Every ticket uses the finished lab from the configuration lessons: R1, R2 and R3 in a line, point-to-point router links, passive LAN interfaces, a reference bandwidth of 10 000 Mbps (so each gigabit interface costs 10), and a default route from R1 to the ISP. Read the symptom and the output, decide on the cause and the fix, then open the diagnosis.
- 1. Router links: 10.0.12.0/30 and 10.0.23.0/30, both ip ospf network point-to-point, area 0.
- 2. LANs: 192.168.1.0/24, 192.168.2.0/24 and 192.168.3.0/24, all passive.
- 3. Internet: R1 has a static default to 203.0.113.1 and default-information originate.
Ticket 1: nobody can reach the internet
Since a change on R1 last night, users on every LAN can reach each other but not the internet. R1 can ping 203.0.113.1.
R3#show ip route | include 0.0.0.0 Gateway of last resort is not set
R1#show running-config | include ip route|default-information ip route 0.0.0.0 0.0.0.0 203.0.113.11 default-information originate
Show diagnosis
The static default points at 203.0.113.11, a typo for 203.0.113.1. That address is not on any of R1's subnets (Gi0/2 is 203.0.113.2/30), so the static route is never installed. Without a default route of its own, R1 doesn't originate one into OSPF. Fix: no ip route 0.0.0.0 0.0.0.0 203.0.113.11 and ip route 0.0.0.0 0.0.0.0 203.0.113.1. R2 and R3 get O*E2 0.0.0.0/0 back within seconds. Adding always would have hidden the problem, not fixed it.
Ticket 2: R1 is cut off after security hardening
A security checklist was applied to R1. LAN 1 now reaches nothing outside itself, and R2 has lost R1 as a neighbour.
R1#show ip protocols | begin Passive Passive Interface(s): GigabitEthernet0/0 GigabitEthernet0/1 GigabitEthernet0/2 Routing Information Sources: Gateway Distance Last Update
Show diagnosis
The checklist added passive-interface default, which also made Gi0/1, the link to R2, passive. No hellos, no neighbour. Fix: under router ospf 1, no passive-interface GigabitEthernet0/1. Gi0/0 (LAN 1) should stay passive. Gi0/2 is not in OSPF anyway, so its passive setting does nothing.
Ticket 3: R2 and R3 never finish
R3's Gi0/0 was reconfigured during a VPN test. Now R1 and R2 have no routes to LAN 3.
R3#show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 2.2.2.2 0 EXSTART/ - 00:00:33 10.0.23.1 GigabitEthernet0/0
R3#show ip interface GigabitEthernet0/0 | include MTU MTU is 1400 bytes
Show diagnosis
Hellos work (the neighbour exists), but the database exchange doesn't. R3's IP MTU is 1400 while R2's is 1500, so R3 rejects R2's DBDs, which announce the larger MTU. R3 sits in EXSTART; R2 would show EXCHANGE. Fix: on R3, interface GigabitEthernet0/0, no ip mtu. ip ospf mtu-ignore would also let the adjacency form, but leaves large packets broken.
Ticket 4: LAN 2 has disappeared
R2 was rebuilt from notes after a hardware swap. Its neighbours are Full, but R1 and R3 have no route to 192.168.2.0/24.
R2#show ip ospf interface brief Interface PID Area IP Address/Mask Cost State Nbrs F/C Gi0/1 1 0 10.0.23.1/30 10 P2P 1/1 Gi0/0 1 0 10.0.12.2/30 10 P2P 1/1
R2#show running-config | section router ospf router ospf 1 router-id 2.2.2.2 auto-cost reference-bandwidth 10000 passive-interface GigabitEthernet0/2 network 10.0.12.0 0.0.0.3 area 0 network 10.0.23.0 0.0.0.3 area 0 network 192.168.2.0 0.0.0.0 area 0
Show diagnosis
Gi0/2 is missing from the interface list, so OSPF isn't running on it at all. The statement network 192.168.2.0 0.0.0.0 area 0 only matches an interface whose address is exactly 192.168.2.0, and Gi0/2 is 192.168.2.1. The passive line doesn't enable anything by itself. Fix: no network 192.168.2.0 0.0.0.0 area 0, then network 192.168.2.0 0.0.0.255 area 0 (or network 192.168.2.1 0.0.0.0 area 0).
Ticket 5: the costs look wrong
Everything works, but an audit notices odd metrics on R3.
R3#show ip route ospf | include 192.168 O 192.168.1.0/24 [110/21] via 10.0.23.1, 01:12:40, GigabitEthernet0/0 O 192.168.2.0/24 [110/11] via 10.0.23.1, 01:12:40, GigabitEthernet0/0
Show diagnosis
With every router at 10 000 Mbps, each gigabit interface costs 10, so LAN 1 should be 30 (R3 Gi0/0 + R2 Gi0/0 + R1 Gi0/0) and LAN 2 should be 20. The totals are 9 lower on each route that passes R2: R2's interfaces cost 1, which means R2 still uses the default 100 Mbps reference (100 ÷ 1000 is less than 1, so it becomes the minimum cost of 1). Confirm with show ip ospf | include Reference on R2. Fix: auto-cost reference-bandwidth 10000 under R2's router ospf 1. In a network with more than one path, this mismatch would also change which paths are chosen.
Ticket 6: Full neighbours, missing routes
A colleague tidied up the R2–R3 link. Both routers show each other as Full, yet R1 has no route to LAN 3.
R2#show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 3.3.3.3 0 FULL/DROTHER 00:00:36 10.0.23.2 GigabitEthernet0/1 1.1.1.1 0 FULL/ - 00:00:31 10.0.12.1 GigabitEthernet0/0
R3#show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 2.2.2.2 0 FULL/ - 00:00:38 10.0.23.1 GigabitEthernet0/0
Show diagnosis
R2 gives R3 a DR/BDR role (DROTHER), which only exists on broadcast networks, while R3 shows R2 with no role (-). R2's Gi0/1 has gone back to the broadcast type (the "tidy-up" removed ip ospf network point-to-point), while R3 is still point-to-point. The timers match, so they reach Full, but they describe the link differently in their LSAs and SPF can't use it. Fix: put ip ospf network point-to-point back on R2 Gi0/1. Compare Network Type in show ip ospf interface on both ends.
Ticket 7: a log message on R2
R1 was re-addressed this morning. R2 now logs this every 10 seconds, and LAN 1 is unreachable.
%OSPF-4-ERRRCV: Received invalid packet: mismatched area ID from backbone area must be virtual-link but not found from 10.0.12.1, GigabitEthernet0/0
Show diagnosis
R1's Gi0/1 (10.0.12.1) is now in a different area from R2's Gi0/0 in area 0. Likely cause: R1 was given ip ospf 1 area 1 on Gi0/1, or a network statement with the wrong area. Interface configuration overrides network statements, so check both. Fix: put R1's Gi0/1 back in area 0 (ip ospf 1 area 0 on the interface, or correct the network statement).
Ticket 8: an unknown neighbour
Some traffic from LAN 1 to LAN 3 is going missing. R2's neighbour table has an extra entry.
R2#show ip ospf neighbor Neighbor ID Pri State Dead Time Address Interface 10.10.10.10 1 FULL/DR 00:00:35 192.168.2.50 GigabitEthernet0/2 3.3.3.3 0 FULL/ - 00:00:37 10.0.23.2 GigabitEthernet0/1 1.1.1.1 0 FULL/ - 00:00:33 10.0.12.1 GigabitEthernet0/0
Show diagnosis
A device on LAN 2 (192.168.2.50, router ID 10.10.10.10) has become an OSPF neighbour and is advertising routes, probably a lab VM or a misconfigured server. That can only happen because R2's Gi0/2 is no longer passive. Fix: passive-interface GigabitEthernet0/2 under router ospf 1, then find the device. OSPF authentication on the router links would add a second layer of protection.