skip to content

OSPF

OSPF floods link-state advertisements so every router holds the same map and runs Dijkstra itself, with areas bounding the database. It is the default IGP question in network interviews.

on this pageshow

explore

questions

page 1 of 2

In OSPF, why is a large network split into areas, and what job do backbone area 0, ABRs and ASBRs each do?

level: juniorimportance: must knowfreq 55%

answer

  1. what one flapping link touches
  2. one database per attached area
  3. hub and spokes
  4. a router with a foot in two areas
  5. where outside routes come in

basics

~20 s

OSPF areas bound LSA flooding and SPF runs, so a change in one area does not ripple through every router. Area 0 is the hub every area attaches to; ABRs join areas to it, and ASBRs inject routes learned outside OSPF.

solid answer

~50 s

Each OSPF area keeps its own link-state database: router- and network-LSAs are flooded only inside the area, so a flapping link forces a full SPF run only on that area's routers, and other areas see at most a changed summary-LSA. Inter-area routing is a star. **Area 0** (`0.0.0.0`), the backbone, is the hub, and every other area must attach to it. An **area border router (ABR)** sits in area 0 and at least one other area, runs one copy of the algorithm per area, and condenses each area into summary-LSAs for the others. An **AS boundary router (ASBR)** imports routes from outside OSPF, such as static routes or another protocol's routes, as AS-external-LSAs; it may sit in the backbone, a normal area or an NSSA, but not inside a stub area. Internal routers know only their own area's topology and reach everything else through summaries and externals.

go deeper

for a junior

Recall the one-liner: areas limit how far topology changes spread, area 0 is the hub, ABRs connect areas to it, ASBRs bring in outside routes.

for a middle

Explain that each area has its own database and SPF run, that ABRs condense areas into summaries, and why inter-area traffic always transits area 0.

for a senior

Show what a flap in one area costs the others, why the backbone must stay contiguous, and how a router outside area 0 fails to join two areas.

for a principal

Argue when splitting a network into areas is worth the loss of path precision and the design constraint of a hub every area must touch.

## What an OSPF area is OSPF (RFC 2328, Internet Standard 54) is a **link-state** protocol: routers flood descriptions of their links, every router builds the same map, and each one computes shortest paths over it. An **area** is a group of networks plus the routers that have interfaces on them. RFC 2328 gives each area its **own link-state database (LSDB)** and its own run of the shortest-path calculation: - Two routers in the same area hold identical databases **for that area**. - A router with interfaces in three areas holds **three** databases, one per area. - The topology inside an area is invisible from outside it; other areas learn only *which destinations* it holds and *at what cost*. Each interface belongs to exactly one area, so an area boundary runs **through a router**, never through the middle of a link. ## Why split at all In one flat area of 300 routers, every link change is flooded to all 300 routers and every one of them reruns SPF. Splitting into areas changes three things: | Concern | One flat area | Area 0 plus three areas | |---|---|---| | Flooding of router- and network-LSAs | All 300 routers | Only the routers of the affected area | | Full SPF run after a link flap | All 300 routers | Only the affected area's routers | | Database size on an internal router | Every router and segment in the AS | Its own area, plus one summary per destination outside it | | Effect of a change on other areas | Full recalculation | At most a changed summary-LSA, often none when a range hides the prefix | The price is that routers outside an area no longer see its inside, so they choose exits on advertised summary costs rather than on the full topology. ## Area 0 and the hub-and-spoke rule The **backbone** is area `0.0.0.0`. RFC 2328 states that it always contains every area border router, that it is responsible for distributing routing information between non-backbone areas, and that it must be contiguous. Inter-area routing is therefore a **star**: area 0 is the hub and each other area is a spoke. A packet from area 1 to area 2 takes an intra-area path to an ABR, a backbone path, then an intra-area path in area 2. Two rules keep that star loop-free: 1. An ABR advertises only **intra-area** routes into the backbone, while it advertises both intra-area and inter-area routes into its other areas. 2. A router attached to several areas computes its inter-area routes from **backbone** summary-LSAs only. A router that sits in areas 1 and 3 but has no foot in area 0 has no backbone summaries to compute from, so it cannot give area 3 routes to the rest of the network; an area that cannot reach area 0 directly needs a physical link to it or, as a repair, a virtual link. ## The four router roles RFC 2328 defines four overlapping categories: | Role | Definition | What it does | |---|---|---| | Internal router | All interfaces in one area | Runs one copy of the algorithm | | Area border router (ABR) | Attaches to more than one area | Runs one copy per area; originates summary-LSAs into each | | Backbone router | Has an interface in area 0 | Every ABR is one; a router entirely inside area 0 is too | | AS boundary router (ASBR) | Exchanges routing information with other autonomous systems | Originates AS-external-LSAs flooded through the AS (type 7 LSAs inside an NSSA) | The ASBR role is **independent** of the others: an ASBR can be internal, an ABR, or a backbone router. A router announces its roles in its own router-LSA with the **B** bit (border) and the **E** bit (external). ## A 300-router example Take a network of 300 routers split into area 0 and areas 1, 2 and 3, using `10.1.0.0/16`, `10.2.0.0/16` and `10.3.0.0/16` inside the areas: 1. Two routers join area 1 to area 0; they are its ABRs and run two SPF instances each. 2. A router in area 2 learns a partner's routes from a static configuration and redistributes them; it is an **ASBR**, and its external routes are flooded to every area that accepts them. 3. A link flap inside area 3 floods new router-LSAs inside area 3 only; areas 1 and 2 see, at most, a changed summary from area 3's ABRs. ## What areas cost - **Less precise exit choice**: an internal router picks an ABR by the cost the ABR advertises, not by the full path beyond it. - **A design constraint**: every area must touch area 0, which shapes where links and ABRs go. - **More moving parts**: area types, ranges and border routers are all extra configuration that must agree on every router. Whether a network actually needs several areas depends on its size and churn; the mechanism above is what areas buy when it does.

  • Can one OSPF router be both an ABR and an ASBR?
    Yes. RFC 2328 makes the ASBR role independent of the area roles: an ASBR may be an internal router, an ABR or a backbone router. A router that joins area 1 to area 0 and also redistributes static routes sets both the B bit and the E bit in its router-LSAs, and other routers treat it in both capacities.
  • Why does an OSPF router attached to areas 1 and 3, but not to area 0, fail to connect area 3 to the rest of the network?
    Inter-area routing works like distance vector between ABRs: each ABR advertises only intra-area routes into the backbone and computes inter-area routes from backbone summaries alone, which stops summaries looping between areas. With no backbone attachment the router has no backbone summaries, so it can pass area 1's own networks into area 3 but nothing beyond them. RFC 3509 (Informational) notes that traffic to other areas then gets dropped.
  • Does an OSPF area boundary sit on a router or on a link?
    On a router. Every interface, and so every link, belongs to exactly one area; the ABR is the router whose interfaces sit in different areas. That is why an ABR keeps one link-state database per attached area.

A postal service with district sorting offices: each district office knows its own streets in detail, and mail between districts always goes through the central hub, which knows only which district holds which postcodes.

saying these in an interview costs you the question

  • OSPF areas exist mainly to separate customers or departments for security.
  • A router in two non-backbone areas, with no backbone link, connects them to the whole network.
  • An ABR is any router that redistributes routes from another protocol.
  • Every router in a multi-area OSPF network holds the same link-state database.
  • Area 0 is just a convention; any area number can serve as the backbone.
open as a page

In OSPF, what does a router's SPF calculation take as input, and what does it produce?

level: juniorimportance: must knowfreq 45%

basics

~20 s

An OSPF router runs Dijkstra's shortest-path-first algorithm over its area's link-state database with itself as the root. The result is a shortest-path tree giving the lowest total cost and next hops to every destination, which becomes its routing table.

open as a page

How does OSPF elect a Designated Router and Backup Designated Router on a LAN, and why doesn't a higher-priority newcomer take over?

level: middleimportance: must knowfreq 45%

basics

~20 s

On broadcast and NBMA networks, OSPF elects a BDR, then a DR, from routers in 2-Way or above: highest Router Priority wins, highest Router ID breaks ties, priority 0 never qualifies. A better newcomer never preempts a working DR.

open as a page

In OSPF, which states does a neighbour pass through from the first Hello to Full, and what happens in each?

level: middleimportance: must knowfreq 48%

basics

~20 s

An OSPF neighbour goes Down, Init (its Hello heard), 2-Way (each sees itself in the other's Hello), ExStart (master and slave chosen), Exchange (database summaries traded), Loading (missing LSAs requested) and Full (databases synchronised). NBMA adds Attempt.

open as a page

In OSPFv2, what do LSA types 1, 2, 3, 4, 5 and 7 describe, who originates each, and how far does each flood?

level: middleimportance: must knowfreq 45%

basics

~20 s

Types 1 (router) and 2 (network, from the DR) map an area's topology and stay inside it; ABRs originate 3 (network summary) and 4 (ASBR summary) per area; ASBRs' type 5 floods AS-wide except stub areas and NSSAs, whose own externals use type 7.

open as a page

In OSPF, why do a 10 Gb/s link and a 1 Gb/s link often end up with the same interface cost?

level: middleimportance: must knowfreq 42%

basics

~20 s

Many implementations derive an OSPF interface's cost as a reference bandwidth, commonly 100 Mb/s by default, divided by the interface bandwidth, never below 1, so every link of 100 Mb/s or faster costs 1 until the reference is raised.

open as a page

In OSPF, how does a router run SPF by hand over a five-router area, and what happens when two paths tie on cost?

level: middleimportance: must knowfreq 32%

basics

~20 s

OSPF's SPF moves the cheapest tentative vertex from a candidate list onto the shortest-path tree, then updates its neighbours' totals. Equal-cost totals merge their next hops instead of picking one, and stub networks are attached as leaves at the end.

open as a page

When a link fails in an OSPF network, what steps make up the time until traffic takes a new path, and which usually dominates?

level: seniorimportance: must knowfreq 34%

basics

~20 s

OSPF convergence is detection, LSA origination, flooding, SPF and route install. Detection usually dominates: lost carrier is noticed at once, but a failure hidden behind a switch waits for the Dead interval, 40 s with RFC 2328's sample timers.

open as a page

Why did OSPFv3 take IPv6 prefixes out of router-LSAs and network-LSAs and put them in Intra-Area-Prefix-LSAs, and what does that buy?

level: seniorimportance: must knowfreq 20%

basics

~20 s

RFC 5340 made router- and network-LSAs pure topology and moved every prefix into Intra-Area-Prefix-LSAs that point at a router or transit link. A prefix change then leaves the SPF graph untouched, and the topology LSAs become address-family independent.

open as a page

In OSPF, what do Hello packets do, and how do the Hello and Dead intervals decide that a neighbour has gone?

level: juniorimportance: should knowfreq 42%

basics

~20 s

OSPF Hellos, sent every HelloInterval, discover neighbours, prove two-way communication and carry DR election data. Each Hello received restarts that neighbour's RouterDeadInterval timer; if the timer expires with no Hello heard, the neighbour is declared Down.

open as a page

What is OSPFv3, and what changed from OSPFv2 when OSPF was redesigned to route IPv6?

level: juniorimportance: should knowfreq 26%

basics

~20 s

OSPFv3 (RFC 5340) is OSPF for IPv6. It keeps OSPFv2's flooding, areas, neighbour states and SPF, but strips addresses from its headers and topology LSAs, runs per link, adds Link and Intra-Area-Prefix LSAs, and drops built-in authentication.

open as a page

On an OSPF broadcast LAN, why do some neighbours stay in 2-Way while others reach Full, and how many adjacencies does that save?

level: middleimportance: should knowfreq 27%

basics

~20 s

On broadcast and NBMA networks, OSPF routers become adjacent only with the DR and BDR, so other pairs stop at 2-Way by design: 2n − 3 adjacencies instead of n(n − 1)/2, or 17 instead of 45 for ten routers.

open as a page

Two OSPF routers on one Ethernet segment never become neighbours; which parameters must agree, and where does OSPF check each one?

level: middleimportance: should knowfreq 38%

basics

~20 s

OSPF silently drops a Hello whose area ID, authentication, Hello or Dead interval, network mask (on broadcast and NBMA links) or stub-area E-bit disagrees with the receiving interface, so neither router even reaches Init. Interface MTU is checked later, in Database Description packets.

open as a page

In OSPF, what do stub, totally stubby and not-so-stubby (NSSA) areas each block, and what default route does each receive?

level: middleimportance: should knowfreq 35%

basics

~20 s

Stub areas block type 5 and 4 LSAs and get a type 3 default; totally stubby, an implementation option, also blocks other type 3s. An NSSA blocks 5 and 4, carries local externals as type 7, and gets a type 7 or 3 default.

open as a page

How are OSPFv3 packets authenticated, given that RFC 5340 removed the authentication fields from the OSPF header?

level: middleimportance: should knowfreq 14%

basics

~20 s

OSPFv3 has no authentication of its own. RFC 4552 protects it with IPsec, ESP required and AH optional, using manually configured keys; RFC 7166 adds an HMAC Authentication Trailer appended to each packet, with a 64-bit sequence number against replay.

open as a page

Two OSPF routers list each other as neighbours but never get past ExStart or Exchange; what usually causes this, and how do you confirm it?

level: seniorimportance: should knowfreq 30%

basics

~20 s

Usually an interface MTU mismatch: each OSPF Database Description packet carries its sender's interface MTU, and a router rejects one advertising more than it can receive, so the exchange never completes. Duplicate Router IDs and dropped unicast OSPF packets are the other suspects.

open as a page

In OSPF, an ASBR inside area 1 redistributes 198.51.100.0/24; which LSAs carry it to a router in area 2, and what changes if area 1 is an NSSA?

level: seniorimportance: should knowfreq 22%

basics

~20 s

The ASBR's type 5 floods unchanged into area 2, while ABRs originate type 4 LSAs so area 2 can reach that ASBR. In an NSSA the ASBR originates a type 7, and a translating ABR originates the type 5 itself.

open as a page

In OSPF, where can routes be summarised, why only there, and how does a summarising ABR keep traffic for unused addresses from looping?

level: seniorimportance: should knowfreq 28%

basics

~20 s

OSPF summarises only at borders: ABRs advertise configured area ranges as type 3 LSAs, and ASBRs or NSSA translators aggregate externals. Inside an area every router needs the full topology. A discard entry per active range drops unmatched traffic instead of looping it.

open as a page

Before maintenance on an OSPF router, how do you move transit traffic off it without dropping packets, and why not simply shut OSPF down?

level: seniorimportance: should knowfreq 20%

basics

~20 s

Cost the OSPF router out first: reoriginate its router-LSA with every transit link at the maximum cost, 0xffff (RFC 6987 stub router advertisement), let traffic reconverge around it, then work. A hard shutdown drops traffic until the area reconverges.

open as a page

How does OSPF graceful restart (RFC 3623) keep traffic flowing while a router's OSPF software restarts, and what ends it early?

level: seniorimportance: should knowfreq 15%

basics

~20 s

In OSPF graceful restart, the restarting router announces a grace period in link-local grace-LSAs and keeps forwarding on its preserved table; helper neighbours keep advertising it as fully adjacent until it resynchronises, the period expires or the topology changes.

open as a page

When an OSPF router installs a changed LSA, which changes force a full SPF run and which allow a cheaper recalculation?

level: seniorimportance: should knowfreq 18%

basics

~20 s

Under RFC 2328, a changed router-LSA or network-LSA forces a full recalculation that includes SPF for every attached area. A changed summary-LSA or AS-external-LSA normally recomputes just its destination. Incremental SPF, which repairs part of the tree, is an implementation feature.

open as a page

Why do OSPF routers delay and throttle SPF runs, and how does an initial delay with back-off batch a flapping link's updates?

level: seniorimportance: should knowfreq 24%

basics

~20 s

One failure produces several LSAs and a flapping link a stream of them. SPF throttling waits briefly so related changes go into one run, then backs off while churn continues. RFC 8405 standardises one such back-off for link-state IGPs.

open as a page

How does OSPFv3 route IPv4 prefixes using RFC 5838 address families, and why must IPv6 still be enabled on every link that carries them?

level: seniorimportance: nice to knowfreq 7%

basics

~20 s

RFC 5838 maps each address family to its own OSPFv3 instance by Instance ID, 64 to 95 for IPv4 unicast. IPv4 prefixes ride in the existing LSAs, but the protocol's packets still travel between IPv6 link-local addresses.

open as a page

showing 1–30 of 32