Fundamentals 27 min read

TCP Explained in 28 Diagrams: Handshakes, Congestion Control & Reliable Transmission

This article uses 28 diagrams to comprehensively explain TCP, covering network layering, TCP header structure, byte-stream orientation, reliable transmission mechanisms (sliding window, ARQ, acknowledgments), congestion control algorithms (slow start, congestion avoidance, fast retransmit/recovery), three-way handshake and four-way termination, UDP comparison, and practical issues like packet fragmentation, sticky packets, and SYN flood attacks.

Linux Tech Enthusiast
Linux Tech Enthusiast
Linux Tech Enthusiast
TCP Explained in 28 Diagrams: Handshakes, Congestion Control & Reliable Transmission

Network Layering Foundation

The article begins by building the network stack from the ground up. The physical layer defines hardware interfaces (cables, voltages, frequencies). The data link layer uses MAC addresses for LAN communication via switches. The network layer introduces IP addresses for logical host-to-host communication across routers, enabling internetwork routing. The transport layer adds ports (sockets) to distinguish processes on the same host, providing process-to-process logical communication. Finally, the application layer implements specific protocols like HTTP and FTP. This five-layer model mirrors the responsibility-chain design pattern, encapsulating lower-layer details.

Transport Layer Essentials

Transport layer performs multiplexing (gathering data from multiple processes) and demultiplexing (delivering incoming segments to correct sockets). A socket is an abstract endpoint identified by IP:port (UDP) or srcIP:srcPort:dstIP:dstPort (TCP). The two main protocols are UDP (minimal, unreliable) and TCP (reliable, connection-oriented, with flow/congestion control).

TCP Header Structure

The TCP header is 20 bytes fixed plus up to 40 bytes of options. Key fields include source/destination port, sequence number, acknowledgment number, header length, flags (SYN, ACK, FIN, RST, PSH, URG), window size, checksum, urgent pointer, and options (MSS, window scaling, SACK permitted, timestamps). The article provides reference tables for all fields and options.

Byte-Stream Orientation

TCP treats application data as a continuous byte stream. It reads bytes into a send buffer, assigns sequence numbers, segments them into packets, and reassembles at the receiver's buffer. This avoids large memory copies but causes sticky packet and packet splitting issues, which the application must handle (e.g., delimiters, length prefixes).

Reliable Transmission Mechanisms

Stop-and-Wait & Timeout Retransmission

Simplest reliable method: send one segment, wait for ACK. To handle loss, sender starts a timer on each send; timeout triggers retransmission. Sequence numbers distinguish new data from retransmissions.

Continuous ARQ & Sliding Window

Stop-and-wait is inefficient. Continuous ARQ pipelines multiple segments. The sliding window limits outstanding bytes based on receiver's advertised window (flow control). The window slides forward as ACKs arrive.

Acknowledgment Strategies

Cumulative ACK : Receiver acknowledges up to the last in-order byte (e.g., ACK 4 implies 1-3 received).

Selective ACK (SACK) : Optionally reports non-contiguous blocks received, allowing sender to retransmit only missing segments (avoiding Go-Back-N waste).

Congestion Control

Prevents network collapse by limiting sender's window based on inferred congestion. Four core algorithms:

Slow Start : Window starts at 1 MSS, doubles each RTT until ssthresh.

Congestion Avoidance : After ssthresh, window increases by 1 MSS per RTT (additive increase).

Fast Retransmit : On three duplicate ACKs, retransmit missing segment immediately (without waiting for timeout).

Fast Recovery : After fast retransmit, set ssthresh = cwnd/2, set cwnd = ssthresh + 3 MSS, then enter congestion avoidance.

Timeout resets to slow start with ssthresh = cwnd/2. Window also bounded by receiver's advertised window. Active Queue Management (AQM) like RED can signal congestion earlier.

Connection Management

Three-Way Handshake

Client sends SYN (seq=x), enters SYN_SENT.

Server replies SYN+ACK (seq=y, ack=x+1), enters SYN_RCVD.

Client sends ACK (ack=y+1), both enter ESTABLISHED.

SYN carries initial sequence number and options (MSS, window scale, SACK permitted). The handshake exchanges buffer sizes and capabilities.

Four-Way Termination

Active closer sends FIN, enters FIN_WAIT_1.

Passive closer ACKs, enters CLOSE_WAIT (may still send data).

Passive closer sends FIN, enters LAST_ACK.

Active closer ACKs, enters TIME_WAIT for 2×MSL (maximum segment lifetime) to handle delayed/retransmitted FINs, then CLOSED.

TIME_WAIT ensures reliable termination and prevents old segments from confusing new connections.

UDP Protocol

UDP header: source/destination port, length, checksum (8 bytes). No connection, no reliability, no flow/congestion control. Advantages: lower latency, no connection overhead, supports broadcast/multicast, smaller header. Used for DNS, RIP, live streaming where occasional loss is acceptable.

Supplementary Topics

Packet Fragmentation

Transport layer segments data to fit path MTU (typically 1500 bytes Ethernet, 1460 bytes TCP payload). Too large → fragmentation/reassembly overhead; too small → header overhead dominates.

Routing

Routers provide multiple paths, improving fault tolerance and load balancing. Core router failure can partition network.

Sticky Packets & Splitting

Caused by TCP's byte-stream nature. Application must frame messages (delimiters, length fields, fixed-size records).

SYN Flood Attack

Attacker sends spoofed SYNs, server allocates half-open connection state (SYN_RCVD), exhausting resources. Mitigations: SYN cookies, rate limiting, deferred buffer allocation.

Long Connections

Reuse TCP connection for multiple requests (HTTP keep-alive). Reduces handshake overhead but consumes server resources; requires idle timeouts and limits.

The article concludes that deep understanding of these fundamentals pays off when debugging real-world network issues or designing high-performance systems.

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

TCPnetworkingfour-way handshakethree-way handshakesliding windowcongestion controlUDPtransport layerSYN floodreliable transmission
Linux Tech Enthusiast
Written by

Linux Tech Enthusiast

Focused on sharing practical Linux technology content, covering Linux fundamentals, applications, tools, as well as databases, operating systems, network security, and other technical knowledge.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.