Networking · Concept · 12 min read

The IS-IS Protocol, and Why It Runs the Networks You Never See

The concept is the same as OSPF and every difference is structural. One of them changes how a network is designed, and one of them is the reason carriers never looked back.

Written by Marko Ristic, Editor Updated Sep 23, 2026
2Levels, where OSPF has numbered areas and a mandatory area zero
1Process carrying both address families, against two for OSPF
0IP ports it listens on, which is why it cannot be reached over IP
63The old metric ceiling, and the reason wide metrics exist
Short answer

IS-IS is a link state routing protocol: every router holds an identical map of the network and runs Dijkstra on it, exactly as OSPF does. It runs directly on the link layer rather than on IP, and divides the network into levels with the boundary on a link.

  • Link state, so every router computes its own routes from the same map
  • Runs on the link layer, not on IP, so addressing errors do not stop it
  • One process carries IPv4 and IPv6, where OSPF needs two protocols
  • The area boundary falls on a link, not inside a router
  • Carriers run it, enterprises run OSPF, and both work
On this page

Every link state routing protocol works the same way, and the value is in what that produces.

Each router describes its own links. A router builds a description of everything directly attached to it, called a link state PDU in this routing protocol, and floods that packet to its neighbors.

Every router on the network collects every description. Flooding continues until every router in the area holds an identical topology database of every other router's links, and the same happens at level 2 across the routing domain. No routing information is summarized or believed second hand.

Each router computes its own routes. With a complete topology, every router runs Dijkstra's algorithm independently, produces the same shortest path tree, and installs the resulting routes in its routing table.

Two routers with the same database pick the same path to every destination, so a route that appears on one appears on all of them. There is no equivalent of a distance vector protocol like RIP trusting a neighbor's arithmetic about a path it cannot see.

That is exactly what OSPF does too, and it is what separates both from the distance vector protocols. Everything distinctive about the IS-IS protocol is in how it carries the routing information rather than in what it does with it.

Not on IPThe thing that makes it different: it does not use IP

IS-IS was designed for the OSI protocol suite, not for IP, and it still runs directly on the data link layer using connectionless network service rather than inside IP packets. Support for IP routing was added later, by defining new fields inside the protocol's own messages.

The standards are worth naming, because the vocabulary comes from them. The protocol itself is ISO 10589. RFC 1195 is the document that added IP to it, and it describes itself as an integrated routing protocol based on the OSI Intra-Domain IS-IS Routing Protocol.

That same RFC says IS-IS is designed to work with ISO 8473, the ISO connectionless network layer protocol, and with ISO 9542, the end system to intermediate system protocol. Those two numbers are where CLNS and the ES-IS hellos on a router come from.

Three consequences follow, and they are the whole argument for the protocol.

The routing protocol works when IP addressing does not. Neighbors form adjacencies without needing correct IP addresses on the interface between them, so the routing comes up and the routes appear even where the addressing is wrong. On a network where addressing errors are the usual cause of trouble, that is a genuine operational advantage.

Adding an address family means adding fields, not a protocol. IS-IS carries its routing information in type-length-value structures inside the same packets, and supporting IPv6 meant defining new TLVs. OSPF needed an entirely separate protocol, OSPFv3, to do the same thing. One IS-IS process produces routes for both families from one topology.

It cannot be attacked over IP. A routing protocol that does not listen on any IP port is not reachable from anywhere that is not directly attached at layer two. That is a meaningful reduction in exposure for a carrier backbone.

The cost of all this is unfamiliarity, and it starts with the name. An intermediate system is a router and an end system is a host, which is OSI terminology nobody else uses.

Router identity is a NET address in NSAP format, an OSI addressing scheme that looks nothing like an IP address and that appears nowhere else. Configuring your first intermediate system is a strange experience, and it is most of why the protocol has a reputation for being difficult.

LevelsLevels, and the boundary that sits on a router

IS-IS divides a network into two levels, and the distinction from OSPF areas is subtle and consequential.

Level 1 is routing inside an area. A level 1 router knows the topology of its own area and nothing beyond it, so its routing table holds a default route pointing at the nearest level 1-2 router for everything else.

Level 2 is the routing between areas. Level 2 routers form a contiguous backbone and hold the routes and the paths to reach every other area in the routing domain.

Level 1-2 routers do both, holding two separate topology databases and running Dijkstra twice, once against each.

The structural difference is where the boundary falls. In OSPF, an area border router has some interfaces in one area and some in another, so the boundary runs through the router and every link belongs to exactly one area.

In IS-IS, a router belongs to exactly one area and the boundary falls on the link between two routers in different areas.

That sounds like a detail and it changes how a network is designed. An IS-IS area is a set of routers, so growing or splitting an area means moving routers rather than renumbering interfaces, and the level 2 backbone is a set of routers that happen to be adjacent rather than a specifically numbered area zero that every other area must touch.

The packetsThe four packets it sends

Everything the protocol does is carried by four kinds of packet, and each kind exists at level 1 and at level 2. Naming the packet that is missing is most of what troubleshooting this routing protocol amounts to.

IS-IS Hello packets build and hold adjacencies. One goes out of every enabled interface, and the adjacency drops when they stop arriving. RFC 1195 says each IS-IS Hello carries the IP addresses of the interface it is sent over, and the list of protocols the router supports.

Link state PDUs carry the topology. An LSP is one router's description of its own links and its own reachable prefixes, flooded unchanged through the level until every router in the routing domain holds the same set of LSPs. The topology database is nothing but those packets.

LSPs are the rough equivalent of the OSPF LSA types, gathered into one packet per router rather than issued separately for each kind of information.

A level 1 router floods level 1 LSPs inside its own area, a level 2 router floods level 2 LSPs across the backbone, and a level 1-2 router holds both sets.

Complete sequence number PDUs summarize the database. A CSNP lists every LSP a router holds, by identifier and sequence number, so a neighbor can compare that list against its own and see which packets it is missing.

Partial sequence number PDUs close the gaps. A PSNP asks for a specific LSP that a CSNP showed as missing, and on a point to point link it also acknowledges an LSP that arrived. RFC 1195 defines both sequence number packets separately for level 1 and level 2.

On a broadcast segment the protocol elects a designated intermediate system. The DIS originates a pseudonode LSP that stands for the LAN itself, so every router on that segment describes one adjacency to the pseudonode rather than one adjacency to each neighbor, and it sends the periodic CSNPs.

There is no backup DIS. If it disappears another router takes the role, and a router with a better priority preempts and takes it back. OSPF does the opposite on both counts, with a backup designated router and no preemption, which changes how a segment behaves after a failure.

That is why an IS-IS fault is usually named by a packet. No hellos means no adjacency and nothing after it can happen. Adjacencies without LSPs means the topology database stays empty. A full database with routes missing points at the levels rather than at the flooding.

Who runs itWhy service providers chose it and enterprises did not

The split is almost total: carriers run IS-IS, enterprises run OSPF, and both work.

Scale in one area. IS-IS carries less overhead per router in the topology database and floods its link state packets more efficiently, so a single area holds more routers comfortably. Where the usual guidance for OSPF is a rough ceiling around a hundred routers per area, IS-IS is routinely run with more.

One protocol for both address families. A carrier running IPv4 and IPv6 has one IS-IS process, one set of adjacencies and one topology producing both sets of routes, rather than two routing protocols side by side.

MPLS came from that world. Traffic engineering extensions arrived in IS-IS early and the large networks deploying MPLS were already running it, which turned a preference into a standard.

It never had to carry the internet routing table. An IGP in a carrier network carries the provider's own links and nothing else, while BGP carries the several hundred thousand routes of the internet on top of it.

Keeping the two jobs apart is why the IGP can stay small and fast, and IS-IS scaling well inside that small job is exactly what a carrier needs from it. An enterprise usually has no BGP at all, so its IGP is the whole routing table and the scaling argument never arrives.

Enterprise gear and enterprise engineers know OSPF. Every vendor implements it, every certification teaches it, and every engineer has configured it. For a network of thirty routers, that familiarity is worth more than any of the advantages above, whatever the routing protocols do on paper.

The honest summary is that for an enterprise network the choice between the two routing protocols does not matter much, and OSPF wins on people. For a carrier backbone the scale and address family arguments are real, and the industry settled accordingly.

PitfallsWhere people go wrong

Expecting an IP address to identify the router. Identity is a NET address in NSAP format. It does not come from the interface addresses, it does not look like an IP address, and the format has to be understood before the first configuration works.

Assuming areas work like OSPF areas. The boundary is on the link, not in the router. A design translated directly from OSPF thinking will not be the design you meant.

Forgetting the level 2 backbone must be contiguous. As with OSPF area zero, a partitioned backbone breaks routing between areas and the routes simply disappear from the routing table. The rule is the same and the shape is different.

Ignoring the MTU. The IS-IS protocol pads its hello packets to the full interface MTU by default, so an MTU mismatch between two routers stops the adjacency from forming while everything else on the link works perfectly. No adjacency means no routing information and no routes. This is a classic and it is worth checking first.

Running it in an enterprise because it is technically better. It is a fine routing protocol, and the engineers who will maintain the network know OSPF. That usually decides it, and it should.

Treating the wide metric as optional. The original metric field is six bits, which caps a link at 63. Modern deployments enable wide metrics, and a network that has not is choosing between paths with almost no resolution to distinguish them.

THE ONE STRUCTURAL DIFFERENCE: WHERE THE AREA BOUNDARY FALLSIS-IS: THE BOUNDARY IS ON THE LINKevery router in one areaarea 49.0001area 49.0002OSPF: THE BOUNDARY IS IN A ROUTERone router in both areasarea 1area 0SO AN IS-IS AREA IS A SET OF ROUTERS, AND AN OSPF AREA IS A SET OF LINKSResizing one means moving routers. Resizing the other means renumbering interfaces.Everything else is nearly the same: both are link state, both run Dijkstra, both hold one database.The real differences are that IS-IS does not run on IP, and that one process carries IPv4 and IPv6.
One dashed line falls between two routers and the other falls through one. That is the difference that shows up in a design rather than in a specification.

ComparisonTwo link state protocols, and the row that decides most networks

CriterionIS-ISOSPF
FamilyLink stateLink state
AlgorithmDijkstraDijkstra
Runs onThe link layer, CLNSInside IP, protocol 89
Router identityA NET address, NSAP formatA router ID that looks like an IP address
HierarchyLevel 1 and level 2Areas, with area 0 as backbone
Area boundaryOn the linkInside the router
IPv6New TLVs, one processA separate protocol, OSPFv3
Routers per areaMore, comfortablyAround a hundred as guidance
Who runs itService providersAlmost every enterprise
Engineers who know itFewEffectively all of them

The last row decides more networks than every other row combined, and that is not an unreasonable way to choose a routing protocol.

FAQFrequently asked questions

What is the IS-IS protocol?

Intermediate System to Intermediate System, a link state routing protocol in which every router builds an identical map of the network topology and computes its own shortest path routes with Dijkstra's algorithm.

Is IS-IS a link state protocol?

Yes, in the same family as OSPF and unlike the distance vector protocols. Routers flood descriptions of their own links until everyone holds the same topology database, then each computes its routes independently.

What is the difference between the IS-IS protocol and OSPF?

The concept is identical and both are link state routing protocols. IS-IS runs directly on the link layer rather than inside IP, uses levels rather than areas with the boundary on the link, and supports IPv6 by adding fields rather than by adding a second protocol.

Why does IS-IS not run over IP?

Because it was designed for the OSI protocol suite. IP support was added inside its existing message format, which is why the protocol itself never depended on IP being configured correctly.

What is a NET address?

The Network Entity Title, the router's identity in this protocol, written in the NSAP format that comes from OSI addressing. It is not an IP address and looks nothing like one.

What are level 1 and level 2?

Level 1 is routing within an area, level 2 is the backbone between areas, and a level 1-2 router does both with two separate databases.

Where is the area boundary in IS-IS?

On the link between two routers in different areas. Each router belongs to exactly one area, unlike OSPF where a border router has interfaces in more than one.

Why do service providers prefer IS-IS?

More routers per area, one process for IPv4 and IPv6, early traffic engineering extensions for MPLS, and the fact that the large networks deploying MPLS were already running it.

Should an enterprise use IS-IS?

Usually not. OSPF does the same job, every engineer knows it, and every vendor implements it. The advantages of IS-IS start to matter at a scale most enterprises never reach.

What does intermediate system mean?

A router. IS-IS comes from OSI terminology, where an intermediate system forwards traffic and an end system is a host, so the name means router to router routing.

Is IS-IS an alternative to BGP?

No. IS-IS is an interior gateway protocol carrying a provider's own links, and BGP is what carries routes between organizations. Carrier networks run both, doing different jobs.

Does IS-IS support IPv6?

Yes, through additional TLVs in the same protocol, so one process and one set of adjacencies carry both address families.

Why will my adjacency not come up?

Check the interface MTU first. IS-IS pads its hellos to the full MTU, so a mismatch between two routers prevents the adjacency and nothing appears in the routing table, while everything else on that link works normally.

What are wide metrics?

An extension replacing the original six bit metric, which capped a link cost at 63. Enable them, because without wide metrics there is almost no resolution between paths.

Is IS-IS more secure than OSPF?

It is less exposed, because it does not listen on IP and cannot be reached from anywhere that is not directly attached at layer two. Both support authentication and both should have it enabled.

Where is ISIS routing used?

ISIS routing is most common inside service provider and large data center networks, where it carries the internal topology underneath BGP and MPLS. Enterprises more often run OSPF. IS-IS scales well in a single large area and handles IPv4 and IPv6 in one process.

Read next · Routing What Is BGP? The other protocol in every carrier network, doing the job an interior protocol deliberately does not. Open this next12 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.