OSPF floods a description of every router's links to every other router, so all of them hold an identical link state database. Each then runs Dijkstra on that database with itself as the starting point and computes its own shortest paths. The databases agree and the routes differ, because each router is asking a different question.
- Nobody advertises a route: routers flood facts about their own links
- Cost comes from bandwidth, and the 100 Mbps default breaks that
- Every area must touch Area 0, and a virtual link is a repair
- Stuck in ExStart is an MTU mismatch, almost every time
- It runs on IP protocol 89, not on a TCP or UDP port
On this page
Link stateLink state, and why it differs from the alternative
Routing protocols come in two families and the difference explains everything about how OSPF behaves.
Distance vector protocols, such as RIP, tell their neighbors the answers. A router says "I can reach network X in three hops" and the neighbor believes it. No router sees the whole network, only what it was told, which makes those protocols simple, slow to converge, and prone to acting on stale information.
Link state protocols tell their neighbors the facts. An OSPF router says "these are my links, these are their costs, these are my neighbors", and that information floods unchanged to every router in the area. Nobody tells anybody a route. Every router receives every description, assembles them into one link state database, and works out its own routes from it.
That is why OSPF converges in seconds where the older protocols took minutes, and why the failure modes are different: an OSPF problem is usually a router whose database is incomplete, rather than one that was told something wrong.
The cost of the approach is memory and processing time. Every router holds the full topology of its area in its database and recomputes when it changes, and on a large flat network that becomes real work. Areas are the answer to that.
The metricHow the cost is calculated, and why it surprises people
OSPF does not count hops. It adds up cost, and cost comes from interface bandwidth by a formula: a reference bandwidth divided by the interface speed.
The default reference bandwidth is 100 Mbps, and that default is now a genuine problem on modern networks. Anything at or above 100 Mbps produces a cost of 1, so a gigabit link, a ten gigabit link and a hundred megabit link all look identical in the database.
A router will happily send data across a slow path because the arithmetic cannot see the difference.
Raising the reference bandwidth fixes it, and there are two rules. Set it high enough for the fastest link the network will ever have, and set the same value on every OSPF router. A mismatch produces routers that disagree about the cost of the same path, which produces routing that looks arbitrary.
Two other things about the metric.
Cost is per outgoing interface, so the total for a path is the sum along it, and the cost of a route can differ in each direction. Asymmetric routing inside a network is usually this.
Cost can be set manually on an interface, which overrides the calculation entirely. That is the right way to steer traffic deliberately, and it is also a thing somebody did in 2014 that nobody remembers.
AreasAreas, and the rule about Area 0
A single OSPF area works well up to perhaps fifty routers. Beyond that, the link state database every router holds becomes large, every change makes everybody recalculate, and the protocol starts costing more processing time than it delivers.
Areas divide the network. Routers inside an area hold the full detail of that area in their database and only a summary of the other networks. A change inside one area does not force a recalculation in the others, which is the whole point.
Area 0 is the backbone. Every other area must connect to it directly, and traffic between two non backbone areas always passes through it. That rule is absolute and it is where most OSPF designs go wrong: an area attached to another non backbone area does not work, and the workaround, a virtual link, is a repair rather than a design.
Routers take roles depending on where they sit.
An internal router has all its interfaces in one area and holds only that area in detail.
An area border router sits in two or more areas, holds a full database for each, and summarizes between them. This is where address summarization belongs, and doing it properly is what keeps the routing tables small.
An autonomous system boundary router connects OSPF to another routing process, usually BGP or static routes, and injects those external networks into OSPF.
Special area types exist to reduce what small areas have to hold. A stub area does not receive external routes and uses a default route instead, and a totally stubby area receives almost nothing. On a branch with one link back to the core, that is exactly right and it keeps the branch router's table tiny.
AdjacencyThe adjacency, and why it gets stuck
Two OSPF routers do not simply start exchanging databases. They move through a defined sequence of states, and knowing the sequence tells you what is wrong when the process stops.
| State | What is happening | Stuck here usually means |
|---|---|---|
| Down | Nothing heard | No hellos arriving at all |
| Init | A hello arrived, one way | The other side is not hearing yours |
| 2-Way | Both see each other | Normal on some links, and the election runs |
| ExStart | Deciding who leads the exchange | An MTU mismatch, almost always |
| Exchange | Trading database descriptions | An MTU mismatch |
| Loading | Requesting the missing pieces | Rare, usually a resource problem |
| Full | Databases match | Nothing, this is the goal |
Two rows carry most of the diagnostic value.
Stuck in Init means the hellos are one way. Your router hears theirs and they do not hear yours. An access list, a firewall, or a wrong subnet mask on the interface address.
Stuck in ExStart or Exchange means the MTU does not match. OSPF checks the MTU during the database exchange and refuses to proceed if the two ends disagree. This is by far the most common OSPF fault in the field, and it appears every time a jumbo frame setting is applied to one side of a link.
Beyond that, the parameters that must match for neighbors to form at all are the area number, the hello and dead timers, the authentication settings, and whether the area is a stub. A mismatch in any of them produces neighbors that never appear, with a log message naming the reason if anybody reads it.
PitfallsWhere people go wrong
Leaving the reference bandwidth at 100 Mbps. Every link at or above that speed costs the same, so the protocol cannot tell a gigabit path from a ten gigabit one. Raise it, and raise it identically everywhere.
Attaching an area to something other than Area 0. It does not work, and the virtual link that makes it work is a patch. Design the areas around the backbone rather than the other way round.
Running OSPF over a link with mismatched MTU. The adjacency sticks in ExStart and the logs say so. Check both interfaces before checking anything else.
Advertising an interface you did not mean to. A network statement wider than the intended address range puts OSPF on a user facing interface, where it will happily form an adjacency with anything that speaks it. Use passive interfaces by default and enable only the links that should carry the protocol.
Not authenticating. Without authentication, anything on a segment can become a neighbor and inject routes. It is a few lines of configuration and it belongs on every network you do not fully control.
Redistributing without a filter. Pushing BGP or connected networks into OSPF without controlling what goes in floods the database with routes nobody needs, and in the worst case creates a loop between the two routing processes.
Summarizing nowhere. Area border routers exist to summarize address ranges. An OSPF network with no summarization has every router holding every prefix in its database, which is the situation areas were supposed to prevent.
ComparisonOSPF, BGP and static routes, on what each one is actually designed for
| Criterion | OSPF | BGP | Static routes |
|---|---|---|---|
| Designed for | Inside one network | Between networks | Anywhere small |
| Reacts to a failure automatically | Yes | Yes | No |
| Chooses on link speed | Yes | No | No |
| Chooses on policy | No | Yes | Yes, manually |
| Scales to a million routes | No | Yes | No |
| Convergence speed | Seconds | Seconds to minutes | Instant, if correct |
| Configuration effort | Medium | High | Low, until it is not |
| Right for a two site network | Workable | No | Yes |
| Right for a campus with many links | Yes | No | No |
The first row is the whole distinction. OSPF is an interior protocol that assumes everybody is cooperating. BGP is an exterior one that assumes nobody is.
FAQFrequently asked questions
What does OSPF stand for?
Open Shortest Path First. Open because it is a published standard rather than a vendor protocol, and shortest path first after the algorithm it uses.
Is OSPF a link state or distance vector protocol?
Link state. Every router floods a description of its own links, so all routers build an identical link state database and each computes its own routes from it.
How does OSPF calculate cost?
A reference bandwidth divided by the interface speed, summed along the path. The default reference of 100 Mbps makes every modern link cost the same, so it should be raised.
What is Area 0?
The backbone area. Every other area must connect to it directly, and traffic between two other areas always passes through it.
Why is my OSPF neighbor stuck in ExStart?
An MTU mismatch on the link, almost always. OSPF compares MTU during the exchange and refuses to continue when the two ends disagree.
Why is my neighbor stuck in Init?
Hellos are arriving in one direction only. The other side is not receiving yours, usually because of an access list, a firewall, or a subnet mask mismatch.
What must match for two routers to become neighbors?
The area number, the hello and dead intervals, the authentication configuration, and the stub area flag. Any mismatch and the adjacency never forms.
What protocol number does OSPF use?
IP protocol 89. It runs directly on IP rather than over TCP or UDP, which is why a firewall rule for it names a protocol rather than a port.
How many routers fit in one OSPF area?
Around fifty is a common guideline, and it depends on the hardware and how often the network topology changes. Beyond that, split into areas.
What is an OSPF stub area?
An area that receives no external routes and uses a default route instead. It keeps the database on branch routers small, and it is right for any area with a single exit.
Should I use OSPF or BGP internally?
OSPF for a normal enterprise network. BGP internally is a data center design choice for very large fabrics, and it is a different discipline rather than an upgrade.
Does OSPF work with IPv6?
Yes, as OSPFv3, which is a separate protocol instance running alongside OSPFv2 rather than an extension of it. Both can run on the same routers at once.
What is link state routing?
In link state routing every router tells all the others about its own links, and each router builds the same map of the network and runs a shortest path calculation on it. OSPF and IS-IS work this way. Distance vector protocols instead share only their best routes with their neighbors.
What is an OSPF NSSA?
An OSPF NSSA, or not so stubby area, is a stub area that is still allowed to import external routes. It carries them as type 7 LSAs, which the area border router translates to type 5 for the rest of the network. It suits a branch that connects to a partner or to another routing protocol.
What are the OSPF LSA types?
The common OSPF LSA types are type 1, router, type 2, network, type 3, summary, type 4, ASBR summary, type 5, external, and type 7, the external type used inside a not so stubby area. Types 1 and 2 stay inside an area. The others carry routes between areas or in from outside.
Keep readingRelated concepts
Read next · Routing What Is BGP? OSPF runs inside one network where everyone cooperates. BGP runs between networks where nobody does. Open this next12 min- Diagnostics · 11 min Ping and Traceroute An OSPF recalculation shows up as a few seconds of loss, and these commands are how you see it.
- Switching · 11 min Spanning Tree Protocol Spanning tree keeps the switched layer loop free. OSPF decides routes on the layer above it.
- Routing · 10 min BGP States, and Why Only Three of the Six Ever Appear on Screen The exterior protocol, and how to read its session states.
- Routing · 11 min What Is VRF? What fills the routing table a VRF holds.
- Routing · 12 min The IS-IS Protocol, and Why It Runs the Networks You Never See The alternative, and the default in an enterprise.
- Routing · 10 min The RIP Protocol, and Why You Still Meet It What to run instead, in almost every case.
- Routing · 12 min Static vs Dynamic Routing, and the Route That Never Fails What dynamic routing looks like once you need it.
- Remote access · 10 min GRE vs IPsec, and the Reason They Are Normally Used Together The routing protocol that forced this arrangement into existence.
- Routing · 10 min Control Plane vs Data Plane, and Why the Split Matters to an Admin Where routing protocols run inside a router, and why forwarding carries on while they are busy.
- Design · 9 min Hub and Spoke Topology, and the Traffic That Goes the Long Way How the routing works once there is more than one path.
- Routing · 10 min OSPF LSA Types, Explained by Who Sends Them and How Far They Flood The advertisements the OSPF database is built from, type by type.
- Routing · 11 min EIGRP Configuration, and the Feasible Successor Logic That Makes It Work How a link-state protocol converges, compared with EIGRP’s feasible successors.