TCP, UDP & Transport Layer
Transport Layer Role
The Transport Layer provides process-to-process communication across network hosts using Port Numbers (16-bit integers ranging from 0 to 65535). While Layer 3 (IP) routes packets between host IP addresses, Layer 4 (TCP/UDP) multiplexes traffic between specific application processes executing on those hosts.
π Process-to-Process Port Mapping
Port Resolution
Description
Outgoing web requests dynamically lease a high-range port (>49152) from the OS, connecting to a standard HTTPS port (443) on the server.
Bitwise TCP & IPv4 Header Architecture
Port Number Allocations
- Well-Known Ports (0β1023): Reserved for core system services (HTTP: 80, HTTPS: 443, SSH: 22, DNS: 53).
- Registered Ports (1024β49151): Reserved for application databases and services (PostgreSQL: 5432, MySQL: 3306, Redis: 6379, Kafka: 9092).
- Ephemeral / Dynamic Ports (49152β65535): Assigned temporarily by the OS kernel for client-initiated outgoing connections.
TCP β Transmission Control Protocol
TCP provides reliable, ordered, stateful, connection-oriented byte-stream delivery.
π Interactive TCP Segment Structure Header
Source & Destination Ports (16 bits each)
Process addressing. Identifies the specific application protocol on the sender and receiver host machines (ranges: 0β65535).
π‘ Hover over different segment header blocks to inspect their functionality details.
Key Features
- 3-Way Handshake Connection Establishment (
SYNSYN-ACKACK). - Guaranteed Ordered Delivery: Sequence Numbers (
seq) and Acknowledgement Numbers (ack). - Flow Control: Sliding Receive Window (
win) preventing receiver buffer overrun. - Congestion Control: Sender Congestion Window (
cwnd) preventing network intermediate router queue drops.
TCP 3-Way Handshake & Connection Teardown
π€ TCP Handshake Sequences (3-Way & 4-Way)
1. SYN (Synchronize)
Client βββΊ ServerClient sends a segment with SYN flag set, containing its Initial Sequence Number (ISN=x). Client moves to SYN_SENT state.
TCP Segment Parameters
SYN [seq=x] (ISN chosen randomly)
3-Way Handshake Sequence
- Client Server (
SYN): Client selects a random Initial Sequence Number (ISN ) and sends aSYNsegment (seq=x). Client entersSYN_SENT. - Server Client (
SYN-ACK): Server allocates TCB (Transmission Control Block), selects its own ISN (), and responds withSYN-ACK(seq=y, ack=x+1). Server entersSYN_RECEIVED. - Client Server (
ACK): Client acknowledges withACK(seq=x+1, ack=y+1). Both sides enterESTABLISHED.
TCP Flow Control (Sliding Window) vs Congestion Control
π¦ Sliding Window Flow & Zero-Window Control
1. Window Advertised (64KB)
Receiver has empty buffers, advertising Window=64KB. Sender can fire segments without waiting.
Buffer & Window Allocations
π TCP Congestion Control Simulator (AIMD)
1. Slow Start Phase
cwnd = cwnd * 2 (Exponential Growth)Starts with cwnd = 1 MSS. On receiving ACKs, the window doubles every RTT. This continues until cwnd reaches the slow-start threshold (ssthresh) or packet loss occurs.
Congestion Window (cwnd)
cwnd progression: 1 β 2 β 4 β 8 β 16 MSS
- Flow Control: Governed by the receiver's Advertised Window Size (
rwnd), preventing a fast sender from flooding a slow receiver's socket buffer. - Congestion Control: Governed by the sender's Congestion Window (
cwnd), probing network link capacity using algorithms like Slow Start, Congestion Avoidance (AIMD), CUBIC, and Google BBR.
UDP β User Datagram Protocol
π Minimal UDP Segment Header (8 Bytes total)
Source & Destination Ports (16 bits each)
Identifies the process endpoint application ports. Direct process-to-process packet parsing.
π‘ Hover over different UDP header blocks to inspect their functionality details.
UDP provides connectionless, unreliable, low-latency, datagram delivery.
- 8-Byte Fixed Header: Contains Source Port, Destination Port, Length, and Checksum.
- No Handshake / No Retransmissions: Minimal overhead, supporting broadcast and multicast.
Interview Questions
Q1. Describe the step-by-step mechanics of the TCP 3-Way Handshake.
The client sends a
SYNsegment containing a random Initial Sequence Number (ISN ). The server receives theSYN, allocates connection state buffers, and responds withSYN-ACKcontaining its own ISN () and acknowledgement number . The client finishes by sending anACKsegment with acknowledgement number . Both sides enter theESTABLISHEDstate, synchronizing sequence numbers for ordered, reliable byte-stream transmission.
Q2. What is the fundamental difference between TCP Flow Control and TCP Congestion Control?
Flow Control prevents a fast sender from overwhelming a slow receiver's application buffer. The receiver advertises its remaining free buffer capacity (Receive Window
rwnd) in every ACK header. Congestion Control prevents a sender from overwhelming the intermediate network infrastructure (routers, switches). The sender dynamically adjusts its Congestion Window (cwnd) based on network loss or RTT latency feedback.
Q3. Why does TCP require a TIME_WAIT state during connection termination?
When a TCP connection is closed gracefully by initiating a
FIN, the closer entersTIME_WAITfor (Maximum Segment Lifetime, typically ). This guarantees that: (1) The finalACKsent to the peer is delivered (or re-sent if lost); (2) Any lingering duplicate packets from the old connection expire in the network before a new connection reuses the same 4-tuple (Source IP,Source Port,Dest IP,Dest Port).
Q4. What is a SYN Flood attack and how do SYN Cookies mitigate it?
A SYN Flood is a Denial-of-Service attack where an attacker sends thousands of
SYNrequests with spoofed IP addresses without completing the finalACK. This exhausts the server's SYN Backlog Queue. SYN Cookies eliminate the attack by removing server-side memory allocations for half-open connections: the server encodes state into the initial sequence number (seq=y) returned in theSYN-ACK. Memory is allocated only when the client returns a validACK.
