TCP vs UDP: reliable vs best effort
Builds on transport layer basics.
The core split
- TCP: reliable, connection-oriented, sequenced. Typical uses: email, FTP, web, downloads.
- UDP: best effort, connectionless, no sequencing (the app handles it). Typical uses: voice streaming, DHCP, TFTP, DNS.
For TCP traffic, missing pieces corrupt the data: a downloaded binary with one lost packet won’t run. Worth the overhead.
For UDP traffic, a dropped VoIP segment is a blip the listener may not even hear, and retransmitting it later would be worse. UDP also wins for query/response transactions (DNS, DHCP): no answer, just ask again. Cheaper than building a TCP session for one exchange.
UDP keeps no state about sent data. No handshake, no teardown.
Three-way handshake
Like a phone call: ring, “hello,” “hello” back.
- Source sends SYN with its initial sequence number (SN).
- Destination replies SYN-ACK, ack = initiator’s SN + 1.
- Source sends ACK. Session open.
Sequence and acknowledgment numbers
Every transmitted byte is tracked with a 32-bit sequence number. The receiver acks with the next sequence number it expects: gaps expose lost data, and the same numbers catch duplicates and reordering.
During the handshake, ack = seq + 1. After that, numbers accumulate per byte sent, and both sides keep their own independent sequence numbers.
Worked example, HTTP GETs between hosts A and B:
Pkt Sender Seq Ack Payload
4 A 1 200 B (GET)
5 B 1 201 300 B
6 A 201 301 400 B (GET)
7 B 301 601 800 BIn packet 5, B still sends seq 1 (it hasn’t sent data yet) but acks A’s 200 bytes with ack 201. In packet 6, A’s seq is 201 (its first 200 bytes are acknowledged), and 201 + 400 means A’s next seq will be 601. In packet 7, B acks 601, and after its 800 bytes B’s next seq will be 1101.
What makes TCP reliable
- Connection setup confirms the receiver is ready and negotiates starting parameters before any data moves.
- One full-duplex session, data flowing both directions at once, sometimes called a virtual circuit since the endpoints never see the network in between.
- Numbered segments, so the receiver can reorder and spot holes.
- No ack within the timeout means retransmit. No receiver at all means tear the session down.
- A checksum guards the segment against corruption.
- Flow control tunes the send rate to what the session can handle.
The certified mail analogy again: numbered envelopes, a signed receipt per envelope, resend anything with no receipt. UDP is dropping a bill payment in the mailbox and trusting the postal service.
TCP header fields
Minimum 20 bytes. Segments ride inside IP packets, the TCP header right after the IP header.
- Source port, 16 bits: sending application.
- Destination port, 16 bits: target application.
- Sequence number, 32 bits: byte tracking.
- Acknowledgment number, 32 bits: next expected byte.
- Header length, 4 bits: size of this header.
- Reserved, 3 bits: future use.
- Flags, 9 bits: the control bits, below.
- Window size, 16 bits: flow control.
- Checksum, 16 bits: error check over pseudo header + segment.
- Urgent pointer, 16 bits: offset to the last urgent byte when URG is set.
- Options, 0-320 bits: length set by the header length field.
The flags: SYN (sync sequence numbers), ACK, FIN (sender done), RST (reset the connection), PSH (deliver to the app immediately), URG (priority data), plus three congestion-related bits: ECE (congestion seen), CWR (congestion echo acknowledged), NS (experimental, lets the receiver prove its acks). The exam cares about SYN, ACK, FIN, RST, PSH, and URG.
The checksum’s pseudo header pulls in source and destination IPs and protocol from the IP header, so a misdelivered segment fails the check.
UDP characteristics
Same layer as TCP (OSI Layer 4), same job of handing app data to the internet layer, minus every reliability mechanism.
- Connectionless: fires a one-way datagram at the destination with no advance warning.
- Best effort only. Datagrams can be lost, duplicated, or misdirected and UDP won’t notice. Recovery, if any, is the application’s problem.
- Error checking stops at a checksum for integrity testing. Nothing recovers a corrupt datagram.
The payoff is low overhead and low latency, which is why request/response protocols like DNS and NTP ride on it.
UDP header fields
8 bytes total, versus TCP’s 20-byte minimum: source port, destination port, length (header + data), and checksum, 16 bits each.
Application protocols on UDP: DNS, SNMP, DHCP, RIP, TFTP, NFS, online games, voice streaming.