Course menu

Course 9: OSPFLesson 4.1 (8 of 20 in this course)77 of 118 in the CCNA series

OSPF passive interfaces

Advertise a LAN without sending hellos onto it: what passive-interface does, passive by default, and how to verify it.

Intermediate · 9 min read

What you will learn

After this lesson, you can make LAN interfaces passive so their subnets are advertised without forming neighbours, use passive-interface default safely, and spot a passive interface in show output.

  • passive-interface
  • passive-interface default
  • Security

An OSPF passive interface is an interface that is enabled for OSPF but sends no hello packets and ignores any it receives. Its subnet is still included in the router's LSA and advertised to the rest of the network, but no neighbour can ever form through it.

In simple terms: The router tells everyone "I can reach this network", but it doesn't talk OSPF to the devices on it, because only PCs and printers live there.

A real-life situation

A student brings a laptop running a routing lab program to the office and plugs it into LAN 2. The program happens to speak OSPF. Within a minute R2 has a new neighbour, and the laptop is advertising a route to 10.0.0.0/8 that pulls traffic away from the real network. Nothing was hacked: R2 was sending OSPF hellos onto a LAN full of PCs and was ready to trust whatever answered. Making LAN interfaces passive stops this.

What a passive interface is

Enabling OSPF on an interface does two separate jobs:

  1. the router sends hellos out of it and forms neighbours there, and
  2. the interface's subnet goes into the router's LSA, so every other router learns it.

On a link to another router you want both. On a LAN with only PCs, printers and servers, you want only the second: there are no routers to talk to. A passive interface keeps job 2 and switches off job 1.

Gi0/2Gi0/1 .1.2 Gi0/010.0.12.0/30Gi0/1 .1.2 Gi0/010.0.23.0/30Gi0/0Gi0/2Gi0/1ISP203.0.113.1R1RID 1.1.1.1R2RID 2.2.2.2R3RID 3.3.3.3LAN 1192.168.1.0/24LAN 2192.168.2.0/24LAN 3192.168.3.0/24
  1. 1. Router links: not passive. R1–R2 and R2–R3 must exchange hellos, or the routers never become neighbours.
  2. 2. LAN interfaces: passive. R1 Gi0/0, R2 Gi0/2 and R3 Gi0/1 send no hellos, but 192.168.1.0/24, 192.168.2.0/24 and 192.168.3.0/24 are still advertised.
  3. 3. ISP link: not in OSPF at all. R1 Gi0/2 is left out of OSPF completely. R1 reaches the ISP with a static default route instead.

Why it works this way

Making LAN interfaces passive has three benefits:

  • Security. Nobody on the LAN can become an OSPF neighbour and inject routes, by accident or on purpose.
  • Less noise. No hello every 10 seconds onto a segment where nobody needs it, and no OSPF multicast for every PC's network card to look at and throw away.
  • Less work. On Ethernet, every active OSPF interface also runs a DR election, even if it is alone. A passive interface skips that.

Passive is not the same as "not in OSPF". Leaving an interface out of OSPF means its subnet is not advertised at all, so the other routers would have no route to LAN 2.

Interface settingSends hellos / forms neighboursSubnet advertisedUse it for
In OSPF, not passiveYesYesLinks to other OSPF routers
In OSPF, passiveNoYesLANs with only end devices
Not in OSPFNoNoLinks you don't want in OSPF, such as the ISP link

How to configure it on Cisco IOS

One interface at a time

router ospf 1 passive-interface GigabitEthernet0/2

On R2: LAN 2 becomes passive. passive-interface is a router configuration command (under router ospf), not an interface command.

Passive by default

On a router with many LANs, or to be safe from new interfaces being added later, make every interface passive and switch hellos back on only towards other routers:

router ospf 1 passive-interface default no passive-interface GigabitEthernet0/0 no passive-interface GigabitEthernet0/1

On R2: every interface is passive, then the two router links (to R1 and R3) are made active again. Any interface added later starts passive, which is the safe choice.

💡 If you type passive-interface default on a router that already has neighbours, every adjacency drops at once. On a live network, add the no passive-interface lines first, or apply the change in a maintenance window.

How to verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
R2#show ip protocols | begin Passive
  Passive Interface(s):
    GigabitEthernet0/2
  Routing Information Sources:
    Gateway         Distance      Last Update
    1.1.1.1              110      00:02:11
    3.3.3.3              110      00:02:09
The list of passive interfaces. With passive-interface default it shows every interface except the ones you made active again, so it is a quick way to check you didn't miss a router link.
Example output · based on Cisco documentation; exact format varies by platform and software version
R2#show ip ospf interface GigabitEthernet0/2
GigabitEthernet0/2 is up, line protocol is up
  Internet Address 192.168.2.1/24, Area 0, Attached via Network Statement
  Process ID 1, Router ID 2.2.2.2, Network Type BROADCAST, Cost: 1
  Transmit Delay is 1 sec, State DR, Priority 1
  Designated Router (ID) 2.2.2.2, Interface address 192.168.2.1
  No backup designated router on this network
  Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5
    No Hellos (Passive interface)
  Neighbor Count is 0, Adjacent neighbor count is 0
No Hellos (Passive interface) confirms it. The interface still has an area and a cost, because it is still part of OSPF and its subnet is still advertised.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip route ospf | include 192.168.2
O     192.168.2.0/24 [110/2] via 10.0.12.2, 00:05:40, GigabitEthernet0/1
On R1, LAN 2 is still learned through OSPF. The passive setting on R2 changed nothing for the rest of the network. (Cost 2 here uses the default reference bandwidth.)

What goes wrong and how to troubleshoot it

  • A neighbour disappeared after a tidy-up. A router link was made passive, usually by passive-interface default without the matching no passive-interface. Check show ip protocols on both routers.
  • A neighbour stays missing although only one side is passive. That is expected: one passive side is enough. The passive router sends no hellos and ignores the other router's, so neither side ever reaches 2-Way.
  • A LAN is missing from other routers' tables. The interface is not in OSPF at all, which is a different problem from passive. Check show ip ospf interface brief: a passive interface is still listed there.

Common mistakes

  • Thinking passive stops the network being advertised. It only stops hellos.
  • Typing passive-interface in interface configuration mode. It belongs under router ospf.
  • Making a router-to-router link passive and then troubleshooting timers and areas.
  • Forgetting that passive-interface default drops every existing adjacency until the active interfaces are listed.

💡 Exam tip: know exactly what passive does (no hellos, no neighbours, subnet still advertised) and where the command goes. A common question shows passive-interface default and asks why two routers are not neighbours, or asks which interfaces should be passive (the ones with no OSPF routers behind them).

Key takeaways

✅ Key takeaways
  • A passive interface sends no hellos and forms no neighbours, but its subnet is still advertised.
  • Make LAN interfaces with no routers behind them passive: safer, quieter, no DR election.
  • passive-interface <if> or passive-interface default plus no passive-interface <if>, under router ospf.
  • Verify with show ip protocols and "No Hellos (Passive interface)" in show ip ospf interface.

Check yourself

Predict · scenario 1

R2's Gi0/2 (LAN 2, 192.168.2.0/24) is made passive. What happens to R1's route to 192.168.2.0/24?

Predict · scenario 2

R2 has passive-interface default and no other passive commands. How many OSPF neighbours does it have?

Predict · scenario 3

Where do you type passive-interface GigabitEthernet0/2?

Predict · scenario 4

Which interface in the lab should NOT be passive?

FAQ

Does a passive interface stop OSPF advertising the network?
No. The interface stays in OSPF, so its subnet is still in the router's LSA and every other router learns it. Only hellos stop. To stop advertising a network, take the interface out of OSPF (remove the network statement or the ip ospf area command).
Does a passive interface still receive routes?
Not through that interface. Routes are only exchanged with neighbours, and a passive interface never has any. The router still learns routes through its other, non-passive interfaces.
Do loopback interfaces need to be passive?
It does no harm, but it isn't needed: OSPF never sends hellos out of a loopback, because nothing can be on the other end. passive-interface default also covers loopbacks, which is fine.