Course menu

Course 9: OSPFLesson 1.3 (3 of 9 in this course)72 of 107 in the CCNA series

How does OSPF work?

The four jobs OSPF does: meet neighbours, share LSAs, build an identical link-state database, and run SPF to choose the best paths.

Intermediate · 13 min read

What you will learn

After this lesson, you can list the five steps OSPF goes through, say which packet and which table belong to each step, and explain what happens, step by step, when a link fails.

  • LSAs and the LSDB
  • SPF (Dijkstra)
  • Reconvergence

OSPF operation is the sequence every OSPF router follows: start the process with a unique router ID, form neighbour adjacencies with hellos, synchronise the link-state database with DBD, LSR, LSU and LSAck packets, run the SPF algorithm on that database, and install the resulting best paths in the routing table. After a change, the router floods a new LSA and steps 3 to 5 repeat.

In simple terms: Switch it on, meet the neighbours, swap maps, work out the best routes, use them. When something changes, update the map and work the routes out again.

A real-life situation

You have just cabled the four routers of the square network and typed a few OSPF commands on each. Thirty seconds later, every router can reach both LANs, and if you pull a cable the traffic moves to the other path. Between your last command and that working network, each router went through the same five steps. This lesson walks through them in order, so that when OSPF doesn't work you know which step to check.

The five steps at a glance

  1. 1Start the processEnable OSPF, choose a router ID, and pick the interfaces that take part.
  2. 2Find neighboursSend hellos on those interfaces and agree with the routers that answer.
  3. 3Share the mapExchange LSAs until every router in the area holds the same LSDB.
  4. 4Run SPFCalculate the lowest-cost path from this router to every network.
  5. 5Fill the routing tableInstall the best paths and start forwarding packets with them.

Step 1: start the process

Which OSPF version?

VersionStandardRoutesStarted with
OSPFv1RFC 1131 (1989)Experimental onlyNot used
OSPFv2RFC 2328IPv4router ospf 1
OSPFv3RFC 5340IPv6 (and IPv4 with address families)router ospfv3 1

This course is about OSPFv2, the version the CCNA has you configure.

Process ID and router ID

router ospf 1 starts process 1. The number is local to the router (1 to 65535), so neighbours don't need to match, although most networks use the same number everywhere to keep things tidy. The process then needs a unique router ID, chosen as described in What is OSPF?; set it explicitly with router-id.

Which interfaces take part

Starting the process doesn't enable OSPF on any interface. You choose them, usually with the network command:

network <ip-address> <wildcard-mask> area <area-id>

Router configuration mode. Every interface whose IP address matches the address and wildcard joins OSPF in that area.

The wildcard mask works like an inverted subnet mask: a 0 bit means "this bit must match" and a 1 bit means "any value". A matching interface gets two things: it starts sending hellos, and its subnet is advertised in the router's LSA. On R1 in the square network:

router ospf 1 router-id 1.1.1.1 network 192.168.1.0 0.0.0.255 area 0 network 10.0.12.0 0.0.0.3 area 0 network 10.0.13.0 0.0.0.3 area 0

Gi0/0 (192.168.1.1), Gi0/1 (10.0.12.1) and Gi0/2 (10.0.13.1) each match one line, so all three join area 0.

network commandMatches interfaces with addresses…
network 10.0.12.1 0.0.0.0 area 0exactly 10.0.12.1 (one interface)
network 10.0.12.0 0.0.0.3 area 010.0.12.0 to 10.0.12.3
network 192.168.1.0 0.0.0.255 area 0192.168.1.0 to 192.168.1.255
network 10.0.0.0 0.255.255.255 area 0anything starting with 10.
network 0.0.0.0 255.255.255.255 area 0every interface

The other way is to enable OSPF on the interface itself, which some engineers prefer because it leaves no doubt about which interfaces are in:

interface GigabitEthernet0/1 ip ospf 1 area 0

Interface configuration mode. Enables OSPF process 1 in area 0 on this interface only.

Either way, an interface that doesn't match sends no hellos and its subnet is not advertised: the rest of the network simply won't know that subnet exists.

Step 2: find neighbours

Each OSPF interface now sends a hello every 10 seconds (on Ethernet) to 224.0.0.5. Two routers on the same link become neighbours once each sees its own router ID listed in the other's hello, and only if settings such as the area, subnet and timers match. Then they synchronise their databases. Here is the whole conversation between R1 and R2:

R1RID 1.1.1.1
R2RID 2.2.2.2
  1. DownNothing heard yet. Both start sending hellos to 224.0.0.5 every 10 seconds.
  2. I'm 1.1.1.1, area 0, timers 10/40. I haven't heard any neighbours yet.Hello from R1 to R2.Hello
  3. InitR2 has heard R1, but R1 hasn't heard R2 yet.
  4. HelloI'm 2.2.2.2, same area and timers, and I can hear 1.1.1.1.Hello from R2 to R1.
  5. I can hear 2.2.2.2 too.Hello from R1 to R2.Hello
  6. 2-WayEach router sees its own ID in the other's hello: they are neighbours.
  7. Time to synchronise. I'm 1.1.1.1 and I'll lead.DBD from R1 to R2.DBD
  8. DBDNo, my router ID 2.2.2.2 is higher, so I lead.DBD from R2 to R1.
  9. ExStart → ExchangeR2 leads; the DBDs now carry lists of LSA headers.
  10. DBDHere is the list of LSAs I have.DBD from R2 to R1.
  11. And here is mine.DBD from R1 to R2.DBD
  12. LoadingEach router asks only for the LSAs it is missing.
  13. Please send the full LSAs from 3.3.3.3 and 4.4.4.4.LSR from R1 to R2.LSR
  14. LSUHere they are.LSU from R2 to R1.
  15. Got them, thanks.LSAck from R1 to R2.LSAck
  16. FullIdentical LSDBs. From now on: hellos every 10 s, and LSUs only when something changes.
R1 and R2 on 10.0.12.0/30, from the first hello to a Full adjacency. Each envelope is drawn at the router that receives it.

The neighbour states at a glance

StateWhat it meansPackets
DownNothing heard from this neighbour (yet, or for a full dead interval).Hellos sent, none received
AttemptOnly on non-broadcast (NBMA) networks, where neighbours are configured by hand and polled with unicast hellos. Not seen on Ethernet.Unicast hellos
InitA hello arrived, but it doesn't list this router yet: one-way only.Hello
2-WayEach router sees itself in the other's hello: they are neighbours. On Ethernet the DR and BDR are elected here, and two DROthers stay at 2-Way on purpose.Hello
ExStartThe two agree who leads the database exchange (the higher router ID).Empty DBDs
ExchangeThey swap lists of the LSAs they hold.DBDs with LSA headers
LoadingEach asks for the LSAs it is missing and receives them.LSR, LSU, LSAck
FullThe LSDBs match: the routers are adjacent.Hellos to stay alive; LSUs when something changes

Where two routers get stuck tells you what to check. A neighbour that never appears, or stays in Init, points at the hello settings (area, subnet, timers, authentication). Stuck in ExStart or Exchange points at an MTU mismatch or a duplicate router ID. The full checklist is in the neighbours lesson.

On a shared Ethernet segment with several routers, routers don't form a full adjacency with every other router; a designated router (DR) is elected to keep things efficient. The states, the matching rules and the DR are covered in depth in OSPF neighbours and adjacencies and DR/BDR election.

The five OSPF packet types

OSPF runs directly on IP (protocol number 89), not on TCP or UDP, and uses five packet types:

TypePacketJobUsed in step
1HelloFind neighbours, check settings match, keep neighbours alive2
2DBD (database description)List the LSAs a router has, without their contents2–3
3LSR (link-state request)Ask for specific LSAs3
4LSU (link-state update)Carry full LSAs, both on request and when flooding a change3
5LSAckConfirm LSAs arrived, which makes flooding reliable3

Step 3: share the map (the LSDB)

Once neighbours are Full, any new or changed LSA is flooded: sent in an LSU to every neighbour, acknowledged, and passed on until every router in the area has it. Every router stores every LSA in its LSDB, so all routers in the area hold the same map. You can see it with show ip ospf database: one router LSA per router, the same list on every router.

Four routers, four router LSAs. Seq# rises each time a router sends a new version of its LSA, which is how routers tell new information from old. The output is trimmed: on Ethernet links you also see network LSAs from the DRs.
R1#show ip ospf database
            OSPF Router with ID (1.1.1.1) (Process ID 1)

                Router Link States (Area 0)

Link ID         ADV Router      Age         Seq#       Checksum Link count
1.1.1.1         1.1.1.1         412         0x80000004 0x00A1C3 3
2.2.2.2         2.2.2.2         409         0x80000003 0x0062F1 2
3.3.3.3         3.3.3.3         405         0x80000003 0x00B804 2
4.4.4.4         4.4.4.4         398         0x80000004 0x0024D9 3

LSAs are refreshed every 30 minutes even when nothing changes, and an LSA that isn't refreshed for an hour is removed. That way a router that has vanished can't leave stale information behind for ever.

Step 4: run SPF

The LSDB is a map, not a list of directions. Think of a sat-nav: every car has the same map, but each one plans its journey from where it is. Each router runs SPF (Dijkstra's algorithm) with itself as the starting point and finds the cheapest path to every network, adding the cost of each outgoing interface on the way. With the R1–R3 link at cost 10 and every other link at cost 1:

Gi0/0Gi0/1Gi0/0cost 1Gi0/2Gi0/0cost 10Gi0/1Gi0/1cost 1Gi0/1Gi0/2cost 1Gi0/0LAN A192.168.1.0/24R1RID 1.1.1.1R2RID 2.2.2.2R3RID 3.3.3.3R4RID 4.4.4.4LAN B192.168.4.0/24
  1. 1. From R1: Through R2 costs 1 + 1 + 1 = 3; through R3 would cost 10 + 1 + 1 = 12. R1 chooses R2.
  2. 2. From R3: Straight to R4 costs 1 + 1 = 2. R3's best path doesn't go near R1 or R2.
  3. 3. R3 to LAN A avoids its own slow link: Direct to R1 costs 10 + 1 = 11; round through R4 and R2 costs 1 + 1 + 1 + 1 = 4. The longer way round is the cheaper one.

The result for R1 is its SPF tree, summarised here:

DestinationBest path from R1Total costNext hop
10.0.24.0/30R1 → R2210.0.12.2 (R2)
10.0.34.0/30R1 → R2 → R4310.0.12.2 (R2)
192.168.4.0/24R1 → R2 → R4310.0.12.2 (R2)

10.0.34.0/30 (the R3–R4 link) is reached through R4 at cost 3 rather than through R3 at cost 11, because the R1–R3 link is expensive.

Step 5: fill the routing table

The best path to each network is installed in the routing table, marked O, with administrative distance 110 and the total cost as the metric. From now on the router forwards packets using these routes; OSPF itself isn't involved in forwarding each packet.

Exactly the SPF table above. 10.0.12.0/30, 10.0.13.0/30 and LAN A are connected routes on R1, so they don't appear as OSPF routes.
R1#show ip route ospf
      10.0.0.0/8 is variably subnetted, 7 subnets, 2 masks
O        10.0.24.0/30 [110/2] via 10.0.12.2, 00:05:41, GigabitEthernet0/1
O        10.0.34.0/30 [110/3] via 10.0.12.2, 00:05:41, GigabitEthernet0/1
O     192.168.4.0/24 [110/3] via 10.0.12.2, 00:05:41, GigabitEthernet0/1

When something changes

The five steps aren't a one-off. When the R2–R4 link fails:

  1. R2 and R4 notice at once because their interfaces go down (a silent failure is noticed when the 40-second dead timer runs out).
  2. Each sends a new version of its router LSA, without that link, in an LSU to its remaining neighbours (step 3).
  3. The new LSAs are flooded and acknowledged until every LSDB is updated.
  4. Every router reruns SPF on the new map (step 4).
  5. R1 replaces its routes through R2 with routes through R3, at the higher cost (step 5).

Only the changes are sent, so reconvergence takes well under a second in a network this size, compared with the minutes an engineer would need to fix static routes.

Why one area works only up to a point

Every change is flooded to every router in the area and makes all of them rerun SPF, and every router stores the whole map. With a few dozen routers that is nothing for modern hardware. With hundreds of routers and links that flap, it adds up, which is why large networks are split into several areas, each with its own smaller LSDB. For the CCNA, a single area 0 is all you configure.

Common mistakes

  • Using a subnet mask instead of a wildcard mask in the network command (0.0.0.255, not 255.255.255.0).
  • Forgetting a network command for a LAN: the routers become neighbours but nobody learns that LAN.
  • Thinking the network command advertises exactly the range typed. It selects interfaces; each interface's own subnet is advertised.
  • Expecting OSPF to resend everything periodically. It sends changes, plus a 30-minute refresh.
  • Forgetting that each router runs SPF itself: a wrong cost on one router changes paths through that router.

💡 Exam tip: match each packet to its job (Hello, DBD, LSR, LSU, LSAck) and each step to its show command: show ip protocols (step 1), show ip ospf neighbor (step 2), show ip ospf database (step 3), show ip route ospf (step 5). Expect a network command question: which interfaces does network 10.1.0.0 0.0.255.255 area 0 enable?

Key takeaways

✅ Key takeaways
  • Five steps: start the process, find neighbours, share LSAs into the LSDB, run SPF, fill the routing table.
  • OSPFv2 routes IPv4 and is started with router ospf; the process ID is local, the router ID must be unique.
  • The network command (address + wildcard + area) selects interfaces; matching interfaces send hellos and have their subnets advertised.
  • Hello, DBD, LSR, LSU and LSAck take two routers from strangers to Full, with identical LSDBs.
  • Every router runs SPF from its own position; the best paths go into the routing table as O routes.
  • A change triggers new LSAs, flooding, SPF and new routes: that is OSPF convergence.

Check yourself

Predict · scenario 1

R1 has interfaces 10.1.5.1, 10.1.200.1 and 10.2.0.1. Which of them does network 10.1.0.0 0.0.255.255 area 0 enable?

Predict · scenario 2

During the database exchange, R1 sees an LSA listed in R2's DBD that it doesn't have. What does R1 send next?

Predict · scenario 3

A LAN interface on R4 is not matched by any network command. What happens?

Predict · scenario 4

All routers in the area have the same LSDB. Which step makes R1 and R3 install different next hops for LAN B?

Predict · scenario 5

The R2–R4 link fails. Put R1's experience in the right order.

FAQ

Does OSPF send its whole database every few minutes?
No. After the first synchronisation, routers send only changes, plus a refresh of each LSA every 30 minutes so that old information eventually ages out. Hellos (every 10 seconds on Ethernet) only keep neighbours alive; they don't carry routes.
Do I configure OSPFv2 or OSPFv3 for the CCNA?
OSPFv2 (router ospf) for IPv4 is what the CCNA 200-301 blueprint asks you to configure and verify. OSPFv3 works on the same principles for IPv6 and is not a configuration topic in the CCNA.
Is it the network command or the interface command that I should use?
Either works and the result is the same for the CCNA. The network command matches interfaces by address range; ip ospf <process> area <area> under an interface enables that one interface directly. Many engineers prefer the interface command because it is explicit.