four layers: Network Access, Internet, Transport, Application.
Interview Round Script

When choosing a balancer, reason aloud: "For database proxying I want NLB L4 at line rate; for microservice path routing and per-token rate limiting I need ALB L7 — and SSL termination is only possible at L7." Noting the ~79-byte header overhead also justifies picking Protobuf/gRPC over JSON/REST for chatty internal calls.

Key Trade-Offs

More layers inspected mean richer routing and security at higher CPU cost and per-hop latency; abstraction enables independent innovation per layer.

Related Curriculum Chapter

OSI vs TCP/IP Model Overview

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs