A real-life situation
A student brings a laptop running a routing lab program to the office and plugs it into LAN 2. The program happens to speak OSPF. Within a minute R2 has a new neighbour, and the laptop is advertising a route to 10.0.0.0/8 that pulls traffic away from the real network. Nothing was hacked: R2 was sending OSPF hellos onto a LAN full of PCs and was ready to trust whatever answered. Making LAN interfaces passive stops this.
What a passive interface is
Enabling OSPF on an interface does two separate jobs:
- the router sends hellos out of it and forms neighbours there, and
- the interface's subnet goes into the router's LSA, so every other router learns it.
On a link to another router you want both. On a LAN with only PCs, printers and servers, you want only the second: there are no routers to talk to. A passive interface keeps job 2 and switches off job 1.
- 1. Router links: not passive. R1–R2 and R2–R3 must exchange hellos, or the routers never become neighbours.
- 2. LAN interfaces: passive. R1 Gi0/0, R2 Gi0/2 and R3 Gi0/1 send no hellos, but 192.168.1.0/24, 192.168.2.0/24 and 192.168.3.0/24 are still advertised.
- 3. ISP link: not in OSPF at all. R1 Gi0/2 is left out of OSPF completely. R1 reaches the ISP with a static default route instead.
Why it works this way
Making LAN interfaces passive has three benefits:
- Security. Nobody on the LAN can become an OSPF neighbour and inject routes, by accident or on purpose.
- Less noise. No hello every 10 seconds onto a segment where nobody needs it, and no OSPF multicast for every PC's network card to look at and throw away.
- Less work. On Ethernet, every active OSPF interface also runs a DR election, even if it is alone. A passive interface skips that.
Passive is not the same as "not in OSPF". Leaving an interface out of OSPF means its subnet is not advertised at all, so the other routers would have no route to LAN 2.
| Interface setting | Sends hellos / forms neighbours | Subnet advertised | Use it for |
|---|---|---|---|
| In OSPF, not passive | Yes | Yes | Links to other OSPF routers |
| In OSPF, passive | No | Yes | LANs with only end devices |
| Not in OSPF | No | No | Links you don't want in OSPF, such as the ISP link |
How to configure it on Cisco IOS
One interface at a time
router ospf 1
passive-interface GigabitEthernet0/2On R2: LAN 2 becomes passive. passive-interface is a router configuration command (under router ospf), not an interface command.
Passive by default
On a router with many LANs, or to be safe from new interfaces being added later, make every interface passive and switch hellos back on only towards other routers:
router ospf 1
passive-interface default
no passive-interface GigabitEthernet0/0
no passive-interface GigabitEthernet0/1On R2: every interface is passive, then the two router links (to R1 and R3) are made active again. Any interface added later starts passive, which is the safe choice.
💡 If you type passive-interface default on a router that already has neighbours, every adjacency drops at once. On a live network, add the no passive-interface lines first, or apply the change in a maintenance window.
How to verify it
R2#show ip protocols | begin Passive Passive Interface(s): GigabitEthernet0/2 Routing Information Sources: Gateway Distance Last Update 1.1.1.1 110 00:02:11 3.3.3.3 110 00:02:09
passive-interface default it shows every interface except the ones you made active again, so it is a quick way to check you didn't miss a router link.R2#show ip ospf interface GigabitEthernet0/2 GigabitEthernet0/2 is up, line protocol is up Internet Address 192.168.2.1/24, Area 0, Attached via Network Statement Process ID 1, Router ID 2.2.2.2, Network Type BROADCAST, Cost: 1 Transmit Delay is 1 sec, State DR, Priority 1 Designated Router (ID) 2.2.2.2, Interface address 192.168.2.1 No backup designated router on this network Timer intervals configured, Hello 10, Dead 40, Wait 40, Retransmit 5 No Hellos (Passive interface) Neighbor Count is 0, Adjacent neighbor count is 0
R1#show ip route ospf | include 192.168.2 O 192.168.2.0/24 [110/2] via 10.0.12.2, 00:05:40, GigabitEthernet0/1
What goes wrong and how to troubleshoot it
- A neighbour disappeared after a tidy-up. A router link was made passive, usually by
passive-interface defaultwithout the matchingno passive-interface. Checkshow ip protocolson both routers. - A neighbour stays missing although only one side is passive. That is expected: one passive side is enough. The passive router sends no hellos and ignores the other router's, so neither side ever reaches 2-Way.
- A LAN is missing from other routers' tables. The interface is not in OSPF at all, which is a different problem from passive. Check
show ip ospf interface brief: a passive interface is still listed there.
Common mistakes
- Thinking passive stops the network being advertised. It only stops hellos.
- Typing
passive-interfacein interface configuration mode. It belongs underrouter ospf. - Making a router-to-router link passive and then troubleshooting timers and areas.
- Forgetting that
passive-interface defaultdrops every existing adjacency until the active interfaces are listed.
💡 Exam tip: know exactly what passive does (no hellos, no neighbours, subnet still advertised) and where the command goes. A common question shows passive-interface default and asks why two routers are not neighbours, or asks which interfaces should be passive (the ones with no OSPF routers behind them).
Key takeaways
- A passive interface sends no hellos and forms no neighbours, but its subnet is still advertised.
- Make LAN interfaces with no routers behind them passive: safer, quieter, no DR election.
passive-interface <if>orpassive-interface defaultplusno passive-interface <if>, underrouter ospf.- Verify with
show ip protocolsand "No Hellos (Passive interface)" inshow ip ospf interface.
Check yourself
R2's Gi0/2 (LAN 2, 192.168.2.0/24) is made passive. What happens to R1's route to 192.168.2.0/24?
R2 has passive-interface default and no other passive commands. How many OSPF neighbours does it have?
Where do you type passive-interface GigabitEthernet0/2?
Which interface in the lab should NOT be passive?