Skip to main content

OSI Layers

The OSI model is a seven-layer reference model, not a guarantee that each protocol provides reliability.

What is OSI Layers?

The OSI model is a seven-layer reference model, not a guarantee that each protocol provides reliability. The data link layer transfers frames over a link and can provide link-specific detection or recovery. The network layer routes packets between networks. The transport layer provides end-to-end transport services. TCP is reliable and UDP is not. Pomerium makes HTTP policy decisions with Layer 7 information and can also proxy TCP and UDP routes through supported clients.

Why it matters

The layer model gives teams a shared way to locate a protocol, control, or failure. It also helps them see when a network rule lacks the application information needed for a precise access decision.

How it works

  1. Each layer provides services to the layer above it and uses services from the layer below it.
  2. A sender adds protocol information as data moves down the stack, and a receiver processes that information as data moves up the stack.
  3. Network and security controls inspect the fields and behavior available at the layers they understand.

Example

Teams often describe an HTTPS request as IP at Layer 3, TCP at Layer 4, and HTTP at Layer 7. A Layer 7 proxy can distinguish two HTTP paths that share one IP address and port.

Pomerium boundary

Pomerium applies application-aware policy to HTTP routes and can inspect HTTP request information. It can also tunnel TCP and UDP services through supported clients, but those connections do not expose the same HTTP semantics for policy.

Limits and non-claims

  • Internet protocols do not always map cleanly to one OSI layer.
  • A product can operate across several layers, so one layer label can hide important behavior.
  • A higher layer number does not make a protocol more secure or more reliable.

Evaluation checklist

  • At which layer does each control read data, make a claim, and enforce a result?
  • Which identity, authorization, or application property is outside that layer's scope?
  • Where do encapsulation, proxy termination, or tunneling move the effective trust boundary?

Sources and further reading

Keep learning

Application and Service Access

Layer-7 Enforcement

Layer 7 enforcement uses protocol facts, such as host, route, method, tool name, and verified identity, to make access decisions.

Learn this term
Network and Infrastructure

Firewall

A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy.

Learn this term
Application and Service Access

Route

In Pomerium, a route defines how a requester reaches a service behind Pomerium.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo