1. The 7 Layers of the OSI Model (Top-to-Bottom / In Order)
| Layer | ชื่อ Layer | Data Unit (PDU) | หน้าที่หลัก และ Protocols/เทคโนโลยีที่เกี่ยวข้อง |
| 7 | Application | Data | จุดเชื่อมต่อระหว่างซอฟต์แวร์ของผู้ใช้กับบริการเครือข่าย เช่น Web Browser หรือ Mail Client ส่งคำขอ • Protocols: HTTP/HTTPS, DNS, SSH, FTP, SMTP, DHCP |
| 6 | Presentation | Data | จัดการรูปแบบข้อมูล (Data Formatting/Syntax), การบีบอัด (Compression), และการเข้ารหัส/ถอดรหัส (Encryption/Decryption) • ตัวอย่าง: TLS/SSL, ASCII, JSON, XML, JPEG, MP4 |
| 5 | Session | Data | สร้าง (Establish), บำรุงรักษา (Maintain), ควบคุมบทสนทนา (Dialog Control/Checkpoint), และตัดการเชื่อมต่อ (Terminate) ระหว่าง Application ทั้งสองฝั่ง • Protocols/APIs: NetBIOS, RPC, Sockets, PPTP |
| 4 | Transport | Segment (TCP) / Datagram (UDP) | จัดการส่งข้อมูลแบบ End-to-End ระหว่าง Host (Process-to-Process) ควบคุม Flow Control, Error Recovery, Multiplexing ผ่าน Port Numbers • TCP: Connection-oriented, Reliable, มี 3-Way Handshake • UDP: Connectionless, Fast, ไม่รับประกันการส่งถึง |
| 3 | Network | Packet | ค้นหาเส้นทางที่ดีที่สุด (Routing) และระบุที่อยู่เชิงตรรกะ (Logical Addressing / IP Address) ข้าม Network/Subnet ต่างๆ • Protocols: IPv4, IPv6, ICMP, IPsec, OSPF, BGP |
| 2 | Data Link | Frame | ถ่ายโอนข้อมูลระหว่างโหนดใน Local Network เดียวกัน (Hop-to-Hop) อ้างอิงด้วย Physical Address (MAC Address), ทำ Media Access Control และ Error Detection (CRC/FCS) • มาตรฐาน: Ethernet (802.3), Wi-Fi (802.11), ARP, VLAN (802.1Q) |
| 1 | Physical | Bit (0s & 1s) | แปลงบิตดิจิทัลเป็นสัญญาณทางกายภาพ (ไฟฟ้า, แสง, คลื่นวิทยุ) และส่งผ่านตัวกลาง • ตัวอย่าง: สาย UTP/Cat6, Fiber Optic, ขั้วต่อ RJ-45, SFP+, คลื่น RF |
2. End-to-End Network Connection: User to Server Flow
สมมติสถานการณ์ผู้ใช้พิมพ์ [https://www.example.com](https://www.example.com) ใน Browser จนกระทั่งหน้าเว็บโหลดขึ้นมา
Step 1: Client IP Setup & Local Resolution (Application & Network Layer)
- เครื่อง Client ต้องมี IP Address, Subnet Mask, Default Gateway และ DNS Server (ได้มาจาก DHCP ผ่าน DORA Process: Discover, Offer, Request, Acknowledge)
Step 2: DNS Resolution (Name to IP)
- Browser ตรวจสอบ Local Cache (Browser cache -> OS DNS cache -> Hosts file)
- หากไม่พบ Client ส่ง DNS Query (UDP Port 53) ไปยัง Local DNS Resolver
- Local Resolver สอบถามตามลำดับชั้น: Root Server (.)$\rightarrow$TLD Server (.com)$\rightarrow$Authoritative Nameserver (example.com)
- Resolver ตอบ IP ปลายทาง (เช่น
93.184.216.34) กลับมาให้ Client
Step 3: Local Network Resolution via ARP (Data Link Layer)
- Client เช็ก Routing Table: Server IP ไม่อยู่ใน Local Subnet เดียวกัน จึงต้องส่งผ่าน Default Gateway (Router)
- Client ต้องการ MAC Address ของ Gateway:
- ค้นหาใน ARP Cache หากไม่พบจะส่ง ARP Request (Broadcast:
FF:FF:FF:FF:FF:FF) - Router ตอบ ARP Reply (Unicast) พร้อม MAC Address ของพอร์ต Router
- ค้นหาใน ARP Cache หากไม่พบจะส่ง ARP Request (Broadcast:
Step 4: Encapsulation at Client (L7 $\rightarrow$ L1)
- L7-L5: Browser สร้าง HTTP GET Request
- L4 (Transport): แนบ TCP Header ระบุ Source Port (Ephemeral เช่น
54321) และ Destination Port443 - L3 (Network): แนบ IP Header ระบุ Source IP (Client) และ Destination IP (Server)
- L2 (Data Link): แนบ Ethernet Frame Header ระบุ Source MAC (Client) และ Destination MAC (Gateway Router) + แนบ Frame Check Sequence (FCS) ที่ท้าย Frame
- L1 (Physical): แปลง Frame เป็นสัญญาณดิจิทัล/แสง ส่งผ่านสาย LAN หรือ Wi-Fi
Step 5: Routing & Traversing the Internet (Hop-by-Hop)
- Gateway Router ถอด Frame (Decapsulate L2) ตรวจสอบ Destination IP ใน Routing Table
- Router สลับแพ็กเก็ตผ่าน NAT (Network Address Translation) แปลง Private IP เป็น Public IP
- Encapsulate L2 Frame ใหม่ด้วย Next-Hop MAC Address
- Packet เดินทางผ่าน Core/Edge Routers ของ ISP หลายโหนด โดยใช้ Routing Protocol เช่น BGP และ OSPF จนถึง Edge Firewall / Load Balancer ของ Server
Step 6: TCP 3-Way Handshake (Transport Layer)
ก่อนส่ง Data ต้องสถาปนา TCP Connection:
- Client $\rightarrow$ Server: ส่ง
SYN(กำหนดค่า Initial Sequence Number: ISN เช่นseq=X) - Server $\rightarrow$ Client: ส่ง
SYN-ACK(seq=Y,ack=X+1) - Client $\rightarrow$ Server: ส่ง
ACK(seq=X+1,ack=Y+1)
Step 7: TLS Handshake (Presentation / Application Layer)
- ClientHello: เสนอ TLS Version, Cipher Suites ที่รองรับ และ Client Random
- ServerHello: Server เลือก Cipher Suite, ส่ง Digital Certificate (มี Public Key) และ Server Random
- Authentication & Key Exchange: Client ตรวจสอบใบรับรองผ่าน CA Root, ทั้งสองฝั่งทำการแลกเปลี่ยนคีย์ (เช่น ผ่าน ECDHE) เพื่อสร้าง Symmetric Session Key
- Finished: เริ่มส่งข้อมูลแบบเข้ารหัสด้วย Symmetric Key (AES-GCM / ChaCha20)
Step 8: HTTP Request, Response & Termination
- Client ส่ง
HTTP GET /ผ่าน TLS Tunnel - Web Server (Nginx / Apache) ประมวลผลและส่ง
HTTP 200 OKพร้อม Payload (HTML/CSS/JS) - เมื่อเสร็จสิ้น ทำการปิดการเชื่อมต่อด้วย TCP 4-Way Handshake:
- Client ส่ง
FIN$\rightarrow$ Server ตอบACK - Server ส่ง
FIN$\rightarrow$ Client ตอบACK(Client เข้าสู่สถานะTIME_WAITตามมาตรฐาน RFC เพื่อรอเก็บตก Packet ที่อาจตกค้าง)
- Client ส่ง
3. Deep Dive: Key TCP/IP Interview Topics
1. TCP vs. UDP
- TCP: Connection-oriented, Reliable (มี Retransmission เมื่อ Packet สูญหาย), Ordered Delivery, Flow Control (Sliding Window), Congestion Control (Slow Start, Congestion Avoidance)
- UDP: Connectionless, Unreliable, ไม่มี Overhead เหมาะกับ VoIP, Streaming, DNS Query, Video Gaming, QUIC (HTTP/3)
2. TCP Flow Control vs. Congestion Control
- Flow Control (End-to-End): ป้องกันไม่ให้ Sender ส่งข้อมูลเร็วเกินกว่าที่ Receiver จะประมวลผลทัน ควบคุมด้วย Receiver Window (rwnd) ที่ Receiver ส่งกลับมาแจ้งใน TCP Header
- Congestion Control (Network-wide): ป้องกันไม่ให้ Sender ส่งข้อมูลจนเกิดความแออัดในระบบเครือข่าย ควบคุมด้วย Congestion Window (cwnd) ของฝั่ง Sender ผ่านอัลกอริทึม เช่น CUBIC, BBR, Reno
3. TCP Flags ที่พบบ่อย
SYN(Synchronize): เริ่มต้นสถาปนา ConnectionACK(Acknowledgment): ยืนยันการรับ Data/PacketFIN(Finish): ปิดการเชื่อมต่ออย่างปกติRST(Reset): ปิดการเชื่อมต่อทันที (มักเกิดจาก Port ปิดอยู่ หรือ Session ผิดปกติ)PSH(Push): แจ้งให้ Buffer ส่งข้อมูลให้ Application ทันที ไม่ต้องรอ Buffer เต็มURG(Urgent): ข้อมูลเร่งด่วนที่ต้องประมวลผลก่อน
4. TCP Header Breakdown
- มีขนาดมาตรฐาน 20 Bytes (หากไม่มี Options) ประกอบด้วย:
- Source Port (16 bits) / Destination Port (16 bits)
- Sequence Number (32 bits) / Acknowledgment Number (32 bits)
- Data Offset (4 bits) / Reserved (3 bits) / Control Flags (9 bits)
- Window Size (16 bits) / Checksum (16 bits) / Urgent Pointer (16 bits)
ต้องการให้ลาเต้เจาะลึกเพิ่มในส่วนของ Troubleshooting Tools (เช่น tcpdump, wireshark, netstat/ss, MTU/MSS issues) หรือเน้นจำลองคำถามตอบ (Mock Q&A) ของ TCP/IP รูปแบบไหนเพิ่มเติมไหมคะ?