If I had to pick one interior routing protocol to teach someone first, it would be OSPF. It’s an open standard, it’s used everywhere from small enterprise networks to massive service-provider cores, and understanding it properly — the link-state database, the SPF algorithm, the area design — gives you a mental model that carries over to almost every other routing technology you’ll touch afterward.
Let me walk through the fundamentals, the actual configuration, and the area design decisions that tend to separate a network that scales well from one that doesn’t.
What OSPF Is
Open Shortest Path First is a link-state interior gateway protocol standardized by the IETF (RFC 2328 for OSPFv2/IPv4, RFC 5340 for OSPFv3/IPv6). Instead of routers exchanging distance-vector-style “here’s what I know” summaries, every OSPF router builds an identical map — the link-state database (LSDB) — of the entire area’s topology, and then independently runs Dijkstra’s Shortest Path First algorithm against that map to calculate the best routes.
Fundamentals
- Link-state vs distance-vector: link-state protocols like OSPF give every router a full topological map; distance-vector protocols only exchange reachability and metric info between direct neighbors.
- Areas: OSPF divides a network into areas to control LSDB size and limit the scope of SPF recalculation. Area 0 (the backbone) is mandatory in any multi-area design, and all other areas must connect to it, directly or via a virtual link.
- Router ID: a 32-bit value (formatted like an IP address) uniquely identifying each OSPF router, either manually set or auto-derived from the highest loopback or interface IP.
- Cost metric: OSPF cost is derived from
reference-bandwidth / interface-bandwidth, meaning faster interfaces get a lower (better) cost by default.
How OSPF Operates
- Routers discover neighbors via multicast Hello packets (224.0.0.5) and form adjacencies if area ID, hello/dead timers, authentication, and subnet/MTU match.
- Once adjacent, routers exchange their full LSDB via Database Description, Link State Request, and Link State Update packets.
- Every router in an area ends up with an identical LSDB for that area.
- Each router independently runs SPF (Dijkstra’s algorithm) against that LSDB to build its own shortest-path tree, then installs the best routes into the routing table.
- Multi-area designs use Area Border Routers (ABRs) to summarize and pass routing information between areas, and Autonomous System Boundary Routers (ASBRs) to inject routes from other protocols (redistribution) into OSPF.
Basic Single-Area OSPF Configuration
R1:
R1(config)# router ospf 1
R1(config-router)# router-id 1.1.1.1
R1(config-router)# network 192.168.1.0 0.0.0.255 area 0
R1(config-router)# network 10.0.0.0 0.0.0.3 area 0
R2:
R2(config)# router ospf 1
R2(config-router)# router-id 2.2.2.2
R2(config-router)# network 192.168.2.0 0.0.0.255 area 0
R2(config-router)# network 10.0.0.0 0.0.0.3 area 0
Note that the “1” in router ospf 1 is just a locally significant process ID — it doesn’t need to match between routers the way an EIGRP AS number does. What must match is the area number for interfaces that need to be neighbors.
Verifying OSPF
R1# show ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
2.2.2.2 1 FULL/BDR 00:00:38 10.0.0.2 GigabitEthernet0/0
R1# show ip route ospf
O 192.168.2.0/24 [110/2] via 10.0.0.2, 00:07:12, GigabitEthernet0/0
R1# show ip ospf database
OSPF Router with ID (1.1.1.1) (Process ID 1)
Router Link States (Area 0)
Link ID ADV Router Age Seq# Checksum Link count
1.1.1.1 1.1.1.1 542 0x80000003 0x00a1c4 2
2.2.2.2 2.2.2.2 538 0x80000003 0x00f2e1 2
The neighbor state FULL/BDR tells you two things: the adjacency is fully synchronized (FULL), and this neighbor is the Backup Designated Router (BDR) on that segment.
Designated Router and Backup Designated Router
On multi-access segments (like Ethernet), OSPF elects a Designated Router (DR) and Backup Designated Router (BDR) to reduce the number of adjacencies needed — instead of every router forming a full adjacency with every other router, everyone forms adjacencies only with the DR and BDR. Election is based on OSPF priority (default 1, highest wins; 0 means “never a candidate”), with router ID as tiebreaker.
R1(config-if)# ip ospf priority 200
I use this to deterministically control DR/BDR election on important segments rather than leaving it to router ID tiebreaking, which is rarely what you’d actually choose intentionally.
Multi-Area Design
Here’s a three-router topology with R2 as an ABR connecting Area 0 and Area 1:
! R1 - Area 0 only
R1(config)# router ospf 1
R1(config-router)# network 10.0.0.0 0.0.0.3 area 0
! R2 - ABR between Area 0 and Area 1
R2(config)# router ospf 1
R2(config-router)# network 10.0.0.0 0.0.0.3 area 0
R2(config-router)# network 172.16.0.0 0.0.0.3 area 1
! R3 - Area 1 only
R3(config)# router ospf 1
R3(config-router)# network 172.16.0.0 0.0.0.3 area 1
R3(config-router)# network 192.168.3.0 0.0.0.255 area 1
Stub and Totally Stubby Areas
For branch or edge areas that don’t need full external route visibility, stub areas reduce LSDB size and SPF workload significantly:
! On the ABR
R2(config-router)# area 1 stub
! On the internal router within the stub area
R3(config-router)# area 1 stub
For an even smaller LSDB, a totally stubby area (Cisco-specific) also suppresses inter-area routes, replacing them with a single default route from the ABR:
R2(config-router)# area 1 stub no-summary
I use totally stubby areas constantly for branch office designs — there’s no operational reason for a small branch router to carry the entire enterprise routing table when a default route does the job.
Route Summarization
At an ABR, summarizing routes between areas keeps the LSDB smaller and limits the blast radius of a flapping route:
R2(config-router)# area 1 range 192.168.3.0 255.255.255.0
Securing OSPF
I authenticate every OSPF adjacency in production. MD5 authentication per-area:
R1(config-router)# area 0 authentication message-digest
R1(config-if)# ip ospf message-digest-key 1 md5 MyOspfKey654
Common Configuration Mistakes
- Mismatched area numbers on a shared segment — adjacency never forms, and the log will show an area mismatch error if you check
debug ip ospf adj. - MTU mismatches between neighbors, which stalls the adjacency in
EXSTART/EXCHANGEstate — a classic and often confusing failure mode. - Forgetting that Area 0 must be contiguous, or not planning virtual links when a design accidentally splits the backbone.
- Wildcard mask mistakes in
networkstatements, silently omitting an interface from the process. - Not tuning reference-bandwidth on networks with links faster than 100 Mbps — the default reference bandwidth (100 Mbps) makes anything at or above Gigabit Ethernet look identical in cost unless you adjust it:
R1(config-router)# auto-cost reference-bandwidth 10000
Troubleshooting OSPF
show ip ospf neighbor
show ip ospf interface
show ip ospf database
show ip route ospf
debug ip ospf adj
debug ip ospf events
If neighbors are stuck in EXSTART or EXCHANGE, suspect an MTU mismatch first. If they never get past INIT or 2-WAY, check hello/dead timer mismatches, area mismatches, or authentication.
Performance Tuning
- Design areas around natural summarization boundaries, not arbitrarily.
- Use stub/totally stubby areas at the network edge wherever full external visibility isn’t needed.
- Tune
auto-cost reference-bandwidthon any network with links at or above 1 Gbps to keep cost calculations meaningful. - Tighten hello/dead timers on point-to-point WAN links where faster failure detection matters, but keep them consistent across the segment.
FAQs
What’s the administrative distance of OSPF? 110.
How many areas can a router participate in? Technically unlimited, but in practice, keep ABRs focused on 2–3 areas for manageability and SPF performance.
Does OSPF support unequal-cost load balancing like EIGRP’s variance? Not natively — OSPF only installs equal-cost paths by default (maximum-paths controls how many equal-cost paths are installed, default and max vary by platform).
What’s the difference between OSPFv2 and OSPFv3? OSPFv2 supports IPv4 only; OSPFv3 was built for IPv6 (and later extended to support IPv4 as well via address families).
Summary
OSPF’s link-state model gives every router a complete, consistent view of the topology, which is exactly why it scales so well when areas are designed thoughtfully. The protocol itself is straightforward to configure — the real engineering work is in area boundaries, summarization, and stub design, which is where a well-planned OSPF network and a poorly-planned one start to look very different under load.
References
- Cisco: OSPF Configuration Guide
- IETF: RFC 2328 – OSPF Version 2
