Skip to main content

TCP, UDP & Transport Layer

Transport Layer Role

The Transport Layer provides process-to-process communication across network hosts using Port Numbers (16-bit integers ranging from 0 to 65535). While Layer 3 (IP) routes packets between host IP addresses, Layer 4 (TCP/UDP) multiplexes traffic between specific application processes executing on those hosts.

πŸ”Œ Process-to-Process Port Mapping

Port Resolution

πŸ‘€ Client App: Chrome Web Browser
Source Port: 54321 (Dynamic/Ephemeral)
Destination Port: 443 (Well-known HTTPS)
πŸ–₯️ Target Server: Nginx Web Server

Description

Outgoing web requests dynamically lease a high-range port (>49152) from the OS, connecting to a standard HTTPS port (443) on the server.


Bitwise TCP & IPv4 Header Architecture

Bitwise TCP & IPv4 Packet Header Architecture Visualizer
Standard 20-Byte TCP Header (32-Bit Word Alignment):
Source Port (16 bits)
0 - 15
Destination Port (16 bits)
16 - 31
Sequence Number (32 bits / 4 Bytes)
Tracks byte position in payload stream
Acknowledgment Number (32 bits / 4 Bytes)
Valid only when ACK flag is set
Offset (4b)
Res (3b)
Flags (9b)
Window Size (16b)
Checksum (16 bits)
Urgent Pointer (16 bits)

Port Number Allocations

  • Well-Known Ports (0–1023): Reserved for core system services (HTTP: 80, HTTPS: 443, SSH: 22, DNS: 53).
  • Registered Ports (1024–49151): Reserved for application databases and services (PostgreSQL: 5432, MySQL: 3306, Redis: 6379, Kafka: 9092).
  • Ephemeral / Dynamic Ports (49152–65535): Assigned temporarily by the OS kernel for client-initiated outgoing connections.

TCP β€” Transmission Control Protocol

TCP provides reliable, ordered, stateful, connection-oriented byte-stream delivery.

πŸ“Š Interactive TCP Segment Structure Header

Source Port (16b)
Destination Port (16b)
Sequence Number (32b)
Acknowledgment Number (32b)
Control Flags (9b)
Window Size (16b)
Checksum (16b)
Urgent Pointer (16b)

Source & Destination Ports (16 bits each)

Process addressing. Identifies the specific application protocol on the sender and receiver host machines (ranges: 0–65535).

πŸ’‘ Hover over different segment header blocks to inspect their functionality details.

Key Features

  • 3-Way Handshake Connection Establishment (SYN β†’\to SYN-ACK β†’\to ACK).
  • Guaranteed Ordered Delivery: Sequence Numbers (seq) and Acknowledgement Numbers (ack).
  • Flow Control: Sliding Receive Window (win) preventing receiver buffer overrun.
  • Congestion Control: Sender Congestion Window (cwnd) preventing network intermediate router queue drops.

TCP 3-Way Handshake & Connection Teardown

🀝 TCP Handshake Sequences (3-Way & 4-Way)

1. SYN (Synchronize)

Client ──► Server

Client sends a segment with SYN flag set, containing its Initial Sequence Number (ISN=x). Client moves to SYN_SENT state.

TCP Segment Parameters

SYN [seq=x] (ISN chosen randomly)

3-Way Handshake Sequence

  1. Client β†’\to Server (SYN): Client selects a random Initial Sequence Number (ISN =x= x) and sends a SYN segment (seq=x). Client enters SYN_SENT.
  2. Server β†’\to Client (SYN-ACK): Server allocates TCB (Transmission Control Block), selects its own ISN (yy), and responds with SYN-ACK (seq=y, ack=x+1). Server enters SYN_RECEIVED.
  3. Client β†’\to Server (ACK): Client acknowledges with ACK (seq=x+1, ack=y+1). Both sides enter ESTABLISHED.

TCP Flow Control (Sliding Window) vs Congestion Control

πŸ“¦ Sliding Window Flow & Zero-Window Control

1. Window Advertised (64KB)

Receiver has empty buffers, advertising Window=64KB. Sender can fire segments without waiting.

Buffer & Window Allocations

β€’ ACKed: 1-1000
β€’ In-Flight: 1001-2000
β€’ Can Send: 2001-4000
β€’ Locked: >4000

πŸ“ˆ TCP Congestion Control Simulator (AIMD)

1. Slow Start Phase

cwnd = cwnd * 2 (Exponential Growth)

Starts with cwnd = 1 MSS. On receiving ACKs, the window doubles every RTT. This continues until cwnd reaches the slow-start threshold (ssthresh) or packet loss occurs.

Congestion Window (cwnd)

cwnd progression: 1 β†’ 2 β†’ 4 β†’ 8 β†’ 16 MSS
  • Flow Control: Governed by the receiver's Advertised Window Size (rwnd), preventing a fast sender from flooding a slow receiver's socket buffer.
  • Congestion Control: Governed by the sender's Congestion Window (cwnd), probing network link capacity using algorithms like Slow Start, Congestion Avoidance (AIMD), CUBIC, and Google BBR.

UDP β€” User Datagram Protocol

πŸ“Š Minimal UDP Segment Header (8 Bytes total)

Source Port (16b)
Destination Port (16b)
Length (16b)
Checksum (16b)

Source & Destination Ports (16 bits each)

Identifies the process endpoint application ports. Direct process-to-process packet parsing.

πŸ’‘ Hover over different UDP header blocks to inspect their functionality details.

UDP provides connectionless, unreliable, low-latency, datagram delivery.

  • 8-Byte Fixed Header: Contains Source Port, Destination Port, Length, and Checksum.
  • No Handshake / No Retransmissions: Minimal overhead, supporting broadcast and multicast.

Interview Questions

Q1. Describe the step-by-step mechanics of the TCP 3-Way Handshake.

The client sends a SYN segment containing a random Initial Sequence Number (ISN =x= x). The server receives the SYN, allocates connection state buffers, and responds with SYN-ACK containing its own ISN (yy) and acknowledgement number x+1x+1. The client finishes by sending an ACK segment with acknowledgement number y+1y+1. Both sides enter the ESTABLISHED state, synchronizing sequence numbers for ordered, reliable byte-stream transmission.

Q2. What is the fundamental difference between TCP Flow Control and TCP Congestion Control?

Flow Control prevents a fast sender from overwhelming a slow receiver's application buffer. The receiver advertises its remaining free buffer capacity (Receive Window rwnd) in every ACK header. Congestion Control prevents a sender from overwhelming the intermediate network infrastructure (routers, switches). The sender dynamically adjusts its Congestion Window (cwnd) based on network loss or RTT latency feedback.

Q3. Why does TCP require a TIME_WAIT state during connection termination?

When a TCP connection is closed gracefully by initiating a FIN, the closer enters TIME_WAIT for 2Γ—MSL2 \times \text{MSL} (Maximum Segment Lifetime, typically 60Β seconds60\text{ seconds}). This guarantees that: (1) The final ACK sent to the peer is delivered (or re-sent if lost); (2) Any lingering duplicate packets from the old connection expire in the network before a new connection reuses the same 4-tuple (Source IP, Source Port, Dest IP, Dest Port).

Q4. What is a SYN Flood attack and how do SYN Cookies mitigate it?

A SYN Flood is a Denial-of-Service attack where an attacker sends thousands of SYN requests with spoofed IP addresses without completing the final ACK. This exhausts the server's SYN Backlog Queue. SYN Cookies eliminate the attack by removing server-side memory allocations for half-open connections: the server encodes state into the initial sequence number (seq=y) returned in the SYN-ACK. Memory is allocated only when the client returns a valid ACK.


See Also

πŸ“–
Track Page Progress0 / 635 Read
Knowledge Base Completion0%