A real-life situation
You have just cabled the four routers of the square network and typed a few OSPF commands on each. Thirty seconds later, every router can reach both LANs, and if you pull a cable the traffic moves to the other path. Between your last command and that working network, each router went through the same five steps. This lesson walks through them in order, so that when OSPF doesn't work you know which step to check.
The five steps at a glance
- 1Start the processEnable OSPF, choose a router ID, and pick the interfaces that take part.
- 2Find neighboursSend hellos on those interfaces and agree with the routers that answer.
- 3Share the mapExchange LSAs until every router in the area holds the same LSDB.
- 4Run SPFCalculate the lowest-cost path from this router to every network.
- 5Fill the routing tableInstall the best paths and start forwarding packets with them.
Step 1: start the process
Which OSPF version?
| Version | Standard | Routes | Started with |
|---|---|---|---|
| OSPFv1 | RFC 1131 (1989) | Experimental only | Not used |
| OSPFv2 | RFC 2328 | IPv4 | router ospf 1 |
| OSPFv3 | RFC 5340 | IPv6 (and IPv4 with address families) | router ospfv3 1 |
This course is about OSPFv2, the version the CCNA has you configure.
Process ID and router ID
router ospf 1 starts process 1. The number is local to the router (1 to 65535), so neighbours don't need to match, although most networks use the same number everywhere to keep things tidy. The process then needs a unique router ID, chosen as described in What is OSPF?; set it explicitly with router-id.
Which interfaces take part
Starting the process doesn't enable OSPF on any interface. You choose them, usually with the network command:
network <ip-address> <wildcard-mask> area <area-id>Router configuration mode. Every interface whose IP address matches the address and wildcard joins OSPF in that area.
The wildcard mask works like an inverted subnet mask: a 0 bit means "this bit must match" and a 1 bit means "any value". A matching interface gets two things: it starts sending hellos, and its subnet is advertised in the router's LSA. On R1 in the square network:
router ospf 1
router-id 1.1.1.1
network 192.168.1.0 0.0.0.255 area 0
network 10.0.12.0 0.0.0.3 area 0
network 10.0.13.0 0.0.0.3 area 0Gi0/0 (192.168.1.1), Gi0/1 (10.0.12.1) and Gi0/2 (10.0.13.1) each match one line, so all three join area 0.
| network command | Matches interfaces with addresses… |
|---|---|
network 10.0.12.1 0.0.0.0 area 0 | exactly 10.0.12.1 (one interface) |
network 10.0.12.0 0.0.0.3 area 0 | 10.0.12.0 to 10.0.12.3 |
network 192.168.1.0 0.0.0.255 area 0 | 192.168.1.0 to 192.168.1.255 |
network 10.0.0.0 0.255.255.255 area 0 | anything starting with 10. |
network 0.0.0.0 255.255.255.255 area 0 | every interface |
The other way is to enable OSPF on the interface itself, which some engineers prefer because it leaves no doubt about which interfaces are in:
interface GigabitEthernet0/1
ip ospf 1 area 0Interface configuration mode. Enables OSPF process 1 in area 0 on this interface only.
Either way, an interface that doesn't match sends no hellos and its subnet is not advertised: the rest of the network simply won't know that subnet exists.
Step 2: find neighbours
Each OSPF interface now sends a hello every 10 seconds (on Ethernet) to 224.0.0.5. Two routers on the same link become neighbours once each sees its own router ID listed in the other's hello, and only if settings such as the area, subnet and timers match. Then they synchronise their databases. Here is the whole conversation between R1 and R2:
- DownNothing heard yet. Both start sending hellos to 224.0.0.5 every 10 seconds.
- I'm 1.1.1.1, area 0, timers 10/40. I haven't heard any neighbours yet.Hello from R1 to R2.Hello
- InitR2 has heard R1, but R1 hasn't heard R2 yet.
- HelloI'm 2.2.2.2, same area and timers, and I can hear 1.1.1.1.Hello from R2 to R1.
- I can hear 2.2.2.2 too.Hello from R1 to R2.Hello
- 2-WayEach router sees its own ID in the other's hello: they are neighbours.
- Time to synchronise. I'm 1.1.1.1 and I'll lead.DBD from R1 to R2.DBD
- DBDNo, my router ID 2.2.2.2 is higher, so I lead.DBD from R2 to R1.
- ExStart → ExchangeR2 leads; the DBDs now carry lists of LSA headers.
- DBDHere is the list of LSAs I have.DBD from R2 to R1.
- And here is mine.DBD from R1 to R2.DBD
- LoadingEach router asks only for the LSAs it is missing.
- Please send the full LSAs from 3.3.3.3 and 4.4.4.4.LSR from R1 to R2.LSR
- LSUHere they are.LSU from R2 to R1.
- Got them, thanks.LSAck from R1 to R2.LSAck
- FullIdentical LSDBs. From now on: hellos every 10 s, and LSUs only when something changes.
The neighbour states at a glance
| State | What it means | Packets |
|---|---|---|
| Down | Nothing heard from this neighbour (yet, or for a full dead interval). | Hellos sent, none received |
| Attempt | Only on non-broadcast (NBMA) networks, where neighbours are configured by hand and polled with unicast hellos. Not seen on Ethernet. | Unicast hellos |
| Init | A hello arrived, but it doesn't list this router yet: one-way only. | Hello |
| 2-Way | Each router sees itself in the other's hello: they are neighbours. On Ethernet the DR and BDR are elected here, and two DROthers stay at 2-Way on purpose. | Hello |
| ExStart | The two agree who leads the database exchange (the higher router ID). | Empty DBDs |
| Exchange | They swap lists of the LSAs they hold. | DBDs with LSA headers |
| Loading | Each asks for the LSAs it is missing and receives them. | LSR, LSU, LSAck |
| Full | The LSDBs match: the routers are adjacent. | Hellos to stay alive; LSUs when something changes |
Where two routers get stuck tells you what to check. A neighbour that never appears, or stays in Init, points at the hello settings (area, subnet, timers, authentication). Stuck in ExStart or Exchange points at an MTU mismatch or a duplicate router ID. The full checklist is in the neighbours lesson.
On a shared Ethernet segment with several routers, routers don't form a full adjacency with every other router; a designated router (DR) is elected to keep things efficient. The states, the matching rules and the DR are covered in depth in OSPF neighbours and adjacencies and DR/BDR election.
The five OSPF packet types
OSPF runs directly on IP (protocol number 89), not on TCP or UDP, and uses five packet types:
| Type | Packet | Job | Used in step |
|---|---|---|---|
| 1 | Hello | Find neighbours, check settings match, keep neighbours alive | 2 |
| 2 | DBD (database description) | List the LSAs a router has, without their contents | 2–3 |
| 3 | LSR (link-state request) | Ask for specific LSAs | 3 |
| 4 | LSU (link-state update) | Carry full LSAs, both on request and when flooding a change | 3 |
| 5 | LSAck | Confirm LSAs arrived, which makes flooding reliable | 3 |
Step 3: share the map (the LSDB)
Once neighbours are Full, any new or changed LSA is flooded: sent in an LSU to every neighbour, acknowledged, and passed on until every router in the area has it. Every router stores every LSA in its LSDB, so all routers in the area hold the same map. You can see it with show ip ospf database: one router LSA per router, the same list on every router.
R1#show ip ospf database OSPF Router with ID (1.1.1.1) (Process ID 1) Router Link States (Area 0) Link ID ADV Router Age Seq# Checksum Link count 1.1.1.1 1.1.1.1 412 0x80000004 0x00A1C3 3 2.2.2.2 2.2.2.2 409 0x80000003 0x0062F1 2 3.3.3.3 3.3.3.3 405 0x80000003 0x00B804 2 4.4.4.4 4.4.4.4 398 0x80000004 0x0024D9 3
LSAs are refreshed every 30 minutes even when nothing changes, and an LSA that isn't refreshed for an hour is removed. That way a router that has vanished can't leave stale information behind for ever.
Step 4: run SPF
The LSDB is a map, not a list of directions. Think of a sat-nav: every car has the same map, but each one plans its journey from where it is. Each router runs SPF (Dijkstra's algorithm) with itself as the starting point and finds the cheapest path to every network, adding the cost of each outgoing interface on the way. With the R1–R3 link at cost 10 and every other link at cost 1:
- 1. From R1: Through R2 costs 1 + 1 + 1 = 3; through R3 would cost 10 + 1 + 1 = 12. R1 chooses R2.
- 2. From R3: Straight to R4 costs 1 + 1 = 2. R3's best path doesn't go near R1 or R2.
- 3. R3 to LAN A avoids its own slow link: Direct to R1 costs 10 + 1 = 11; round through R4 and R2 costs 1 + 1 + 1 + 1 = 4. The longer way round is the cheaper one.
The result for R1 is its SPF tree, summarised here:
| Destination | Best path from R1 | Total cost | Next hop |
|---|---|---|---|
| 10.0.24.0/30 | R1 → R2 | 2 | 10.0.12.2 (R2) |
| 10.0.34.0/30 | R1 → R2 → R4 | 3 | 10.0.12.2 (R2) |
| 192.168.4.0/24 | R1 → R2 → R4 | 3 | 10.0.12.2 (R2) |
10.0.34.0/30 (the R3–R4 link) is reached through R4 at cost 3 rather than through R3 at cost 11, because the R1–R3 link is expensive.
Step 5: fill the routing table
The best path to each network is installed in the routing table, marked O, with administrative distance 110 and the total cost as the metric. From now on the router forwards packets using these routes; OSPF itself isn't involved in forwarding each packet.
R1#show ip route ospf 10.0.0.0/8 is variably subnetted, 7 subnets, 2 masks O 10.0.24.0/30 [110/2] via 10.0.12.2, 00:05:41, GigabitEthernet0/1 O 10.0.34.0/30 [110/3] via 10.0.12.2, 00:05:41, GigabitEthernet0/1 O 192.168.4.0/24 [110/3] via 10.0.12.2, 00:05:41, GigabitEthernet0/1
When something changes
The five steps aren't a one-off. When the R2–R4 link fails:
- R2 and R4 notice at once because their interfaces go down (a silent failure is noticed when the 40-second dead timer runs out).
- Each sends a new version of its router LSA, without that link, in an LSU to its remaining neighbours (step 3).
- The new LSAs are flooded and acknowledged until every LSDB is updated.
- Every router reruns SPF on the new map (step 4).
- R1 replaces its routes through R2 with routes through R3, at the higher cost (step 5).
Only the changes are sent, so reconvergence takes well under a second in a network this size, compared with the minutes an engineer would need to fix static routes.
Why one area works only up to a point
Every change is flooded to every router in the area and makes all of them rerun SPF, and every router stores the whole map. With a few dozen routers that is nothing for modern hardware. With hundreds of routers and links that flap, it adds up, which is why large networks are split into several areas, each with its own smaller LSDB. For the CCNA, a single area 0 is all you configure.
Common mistakes
- Using a subnet mask instead of a wildcard mask in the network command (
0.0.0.255, not255.255.255.0). - Forgetting a network command for a LAN: the routers become neighbours but nobody learns that LAN.
- Thinking the network command advertises exactly the range typed. It selects interfaces; each interface's own subnet is advertised.
- Expecting OSPF to resend everything periodically. It sends changes, plus a 30-minute refresh.
- Forgetting that each router runs SPF itself: a wrong cost on one router changes paths through that router.
💡 Exam tip: match each packet to its job (Hello, DBD, LSR, LSU, LSAck) and each step to its show command: show ip protocols (step 1), show ip ospf neighbor (step 2), show ip ospf database (step 3), show ip route ospf (step 5). Expect a network command question: which interfaces does network 10.1.0.0 0.0.255.255 area 0 enable?
Key takeaways
- Five steps: start the process, find neighbours, share LSAs into the LSDB, run SPF, fill the routing table.
- OSPFv2 routes IPv4 and is started with router ospf; the process ID is local, the router ID must be unique.
- The network command (address + wildcard + area) selects interfaces; matching interfaces send hellos and have their subnets advertised.
- Hello, DBD, LSR, LSU and LSAck take two routers from strangers to Full, with identical LSDBs.
- Every router runs SPF from its own position; the best paths go into the routing table as O routes.
- A change triggers new LSAs, flooding, SPF and new routes: that is OSPF convergence.
Check yourself
R1 has interfaces 10.1.5.1, 10.1.200.1 and 10.2.0.1. Which of them does network 10.1.0.0 0.0.255.255 area 0 enable?
During the database exchange, R1 sees an LSA listed in R2's DBD that it doesn't have. What does R1 send next?
A LAN interface on R4 is not matched by any network command. What happens?
All routers in the area have the same LSDB. Which step makes R1 and R3 install different next hops for LAN B?
The R2–R4 link fails. Put R1's experience in the right order.