Network Layer
Network Layer
The Network Layer is the third layer of the OSI model. Its job is to move data packets from a source device to a destination device across one or more interconnected networks — even when those networks use completely different physical technologies underneath.
The Data Link Layer (Layer 2) only knows how to deliver a frame to another device on the same local network. It has no concept of "the other side of the world." The Network Layer is what makes that leap possible: it identifies devices with logical addresses, works out a path between networks, and hands packets from router to router until they reach their destination. Without it, the Internet — a network of networks — could not exist.
Where the Network Layer Sits in the OSI Model
| Layer Number | OSI Layer |
|---|---|
| 7 | Application Layer |
| 6 | Presentation Layer |
| 5 | Session Layer |
| 4 | Transport Layer |
| 3 | Network Layer |
| 2 | Data Link Layer |
| 1 | Physical Layer |
The Network Layer sits between the Transport Layer above it and the Data Link Layer below it. The Transport Layer (Layer 4) cares about end-to-end delivery between applications — things like reliability and ordering. The Data Link Layer (Layer 2) cares only about delivery across a single physical link. The Network Layer bridges the two: it takes a segment from the Transport Layer, wraps it in a packet with source and destination addresses, and figures out which sequence of links and routers will get it to the other network.
Why the Network Layer Matters
A useful analogy is postal mail. Sending a letter from Chennai to New York requires the postal service to:
- Read the destination address on the envelope.
- Decide which route the letter should travel (which sorting centers, which flights).
- Forward it through a chain of intermediate post offices.
- Deliver it to the correct mailbox at the end.
No single post office knows the entire path in advance — each one only decides the next hop. The Network Layer works the same way:
- It identifies devices using IP addresses instead of street addresses.
- It determines a route across multiple networks.
- It forwards packets through a chain of routers, each deciding only the next hop.
- It delivers the packet to the correct destination device.
Main Objectives of the Network Layer
- Logical addressing — giving every device a network-wide identifier.
- Routing — choosing the best path between networks.
- Packet forwarding — moving packets along that path, one hop at a time.
- Fragmentation and reassembly — splitting packets that are too large for a given link and reassembling them later.
- Internetworking — allowing dissimilar networks (Ethernet, Wi-Fi, mobile, satellite) to communicate as one system.
- Congestion management — keeping traffic flowing smoothly when demand exceeds capacity.
The rest of this lesson looks at each of these in turn.
1. Logical Addressing
Every device on a network needs a unique identifier so that other devices can find it. The Network Layer solves this with IP addresses (Internet Protocol addresses).
This is different from the MAC address used at the Data Link Layer. A MAC address is burned into a network interface card and identifies a device only within its local network segment — it has no idea which network that device belongs to. An IP address, by contrast, encodes two pieces of information at once:
- Which network the device is on.
- Which specific device it is within that network.
This dual structure is exactly what makes routing between networks possible: a router only needs to look at the network portion of an IP address to decide which direction to send a packet, without knowing anything about every individual device out there.
IPv4 address example:
192.168.1.10
IPv6 address example:
2001:0db8:85a3:0000:0000:8a2e:0370:7334
A home postal address is a good mental model for this layered structure:
| Postal Address Part | IP Address Equivalent |
|---|---|
| Country | Network |
| City | Subnetwork |
| House Number | Specific Device (Host) |
Just as a postal worker doesn't need to know the exact house number to route a letter to the right city, a router often only needs the network portion of an IP address to forward a packet in the right general direction. The final router in the chain — the one directly connected to the destination network — is the one that resolves the exact host.
2. Routing
Routing is the process of selecting the best path for a packet to travel from its source to its destination. Because multiple paths between two networks usually exist, routers must decide which one to use, based on factors such as:
- Distance (number of hops)
- Cost (link cost assigned by an administrator or protocol)
- Current network congestion
- Administrative policies (e.g., "never route through this ISP")
- Available bandwidth
This is similar to planning a trip from Chennai to Bengaluru: you could go by highway, by train, or by flight, and you typically pick whichever is fastest or cheapest for your needs. Routers make the same kind of trade-off automatically, thousands of times per second.
Routing decisions are stored in a routing table, and routes get into that table in one of two ways: static routing or dynamic routing.
Static Routing
In static routing, a network administrator manually configures each route.
Advantages:
- Simple to understand and predict.
- More secure, since routes cannot be changed by an attacker manipulating routing protocols.
- Uses very little router CPU or memory, since no route computation happens.
Disadvantages:
- Does not scale — every new network requires a manual configuration change on every affected router.
- Does not adapt automatically when a link fails; traffic keeps trying to use a dead route until someone fixes it.
Static routing is typically used in small networks or for specific, stable routes (such as a default route to an ISP) where automatic updates aren't needed.
Dynamic Routing
In dynamic routing, routers run a routing protocol that automatically learns about available networks and recalculates routes when conditions change — for example, when a link goes down or a new network segment is added.
Advantages:
- Scales to large, complex networks.
- Adapts automatically to topology changes (link failures, new links).
- Requires far less manual maintenance.
Disadvantages:
- More complex to configure and troubleshoot.
- Consumes more router CPU and memory to run the routing protocol and recompute paths.
Examples of dynamic routing protocols include RIP, OSPF, EIGRP, and BGP — covered in more depth later in this series.
Note: Routing and forwarding are often confused, but they are two distinct jobs. Routing is the planning step — building the routing table that says which path leads where. Forwarding is the execution step — actually moving each packet along that path. The next section covers forwarding in detail.
3. Packet Forwarding
If routing decides which path to use, forwarding is the act of actually sending a packet along it, one router at a time.
When a router receives a packet, it performs a short, repeatable sequence of steps:
- Reads the destination IP address in the packet header.
- Looks up that address in its forwarding table.
- Selects the outgoing interface associated with the matching entry.
- Sends the packet out through that interface toward the next router (the "next hop").
Example
Suppose a router receives a packet addressed to 172.16.10.5. It checks its forwarding table for an entry matching that network:
| Destination Network | Next Hop | Interface |
|---|---|---|
| 172.16.0.0/16 | Router B | G0/1 |
| 192.168.1.0/24 | Router C | G0/2 |
Since 172.16.10.5 falls inside the 172.16.0.0/16 network, the router forwards the packet out interface G0/1 toward Router B. Router B repeats the same lookup-and-forward process, and this continues until the packet reaches a router directly connected to the destination network.
This table-driven, hop-by-hop process is what allows forwarding to be extremely fast — a router doesn't need to know the entire end-to-end path, only the single next step for a given destination.
4. Fragmentation and Reassembly
Not every network can carry a packet of the same size. Each network link has a maximum frame size it can transmit, known as the Maximum Transmission Unit (MTU). Ethernet, for instance, commonly has an MTU of 1500 bytes.
If a packet is larger than the MTU of the link it needs to cross, the Network Layer must break it into smaller pieces — a process called fragmentation.
Example
If an application generates a 4000-byte packet, but the outgoing network's MTU is 1500 bytes, the packet cannot be sent as-is. It must be split into multiple fragments, each small enough to fit within that 1500-byte limit. Each fragment carries:
- A portion of the original packet's data.
- Fragmentation metadata (such as an identifier common to all fragments of the same original packet).
- Sequencing information, so the fragments can be put back in the correct order later.
Reassembly
At the destination device, the Network Layer collects all the fragments belonging to the same original packet, reassembles them in order using the sequencing information, and passes the complete, reconstructed packet up to the Transport Layer. If even one fragment is lost, the entire original packet typically has to be discarded and (depending on the protocol above it) retransmitted, since Layer 3 fragmentation has no independent recovery mechanism for a missing fragment.
Note: Modern IPv6 does not allow routers to fragment packets in transit — only the sending host can fragment a packet, using Path MTU Discovery to find the smallest MTU along the path beforehand. IPv4 does allow in-transit fragmentation by routers, though it is discouraged today because of the performance cost.
5. Internetworking
Internetworking means connecting multiple independent networks — potentially built on very different physical and link-layer technologies — so they function as a single, unified network. The Internet itself is the largest example of internetworking in existence.
The Network Layer is what makes this possible, because IP provides a common addressing and packet format that sits above the differences between the underlying networks. It doesn't matter whether a packet's journey involves:
- Ethernet networks
- Wi-Fi networks
- Mobile (cellular) networks
- MPLS backbone networks
- Satellite links
As long as every network along the path can carry an IP packet, the Network Layer provides a common language for them to interoperate. A smartphone connected over Wi-Fi can exchange data with a cloud server connected over fiber-optic cable precisely because both ends — and every router in between — speak IP.
6. Traffic Control and Congestion Management
Congestion occurs when the volume of traffic entering a network exceeds what it can carry. When routers cannot forward packets as fast as they arrive, packets queue up in router buffers; if those buffers fill completely, additional packets are dropped. Congestion typically results in:
- Packet loss
- Increased delay (latency)
- Reduced overall throughput
Congestion Management Techniques
Queuing — Routers temporarily hold incoming packets in memory buffers until they can be transmitted, smoothing out short bursts of traffic.
Traffic shaping — Controls the rate at which traffic is allowed to enter the network, preventing a burst from overwhelming downstream links.
Priority handling (Quality of Service) — Assigns higher forwarding priority to traffic that is sensitive to delay, such as:
- Voice calls
- Video conferencing
- Online gaming
Explicit Congestion Notification (ECN) — Allows a router that is starting to experience congestion to mark a packet's header rather than dropping it outright. This lets the receiving endpoint tell the sender to slow down before actual packet loss occurs, which is more efficient than waiting for loss to trigger a retransmission.
Services the Network Layer Can Provide
Depending on the specific protocol and network design, the Network Layer may offer some of the following services to the layers above it:
- Guaranteed delivery — ensuring a packet eventually reaches its destination.
- Delivery with bounded delay — guaranteeing a packet arrives within a defined time limit (important for real-time traffic).
- In-order delivery — ensuring packets arrive in the same sequence they were sent.
- Jitter control — keeping the variation in packet arrival times low and predictable, which matters greatly for video calls, online meetings, and streaming, where inconsistent timing causes visible or audible glitches.
- Security services — authentication, encryption, and data integrity, most commonly implemented through IPsec.
Important nuance: Standard IP itself is a "best-effort" service — it does not guarantee delivery, order, or bounded delay on its own. Services like guaranteed delivery and in-order delivery are usually provided by the Transport Layer (TCP) or by specialized Network Layer technologies (such as MPLS traffic engineering) rather than by plain IP.
Network Layer Protocols
Several protocols operate at the Network Layer, each with a distinct purpose.
Internet Protocol (IP)
IP is the foundation of network communication — it defines the packet format and addressing scheme that everything else in this layer builds on.
IPv4
- 32-bit addresses
- Roughly 4.3 billion possible addresses
- Example:
192.168.1.100
IPv6
- 128-bit addresses
- A vastly larger address space, designed to accommodate the continued growth of Internet-connected devices
- Example:
2001:db8::1
ICMP (Internet Control Message Protocol)
ICMP is used for error reporting and network diagnostics rather than for carrying application data. It's what powers two of the most common network troubleshooting tools:
- Ping — checks whether a host is reachable and measures round-trip time.
- Traceroute — reveals the sequence of routers a packet passes through on its way to a destination.
IGMP (Internet Group Management Protocol)
IGMP manages multicast group membership — it lets a host tell its local router "I want to receive traffic for this multicast group." This is commonly used in video streaming and other one-to-many broadcasting scenarios.
IPsec (Internet Protocol Security)
IPsec adds encryption, authentication, and secure communication directly at the Network Layer. It is the technology underlying most VPNs (Virtual Private Networks).
ARP (Address Resolution Protocol)
ARP converts an IP address into a MAC address, allowing devices on the same local network to actually deliver frames to each other. Technically, ARP sits at the boundary between the Network Layer and the Data Link Layer — IP needs the destination's MAC address to hand a packet down to the Data Link Layer for local delivery, and ARP is what resolves it.
Routing Algorithms
Routers use routing algorithms to determine the best path across a network. These are the general families; a dedicated lesson later in this series covers each one in depth.
1. Distance Vector Routing
Example: RIP (Routing Information Protocol)
Each router exchanges routing information only with its directly connected neighbors and chooses routes based on hop count (the number of routers a packet must pass through).
Advantages: simple, easy to implement. Disadvantages: slow to converge after a topology change, and prone to routing loops in certain failure scenarios.
2. Link State Routing
Example: OSPF (Open Shortest Path First)
Each router builds a complete map of the network's topology (by flooding link-state information to every other router) and independently calculates the shortest path to every destination.
Advantages: converges faster than distance vector protocols, and produces more accurate routing decisions. Disadvantages: requires more router memory and processing power to store the topology map and run the shortest-path calculation.
3. Path Vector Routing
Example: BGP (Border Gateway Protocol)
Used between autonomous systems on the public Internet — that is, between different organizations and Internet Service Providers, rather than inside a single organization's network. BGP advertises the complete path (the sequence of autonomous systems) a route has traveled through, which lets routers detect and avoid routing loops.
4. Hybrid Routing
Example: EIGRP (Enhanced Interior Gateway Routing Protocol)
Combines ideas from both distance vector and link state routing, aiming for the efficiency of distance vector protocols with the fast convergence and accuracy more typical of link state protocols.
Real-World Applications of the Network Layer
Internet browsing — Every time you open a website, your request is broken into packets that routers forward across multiple networks until they reach the web server, and the response follows the same process in reverse.
Virtual Private Networks (VPNs) — VPNs rely on Network Layer technologies (typically IPsec) to encrypt traffic, mask the user's real IP address, and establish a secure tunnel between two networks or between a device and a network.
Cloud computing — Services such as Google Drive, AWS, and Microsoft Azure depend entirely on routing and packet forwarding to move data between users and data centers around the world.
Mobile networks — When a smartphone switches from Wi-Fi to mobile data, the Network Layer (working with mechanisms like Mobile IP or the carrier network's own routing) helps preserve connectivity for ongoing connections.
Video streaming — Platforms like YouTube and Netflix depend on efficient routing and congestion management to keep video playback smooth, even under heavy network load.
Common Mistakes to Avoid
- Confusing routing with forwarding. Routing builds the map (the routing table); forwarding is the router acting on that map for each individual packet.
- Confusing an IP address with a MAC address. IP addresses identify a device across the entire internetwork and can change (e.g., when a device moves networks); MAC addresses identify a network interface on the local link and are effectively fixed.
- Assuming IP guarantees delivery. Standard IP is a best-effort protocol. Reliability, if needed, is typically added by the Transport Layer (TCP) on top of it.
- Ignoring MTU when troubleshooting slow or failing connections. Excessive fragmentation, or packets being silently dropped because a "don't fragment" flag prevents necessary fragmentation, is a common and easy-to-miss cause of connectivity problems.
The Future of the Network Layer
The Network Layer continues to evolve alongside new demands on the Internet:
- IPv6 adoption — providing the address space needed for the continued growth of connected devices and IoT systems, as the pool of available IPv4 addresses is effectively exhausted.
- Software-Defined Networking (SDN) — separates the control plane (routing decisions) from the data plane (packet forwarding hardware), enabling centralized, programmable network management instead of configuring each router individually.
- 5G and beyond — mobile networks increasingly demand low latency, high throughput, and strict Quality of Service guarantees, all of which depend on Network Layer mechanisms for routing and traffic prioritization.
- Network Function Virtualization (NFV) — replaces dedicated hardware appliances (routers, firewalls, load balancers) with software running on general-purpose servers, reducing cost and enabling faster deployment and greater flexibility.
- Enhanced security — growing use of stronger encryption, more robust authentication, and AI-assisted threat detection to protect data as it moves across increasingly complex, interconnected networks.
Related Concepts
- Data Link Layer — handles delivery within a single local network using MAC addresses.
- Transport Layer — builds reliability, ordering, and flow control on top of the Network Layer's best-effort delivery.
- Subnetting and CIDR — the techniques used to divide the IP address space into networks and subnetworks.
- Routing protocols (RIP, OSPF, BGP, EIGRP) — covered in dedicated lessons later in this series.