skip to content

In OSPF, where can routes be summarised, why only there, and how does a summarising ABR keep traffic for unused addresses from looping?

level: seniorimportance: should knowfreq 28%

answer

  1. the topology inside must stay whole
  2. ranges live on border routers
  3. highest cost of the parts
  4. externals have their own aggregation point
  5. a route that drops on purpose

basics

~20 s

OSPF summarises only at borders: ABRs advertise configured area ranges as type 3 LSAs, and ASBRs or NSSA translators aggregate externals. Inside an area every router needs the full topology. A discard entry per active range drops unmatched traffic instead of looping it.

solid answer

~50 s

Inside an area every router must hold the same router- and network-LSAs to run SPF, so no internal router can hide anything. The **ABR** is where an area's prefixes can be condensed: RFC 2328 gives each area a list of **address ranges**, and for a range marked Advertise the ABR originates one type 3 summary whose cost is the **largest** cost of its component networks; DoNotAdvertise hides them. ABRs never summarise type 5 externals. Externals are condensed where they enter: an ASBR chooses what it originates, and an NSSA translator can aggregate type 7s with **type 7 address ranges** (RFC 3101). To stop loops, the ABR installs a **discard entry** for each active range: a packet for an address inside the range that no component covers is dropped with an ICMP unreachable rather than following a default route back out.

go deeper

for a junior

Recall that OSPF summarises at area border routers, and that routers inside an area always see its full detail.

for a middle

Explain area ranges with Advertise and DoNotAdvertise, why ABRs cannot summarise externals, and where external aggregation happens instead.

for a senior

Explain the discard entry and the partition hazard, and judge when a summary hides a failure you still need to see.

for a principal

Plan addressing so each area's prefixes fall inside a few ranges, trading summary stability against per-subnet exit choice.

## Why summarisation stops at the area border An OSPF area's database is its topology: router-LSAs (type 1) and network-LSAs (type 2) say which router connects to which segment, and every router in the area runs SPF over exactly the same set. A router inside the area cannot replace part of that map with a summary without breaking the shortest-path calculation for its neighbours. So OSPF summarises only where information **leaves** the place where it is topology: | Where | What is condensed | Mechanism | Standard | |---|---|---|---| | Inside an area | Nothing | Every router floods its full router-LSA | RFC 2328 | | ABR, toward other areas | The area's own intra-area networks | Area address ranges, one type 3 per range | RFC 2328 | | ASBR | Routes it imports from outside OSPF | It chooses which prefixes to originate as type 5; aggregation options are an implementation feature | Implementation | | NSSA translator | Type 7 externals leaving an NSSA | Type 7 address ranges, one translated type 5 per range | RFC 3101 | Working out which prefix covers which subnets is ordinary CIDR arithmetic; the OSPF question is where the summary may be placed and how it behaves. ## ABR area ranges in RFC 2328 Each area carries a configured list of **address ranges**, each an `[address, mask]` pair with a status: - **Advertise:** if any of the area's networks fall in the range, the ABR originates **one type 3** summary-LSA for the range into the other areas. Its cost is the **largest** cost to any component network. - **DoNotAdvertise:** the type 3 for the range is suppressed and its networks stay hidden from other areas. - **Networks outside every range** get a type 3 each, as without summarisation. Two limits apply: 1. Only **intra-area** routes are condensed this way. Inter-area routes summarised into a non-backbone area are re-advertised individually, and backbone ranges are ignored when summarising into a transit area for a virtual link. 2. AS-external routes are **never** put into summary-LSAs at all, so an ABR cannot shrink type 5 LSAs; they flood through the AS exactly as the ASBR originated them. In the 300-router example, area 1 uses `10.1.0.0/16` for all its subnets. Its two ABRs each advertise one type 3 for `10.1.0.0/16` into area 0 instead of one per subnet. A link flap inside area 1 now changes nothing outside, unless it changes the largest component cost or leaves the range with no reachable network. ## The discard entry: why summaries do not loop A summary claims more than the area may actually use. Suppose `10.1.200.0/24` is unassigned. A packet for `10.1.200.9` from area 2 follows the summary to an area 1 ABR. Without protection, the ABR's best match for that address may be a default route pointing back toward area 0; the packet then bounces between routers until its TTL runs out. RFC 2328 section 11.1 prevents this: 1. For each **active** range (one containing at least one reachable intra-area network), the ABR installs a **discard** routing table entry covering the whole range. 2. Forwarding uses the most specific match, so real component subnets still win over the discard entry. 3. A packet that matches only the discard entry is dropped, and an ICMP destination unreachable message is returned to its source. ## Summarisation hazards in production - **A partitioned area.** RFC 2328 warns that an address range must not be split across the pieces of a partitioned area. If area 1 splits so that half its subnets reach only one ABR, both ABRs keep advertising `10.1.0.0/16`; traffic for the missing half that lands on the wrong ABR hits its discard entry and is dropped. - **Coarser exit choice.** Each ABR's range cost is the largest component cost, so routers in other areas pick an ABR on one number for the whole range, not per subnet. - **Hidden failures.** A dead subnet inside a summarised range is invisible from outside; monitoring must look inside the area. - **Externals summarised in the wrong place.** Translated aggregates leave an NSSA with forwarding address `0.0.0.0`, pulling traffic to the translator rather than to the ASBR that owns the route.

  • What cost does an OSPF ABR advertise for an area address range?
    Under RFC 2328, the largest cost from the ABR to any network inside the range. The summary's cost therefore changes only when that largest component cost changes, which keeps most internal flaps invisible from outside.
  • Can an OSPF ABR summarise the type 5 external routes it passes on?
    No. RFC 2328 never advertises AS-external routes in summary-LSAs, and type 5 LSAs flood unchanged across ABRs. Externals can be condensed only where they are originated: by the ASBR itself, an implementation feature, or by an NSSA translator using type 7 address ranges defined in RFC 3101.
  • What happens when an OSPF area with a summarised range partitions?
    Each fragment acts as a separate area, but every ABR with any component of the range reachable still advertises the whole range. Traffic for subnets in the other fragment can reach an ABR that cannot deliver it and is dropped by its discard entry. RFC 2328 therefore requires that a range not be split across the pieces of a partition.

saying these in an interview costs you the question

  • Any OSPF router can summarise the routes in its own area.
  • An ABR can summarise type 5 external LSAs as it floods them.
  • An area range is advertised with the lowest cost among its networks.
  • Summarising at the ABR shrinks the database inside the summarised area.
  • The discard entry drops traffic for subnets that exist inside the range.