1.2 TCP/IP Protocol Suite and IP Headers

Key Takeaways

  • The TCP/IP model condenses network architecture into four functional layers (Application, Transport, Internet, Network Access), matching real-world IP network deployments.

  • TCP provides reliable, ordered, byte-stream transmission using a three-way handshake (SYN, SYN-ACK, ACK) and sliding-window flow control, whereas UDP provides low-overhead, connectionless datagram transport.

  • The IPv4 header contains a 20-byte base header with critical fields including Time-to-Live (TTL) for loop mitigation, Protocol to identify Layer 4 payloads (TCP: 6, UDP: 17, OSPF: 89, ICMP: 1), and DSCP for QoS classification.

  • Enterprise management and security protocols rely on specific transport assignments, notably TACACS+ operating over reliable TCP port 49, while RADIUS operates over UDP ports 1812 (authentication) and 1813 (accounting).

Last updated: October 2026

TCP/IP Protocol Suite and IP Headers

Quick Summary: The TCP/IP protocol suite forms the operational foundation of modern enterprise networks. While the OSI model serves as a conceptual reference, production campus networks run TCP/IP protocols. At Layer 4, TCP delivers connection-oriented, reliable transmission with sliding-window flow control, while UDP provides lightweight, connectionless delivery ideal for real-time traffic like voice and video. At Layer 3, the IPv4 header provides logical addressing, loop prevention via Time-to-Live (TTL), and protocol multiplexing to direct payloads to the correct upper-layer protocol.


The TCP/IP Architecture vs. OSI Reference Model

Originally developed by DARPA, the TCP/IP model (RFC 1122) focuses on practical protocol implementation rather than theoretical boundaries. Modern network engineering compares the classic 4-layer DoD model, the practical 5-layer model, and the 7-layer OSI model:

OSI 7-Layer ModelTCP/IP Practical 5-Layer ModelOriginal DoD 4-Layer ModelRepresentative Protocols & Standards
Layer 7: ApplicationLayer 5: ApplicationLayer 4: Application (Process)HTTP, HTTPS, SSH, DNS, DHCP, NTP, SNMP, RADIUS
Layer 6: Presentation^^TLS, SSL, Base64, JSON
Layer 5: Session^^RPC, Sockets, Session API
Layer 4: TransportLayer 4: TransportLayer 3: Host-to-Host (Transport)TCP, UDP
Layer 3: NetworkLayer 3: Network (Internet)Layer 2: InternetIPv4, IPv6, ICMP, ARP, OSPF
Layer 2: Data LinkLayer 2: Data LinkLayer 1: Network Access (Link)Ethernet (802.3), Wi-Fi (802.11), 802.1Q VLAN
Layer 1: PhysicalLayer 1: Physical^1000BASE-T, 10GBASE-SR, DAC cables, SFP+

In the TCP/IP suite, application developers integrate data presentation and session logic directly into user applications and shared cryptographic libraries (such as OpenSSL), eliminating the need for standalone Presentation and Session layers.


Layer 4 Transport Protocols: TCP vs. UDP

The Transport Layer establishes logical communication channels between host application processes. Two primary protocols operate at Layer 4:

Transmission Control Protocol (TCP - RFC 793)

TCP provides connection-oriented, reliable, sequenced data delivery:

  • Reliability: Every transmitted segment requires an acknowledgment (ACK). Missing segments trigger timer expiration and automatic retransmission.
  • Sequencing: TCP assigns a 32-bit sequence number to each byte, allowing the receiver to reorder out-of-order packets into a seamless byte stream.
  • Flow Control (Sliding Window): The receiver advertises an available Window Size in its header, preventing high-speed senders from overflowing receiving buffers.
  • Congestion Control: Senders monitor round-trip latency and packet loss, dynamically adjusting transmission rates to prevent campus link congestion.

The TCP Three-Way Handshake

Before transferring application payload, TCP establishes state via a three-way exchange:

  1. SYN (Synchronize): The client transmits a segment with the SYN flag set and an Initial Sequence Number (ISN) xx.
  2. SYN-ACK: The server acknowledges with ACK (x+1x + 1), sets SYN, and supplies its own ISN yy.
  3. ACK: The client acknowledges with ACK (y+1y + 1). The session reaches the ESTABLISHED state, and data transfer begins.

Graceful session termination uses FIN and ACK handshakes, while abrupt resets use the RST flag.

User Datagram Protocol (UDP - RFC 768)

UDP provides connectionless, lightweight, best-effort transmission. It omits connection handshakes, sequence tracking, acknowledgments, and retransmissions:

  • Minimal Overhead: Fixed 8-byte header (versus TCP's 20-byte minimum).
  • Zero Connection Delay: Applications transmit immediately without handshake round trips.
  • Target Workloads: Real-time delay-sensitive traffic (VoIP, streaming video) and lightweight request-response services (DNS queries, DHCP, NTP, syslog).
FeatureTCPUDP
Connection StateConnection-oriented (Handshake required)Connectionless (No handshake)
ReliabilityGuaranteed (Acknowledgments & retransmissions)Best-effort (No retransmissions)
Header Size20 to 60 bytes (20 bytes standard)8 bytes fixed
OrderingEnforced via 32-bit sequence numbersDatagrams delivered as received
Flow ControlYes (Sliding window and congestion avoidance)None
Campus WorkloadsWeb (HTTPS), SSH, TACACS+, File Transfer (SFTP)Voice (RTP), Video, DNS, DHCP, RADIUS, Syslog

Port Addressing and Service Multiplexing

Transport layer headers feature 16-bit Source Port and Destination Port fields (0 to 65,535), enabling service multiplexing across a single IP address.

IANA organizes ports into three standardized tiers:

  • Well-Known Ports (0-1023): Standardized core infrastructure services.
  • Registered Ports (1024-49151): Vendor applications and specific network protocols.
  • Dynamic / Ephemeral Ports (49152-65535): Client-assigned temporary source ports.

Essential Campus Network Ports

ProtocolPort NumberTransport ProtocolRole in Campus Network
SSH22TCPSecure encrypted CLI management for switches and APs
Telnet23TCPInsecure legacy CLI access (disabled by default on AOS-CX)
DNS53UDP / TCPName resolution (UDP queries, TCP zone transfers)
DHCP Server67UDPServer port receiving client discovers and requests
DHCP Client68UDPClient port receiving server offers and acknowledgments
HTTP / HTTPS80 / 443TCPWeb GUI, Aruba Central cloud uplink, Captive Portal
NTP123UDPNetwork Time Protocol clock synchronization
Syslog514UDPSystem event logging to central monitoring servers
SNMP161 / 162UDPPort 161 for device polling; Port 162 for traps
RADIUS Auth / Acct1812 / 1813UDP802.1X authentication (1812) and accounting (1813)
RADIUS CoA3799UDPChange of Authorization (CoA) dynamic policy disconnects
TACACS+49TCPAdministrative AAA authentication and command authorization

Critical Exam Distinction: TACACS+ uses TCP port 49, ensuring reliable command authorization and accounting logs. In contrast, RADIUS uses UDP ports 1812 and 1813, relying on application-level timeouts and retransmissions.


IPv4 Header Deep-Dive

The IPv4 header provides Layer 3 addressing, routing loop prevention, and protocol demultiplexing across enterprise subnets. A standard header without options is 20 bytes long.

IPv4 Header Field Breakdown

  1. Version (4 bits): Set to binary 0100 (4) for IPv4.
  2. Internet Header Length (IHL - 4 bits): Measures header length in 32-bit words (minimum 5, meaning 5×4=20 bytes5 \times 4 = 20\text{ bytes}). With options, it expands up to 60 bytes.
  3. Type of Service / DSCP (8 bits): Differentiated Services Code Point (6 bits) classifies traffic for campus Quality of Service (QoS), alongside Explicit Congestion Notification (2 bits).
  4. Total Length (16 bits): Entire packet size in bytes (header plus payload, up to 65,535 bytes).
  5. Identification, Flags, Fragment Offset (32 bits total): Manage packet fragmentation. Flags include Don't Fragment (DF) and More Fragments (MF).
  6. Time-to-Live (TTL - 8 bits): Hop counter preventing routing loops. Routers decrement TTL by 1 at each hop. If TTL reaches 0, the router discards the packet and returns an ICMP Type 11 Code 0 (Time Exceeded in Transit) error.
  7. Protocol (8 bits): Identifies the encapsulated Layer 4 payload: 1 for ICMP, 6 for TCP, 17 for UDP, and 89 for OSPF.
  8. Header Checksum (16 bits): Verifies IPv4 header integrity. Because routers decrement TTL at each hop, they must recalculate this checksum at every routing hop.
  9. Source and Destination IP Addresses (32 bits each): Logical origin and target endpoints.

Contrast with IPv6 Header Architecture

IPv6 streamlines Layer 3 processing with a fixed 40-byte base header. Key differences include:

  • Hop Limit: Replaces IPv4's TTL field with identical decrement behavior.
  • Next Header: Replaces IPv4's Protocol field, identifying Layer 4 protocols or chained extension headers.
  • No Header Checksum: Eliminates hop-by-hop checksum recalculation, delegating integrity checks to Layer 2 and Layer 4.

Diagnostic Verification on Aruba CX Switches

Network administrators utilize built-in AOS-CX diagnostic tools that leverage these header fields:

  • Ping: Sends ICMP Type 8 (Echo Request) packets and evaluates ICMP Type 0 (Echo Reply) returns to verify Layer 3 reachability.
  • Traceroute: Systematically increments the IPv4 TTL (1, 2, 3...) to elicit ICMP Time Exceeded responses, mapping every router hop along the path.

Common Exam Traps

  • Transport Confusion for Security Protocols: Memorize that TACACS+ = TCP 49 (reliable administrative session) while RADIUS = UDP 1812/1813 (connectionless network access).
  • Header Location of TTL: TTL resides in the Layer 3 IPv4 header, never in Layer 4 TCP/UDP headers.
  • Layer 2 Switches and TTL: Layer 2 switches do not decrement the TTL. Only Layer 3 forwarding hops decrement TTL.
Loading diagram...
TCP 3-Way Handshake vs UDP Datagram Transmission
Test Your Knowledge

During a TCP connection establishment between an administrative management workstation and an Aruba CX 6300 switch via SSH, which sequence of control flags is exchanged during the three-way handshake?

A

Workstation sends RST -> Switch replies SYN -> Workstation sends ACK

B

Workstation sends SYN -> Switch replies ACK -> Workstation sends SYN-ACK

C

Workstation sends ACK -> Switch replies SYN -> Workstation sends FIN

D

Workstation sends SYN -> Switch replies SYN-ACK -> Workstation sends ACK

Test Your Knowledge

When configuring administrative authentication and network access control in an Aruba enterprise campus, what is a primary transport layer difference between the TACACS+ and RADIUS protocols?

A

TACACS+ relies on TCP port 49 to provide reliable transport, whereas RADIUS uses UDP ports 1812 and 1813

B

TACACS+ uses connectionless UDP port 49 for lower latency, while RADIUS uses connection-oriented TCP port 1812 for guaranteed delivery

C

TACACS+ and RADIUS both use UDP to avoid transport-layer connection overhead during authentication

D

TACACS+ uses TCP port 1812, while RADIUS uses UDP port 49

Test Your Knowledge

A network engineer issues a traceroute command from a core Aruba CX 8325 switch to a remote campus branch router. What IPv4 header field is intentionally manipulated to identify intermediate routers, and what ICMP message is generated when this value reaches zero?

A

Differentiated Services Code Point (DSCP); intermediate routers return ICMP Type 8 (Echo Request)

B

Time-to-Live (TTL); intermediate routers drop the packet and return ICMP Type 11 (Time Exceeded)

C

Protocol field; intermediate routers return ICMP Type 3 (Destination Unreachable)

D

Identification field; intermediate routers return ICMP Type 0 (Echo Reply)

Sections you finish are checked off in the contents.