skip to content

In OSPF, which states does a neighbour pass through from the first Hello to Full, and what happens in each?

level: middleimportance: must knowfreq 48%

answer

  1. Hello protocol, then database exchange
  2. one-way, two-way, then master and slave
  3. summaries before full LSAs
  4. Attempt only on NBMA

basics

~20 s

An OSPF neighbour goes Down, Init (its Hello heard), 2-Way (each sees itself in the other's Hello), ExStart (master and slave chosen), Exchange (database summaries traded), Loading (missing LSAs requested) and Full (databases synchronised). NBMA adds Attempt.

solid answer

~40 s

The states come from RFC 2328. **Down**: nothing heard. **Attempt** (NBMA only): Hellos sent to a configured neighbour. **Init**: its Hello arrived, but without my Router ID in it. **2-Way**: I see myself in its Hello, so communication is bidirectional; here the router decides whether to become adjacent, and on a LAN two routers that are neither DR nor BDR deliberately stop. **ExStart**: the pair picks a master (the higher Router ID) and an initial DD sequence number. **Exchange**: Database Description packets list the headers of every LSA in the area database. **Loading**: Link State Requests fetch the LSAs found missing or older. **Full**: the databases match and the adjacency appears in router-LSAs and network-LSAs. If nothing needs requesting, Exchange goes straight to Full.

go deeper

for a junior

Recall the order Down, Init, 2-Way, ExStart, Exchange, Loading, Full, and that Full means the two databases match.

for a middle

Explain what triggers each move, how the master is chosen, and why Exchange trades only LSA headers before Loading fetches full LSAs.

for a senior

Read a stuck state as the last step that worked: Init for one-way loss, ExStart for DD trouble, Loading for update loss, 2-Way as normal for routers that are neither DR nor BDR.

for a principal

Use the state machine to explain how adjacency churn spreads into flooding and recomputation, and how link and timer design limit it.

## Neighbour versus adjacency RFC 2328 separates two relationships. A **neighbour** is any router whose Hellos you exchange on a shared link. An **adjacency** is a neighbour with which you synchronise link-state databases. Every adjacency is a neighbour, but not every neighbour becomes adjacent: on a broadcast LAN only the Designated Router (DR) and Backup Designated Router (BDR) are adjacent to everyone. The neighbour states trace both relationships: the first half belongs to the **Hello protocol**, the second half to **database exchange**. ## The states in order | State | How a neighbour gets here | What it means | |---|---|---| | **Down** | start, or any fatal event | no recent Hello from this neighbour | | **Attempt** | NBMA only, `Start` event | Hellos are being sent to a configured neighbour that has not answered | | **Init** | a Hello arrives (`HelloReceived`) | we hear it, but it does not list our Router ID yet | | **2-Way** | our Router ID appears in its Hello | communication is bidirectional; DR and BDR are chosen from routers in this state or higher | | **ExStart** | the adjacency decision says yes | master and slave are negotiated, plus the starting DD sequence number | | **Exchange** | negotiation done | Database Description (DD) packets describe the whole area database | | **Loading** | exchange done, requests outstanding | Link State Request packets fetch missing or newer LSAs | | **Full** | request list empty | databases synchronised; the adjacency is advertised in LSAs | From ExStart upward the RFC calls the conversation an adjacency; from Exchange upward the neighbour takes part in flooding. ## The database exchange in detail 1. In **ExStart**, each router sends empty DD packets with three flag bits set: `I` (initial), `M` (more) and `MS` (master). Each claims to be master. 2. The router with the **higher Router ID** becomes master; the other becomes slave and adopts the master's DD sequence number. This choice has nothing to do with the DR election. 3. In **Exchange**, the master sends DD packets as polls and the slave answers each one, echoing its sequence number. Only one DD packet is outstanding at a time, and only the master retransmits. 4. Each DD packet carries **LSA headers**, not whole LSAs. A router compares each header with its own database and puts anything missing or older on its **link state request list**. 5. In **Loading**, the router sends Link State Requests and receives the full LSAs in Link State Update packets. 6. When the request list is empty the neighbour is **Full**. If a router had nothing to request, it moves from Exchange directly to Full, as RFC 2328's own bring-up example shows. ## Events that move a neighbour backwards - `1-WayReceived` — the neighbour's Hello no longer lists us: back to **Init**. - `SeqNumberMismatch` or `BadLSReq` — the DD sequence broke, flags or options changed mid-exchange, or a Link State Request asked for an LSA the receiving router does not hold: back to **ExStart** to start the exchange again. - `InactivityTimer`, `KillNbr` or `LLDown` — no Hellos for the dead interval, an administrative kill or a lower-layer failure: straight to **Down**. - `AdjOK?` — re-run when the DR or BDR changes; it can build a new adjacency or break one back to 2-Way. ## Reading the states when troubleshooting - **Stuck in Init** — Hellos flow in only one direction, or the other side drops ours. - **2-Way between two routers that are neither DR nor BDR** — normal on a broadcast or NBMA network. - **Stuck in ExStart or Exchange** — the DD exchange cannot complete; an interface MTU mismatch is the classic cause. - **Stuck in Loading** — requests go out but the matching updates do not arrive intact. - **No neighbour at all** — Hellos are being dropped, for example because the area ID, timers or authentication disagree. Knowing the order is what makes the state a diagnosis: each state names the last step that succeeded.

  • In OSPF's ExStart state, which router becomes master, and does that role matter afterwards?
    The router with the higher Router ID becomes master; the other adopts its DD sequence number as slave. The master sends the polls and is the only side that retransmits. The role exists only to clock the database exchange of that one pair; it has nothing to do with the DR election and no effect on routing once the pair is Full.
  • Can an OSPF neighbour go from Exchange directly to Full, skipping Loading?
    Yes. Loading exists only to fetch LSAs found missing or out of date during Exchange. If the request list is empty when the last Database Description packet is processed, the neighbour goes straight to Full. RFC 2328's bring-up example shows the router with the up-to-date database doing exactly that while its peer passes through Loading.

saying these in an interview costs you the question

  • 2-Way is a failure state that every OSPF neighbour should leave.
  • The DR is always the master during the database exchange.
  • In Exchange the routers send each other their complete LSAs.
  • Every OSPF neighbour passes through Attempt on its way to Full.
  • A neighbour in Init has already confirmed two-way communication.