When an OSPF router holds one instance of an LSA and receives another, how does it decide which instance is more recent?
answer
- identity first, then instance
- a signed 32-bit counter
- tie: the larger checksum
- then MaxAge, then a 15-minute gap
basics
~20 sOSPF compares the LS sequence number first and the higher one wins. On a tie the larger LS checksum wins; then an instance at MaxAge wins; then, if the ages differ by more than 15 minutes, the younger wins. Otherwise the two are identical.
solid answer
~40 sTwo LSAs are instances of the *same* LSA when their `LS type`, `Link State ID` and `Advertising Router` match. RFC 2328 §13.1 then decides which is more recent, in a fixed order: the higher **LS sequence number** wins, compared as a signed 32-bit integer; if the sequence numbers tie, the larger **LS checksum** wins; if those tie too, an instance whose **LS age** is `MaxAge` wins, so flushes always propagate; failing that, if the ages differ by more than `MaxAgeDiff` (15 minutes) the younger instance wins. Otherwise the instances are the same. The sequence number does almost all the work: an originator increments it for every new instance, starting at `0x80000001`. The checksum and age tie-breakers exist for the rare case of a router that restarted and lost track of its last sequence number.
code
pseudocode · 12 linesfunction moreRecent(a, b): # same LS type, Link State ID, Advertising Router
if a.seq != b.seq: # signed 32-bit compare
return a if a.seq > b.seq else b
if a.checksum != b.checksum: # unsigned 16-bit compare
return a if a.checksum > b.checksum else b
if a.age == MaxAge and b.age != MaxAge:
return a
if b.age == MaxAge and a.age != MaxAge:
return b
if abs(a.age - b.age) > MaxAgeDiff: # MaxAgeDiff = 900 s
return a if a.age < b.age else b
return SAME_INSTANCEgo deeper
Recall that OSPF tells two copies of an LSA apart mainly by the sequence number, and that the higher number is the newer copy.
State the full order — sequence number, larger checksum, MaxAge, then a 15-minute age gap — and explain what each tie-breaker is for.
Connect the tie-breakers to the restart case, where a router has lost its last sequence number, and explain how the originator corrects a wrong pick.
Consider why an ordered, deterministic comparison is what lets independently implemented routers agree on one database without any central authority.
## Identity versus instance Every OSPF LSA header carries six fields that matter here. Three name the LSA; three distinguish its versions. | Question | Fields | |---|---| | Which LSA is this? | `LS type`, `Link State ID`, `Advertising Router` | | Which instance of it? | `LS sequence number`, `LS checksum`, `LS age` | A router holds at most one instance of each LSA. Whenever two instances meet — a flooded copy against the database copy, or a neighbour's summary against the local copy during database exchange — the router must decide which is more recent, and every router must reach the same verdict, or the databases would never agree. ## The comparison, in order RFC 2328 §13.1 defines the test. It is an ordered list; a later step is reached only when every earlier one ties. 1. **Sequence number**: the larger value, compared as a signed 32-bit integer, is more recent. 2. **Checksum**: with equal sequence numbers, the larger `LS checksum`, read as an unsigned 16-bit integer, is more recent. 3. **MaxAge**: if only one instance has `LS age` equal to `MaxAge` (1 hour), that one is more recent. 4. **Age gap**: if the ages differ by more than `MaxAgeDiff` (15 minutes), the instance with the smaller age is more recent. 5. Otherwise the two are **the same instance**. Two details make step 4 work. Age grows while an LSA sits in a database and by `InfTransDelay` on every hop, so copies of one instance naturally drift apart in age; `MaxAgeDiff` is the RFC's bound on that drift. And the checksum covers the whole LSA *except* the age field, so age can change without the checksum changing. ## The sequence number space - The field is a **signed 32-bit integer**, so the space is linearly ordered from most negative to most positive. - `0x80000000` is reserved and unused. - `0x80000001` is `InitialSequenceNumber`, the first value a router uses for any LSA — the *oldest* possible instance. - Each new instance increments the number by one. - `0x7fffffff` is `MaxSequenceNumber`. It does not wrap silently: the router must flush the current instance by setting its age to `MaxAge`, wait until all adjacent neighbours acknowledge that flush, then originate again at `0x80000001`. Wrapping is a theoretical event. A router may originate a new instance of one LSA at most every `MinLSInterval` (5 s). The space holds 2³² − 1 usable values, so even at that maximum rate the counter lasts 4,294,967,294 × 5 s ≈ 2.15 × 10¹⁰ s, roughly 680 years. ## Why the checksum and age break ties A router that reboots may have forgotten the sequence number it last used and start again at `0x80000001`. Two different instances can then carry the same sequence number. RFC 2328's notes explain the fallbacks: - **Different checksums** almost always mean different contents. Neither can be proved newer, so the RFC just picks the larger checksum; if that was the wrong one, the originator sees its own LSA come back with content it did not originate and simply originates another instance. - **An age gap beyond 15 minutes** cannot come from flooding delay alone, so the two must be distinct instances, and the younger is taken as current. - **MaxAge wins** so that a flush, which keeps the sequence number and only changes the age, always beats the live copy it is meant to remove. ## Where the test runs - **Flooding**: a newer received instance is installed and flooded on; an identical one is an acknowledgement or a duplicate; an older one makes the router send its own newer copy back. - **Database exchange** when an adjacency forms: a router requests every LSA for which the neighbour's summary is newer than its own copy. - **The originator itself**: a received instance of its own LSA that is newer than what it last originated tells it a stale copy is circulating. ## Mistakes that show up in interviews - Treating the smaller age as the first test. Age is the *last* tie-breaker and only when the gap exceeds 15 minutes. - Expecting the counter to start at zero. It starts at the most negative usable value. - Reaching for a Router ID tie-break. Router IDs break ties in the designated-router election, not between LSA instances.
- Why does OSPF treat an LSA instance at MaxAge as more recent than an otherwise identical one?Flushing an LSA, whether it aged out or was prematurely aged, keeps the sequence number and only sets the age to `MaxAge`. If that copy did not win the comparison, every router would keep the live copy and the flush would never spread. RFC 2328 makes the `MaxAge` instance more recent so old LSAs can be removed from the domain quickly.
- What happens when an OSPF router's LSA sequence number reaches 0x7fffffff?It cannot simply wrap. The router prematurely ages the current instance (sets `LS age` to `MaxAge`, keeps the sequence number) and refloods it. Once every adjacent neighbour has acknowledged that flush, it originates the next instance at `0x80000001`. At one origination per 5 s this takes roughly 680 years to arise.
- Why is the LS age field excluded from an OSPF LSA's checksum?Age changes constantly: it grows every second in each database and by `InfTransDelay` on every flooding hop. Excluding it lets every router age an LSA without recomputing the checksum, and keeps the checksum a property of the instance's contents, which is what lets it serve as a tie-breaker between instances.
saying these in an interview costs you the question
- The OSPF LSA instance with the smaller age is always the newer one.
- OSPF LSA sequence numbers start at zero and count upward.
- With equal sequence numbers, OSPF keeps the LSA copy from the higher Router ID.
- An OSPF LSA sequence number past its maximum simply wraps to the initial value.
- The OSPF LSA checksum only detects corruption and never decides which copy is newer.