8.2 OSPFv2 Protocol Mechanics and Adjacency Formation

Key Takeaways

  • OSPFv2 is a classless link-state Interior Gateway Protocol (IGP) operating directly over IP protocol number 89, supporting Variable-Length Subnet Masking (VLSM).

  • Every OSPF router in an area maintains an identical Link-State Database (LSDB) representing the complete network graph, then executes Dijkstra's Shortest Path First (SPF) algorithm to calculate loop-free paths.

  • OSPF utilizes five distinct packet types: Hello (Type 1), Database Description (DBD, Type 2), Link-State Request (LSR, Type 3), Link-State Update (LSU, Type 4), and Link-State Acknowledgment (LSAck, Type 5).

  • Neighbor adjacency progresses through seven formal states: Down, Init, 2-Way, ExStart, Exchange, Loading, and Full.

  • For neighbors to establish an adjacency, their Area ID, primary subnet mask, Hello/Dead timers, authentication credentials, and stub flags must match identically, while their Router IDs must be unique.

Last updated: October 2026

OSPFv2 Protocol Mechanics and Adjacency Formation

Quick Summary: Open Shortest Path First version 2 (OSPFv2) is the industry-standard link-state Interior Gateway Protocol (IGP) used across enterprise campus networks. Unlike distance-vector protocols that exchange entire routing tables based on rumor, OSPF routers flood Link-State Advertisements (LSAs) to build an identical topological map of the network in their Link-State Database (LSDB). Each switch independently runs Dijkstra's Shortest Path First (SPF) algorithm against this database to calculate the lowest-cost loop-free path to every destination subnet. Establishing an OSPF adjacency requires exchanging five packet types through seven sequential states, governed by strict neighbor parameter validation.


Link-State vs. Distance-Vector Routing

Routing protocols generally fall into two primary architectural categories:

  1. Distance-Vector Protocols (e.g., RIP): Routers share their perspective of the network with immediate neighbors by periodically transmitting full routing tables ("routing by rumor"). Routers know only the distance (metric) and direction (vector/next hop) to remote destinations, without understanding the complete physical topology. This design suffers from slow convergence, counting to infinity, and routing loops.
  2. Link-State Protocols (e.g., OSPFv2, IS-IS): Every router advertises the state of its directly connected links, including IP prefixes, subnet masks, interface types, and administrative costs. These advertisements (LSAs) are flooded reliably throughout the entire routing area. As a result, every router within an area constructs an identical Link-State Database (LSDB). Each router then places itself at the root of a mathematical tree and runs the Shortest Path First (SPF) algorithm to compute the shortest path to all destinations.

OSPF Characteristics

  • Open Standard: Defined in IETF RFC 2328.
  • Protocol Encapsulation: Runs directly over IP using IP Protocol 89 (does not use TCP or UDP).
  • Classless Architecture: Carries subnet masks in route advertisements, fully supporting Variable-Length Subnet Masking (VLSM) and Classless Inter-Domain Routing (CIDR).
  • Fast Convergence: Rapidly recalculates loop-free alternate paths when link failures occur.
  • Hierarchical Area Design: Partitions large networks into distinct areas to restrict SPF recalculation domains and conserve CPU/memory resources.

The OSPF Router ID (RID)

Every OSPF router requires a unique 32-bit Router ID (RID), formatted as an IPv4 address (e.g., 1.1.1.1), to identify itself within the autonomous system. In Aruba AOS-CX, the Router ID is selected using the following operational hierarchy:

  1. Explicit Manual Configuration: An administrator manually assigns the RID under the OSPF process (router-id 10.0.0.1). This is the best-practice method because it guarantees predictable, deterministic identification.
  2. Highest Active Loopback IP Address: If no manual RID is configured, the switch selects the numerically highest IPv4 address assigned to any active loopback interface (e.g., loopback 0). Loopback interfaces are virtual software interfaces that never experience physical link flaps.
  3. Highest Active Physical/SVI IP Address: If no loopback interfaces exist, the switch selects the numerically highest IPv4 address among all operational physical routed interfaces or Switched Virtual Interfaces (SVIs).

Critical Requirement: Router IDs must be globally unique within the OSPF routing domain. If two routers share the same Router ID, neighbor adjacency will fail, or the routers will continuously overwrite each other's LSAs in the LSDB, causing severe routing instability.


The Five OSPF Packet Types

OSPF defines five discrete packet types, distinguished by the Type field in the common OSPF packet header:

Packet TypeNameDirection & DeliveryCore Function
Type 1HelloMulticast (224.0.0.5) or UnicastDiscovers neighbors, negotiates operational parameters, elects DR/BDR, and acts as a periodic keepalive.
Type 2Database Description (DBD)UnicastSummarizes local LSDB contents by listing LSA headers during initial database synchronization.
Type 3Link-State Request (LSR)UnicastRequests full, updated LSA details from a neighbor when the local router discovers missing or outdated LSAs from DBDs.
Type 4Link-State Update (LSU)Multicast (224.0.0.5 / 224.0.0.6) or UnicastCarries one or more full Link-State Advertisements (LSAs) to propagate topological information across the network.
Type 5Link-State Acknowledgment (LSAck)Multicast or UnicastReliably acknowledges receipt of LSUs, ensuring guaranteed delivery of topological updates.

The Seven OSPF Adjacency States

To synchronize link-state databases, two OSPF-enabled switches transition through seven sequential adjacency states:

  [ Down ]
     | (Transmit initial Hello)
     v
  [ Init ]
     | (Receive Hello containing local Router ID)
     v
  [ 2-Way ] -------- (DROther to DROther on Broadcast Link stops here!)
     | (Begin database synchronization)
     v
  [ ExStart ] (Elect Master/Slave; negotiate initial sequence number)
     | (Master and Slave agreed)
     v
  [ Exchange ] (Exchange DBD packets summarizing LSDBs)
     | (Determine missing or outdated LSAs)
     v
  [ Loading ] (Send LSRs; receive LSUs; return LSAcks)
     | (All requested LSAs received and verified)
     v
  [ Full ] (LSDBs are fully synchronized; routers are fully adjacent)

1. Down State

The initial state. No Hello packets have been received from the neighbor. The router initiates the discovery process by transmitting OSPF Hello packets out its enabled interfaces to the multicast address 224.0.0.5 (AllSPFRouters).

2. Init State

The router receives a Hello packet from a neighboring switch, but the receiving router's own Router ID is not present in the neighbor's list of seen neighbors. This indicates unidirectional communication (the neighbor can hear the switch, but the neighbor does not yet know the switch is listening).

3. 2-Way State

The router receives a Hello packet from the neighbor that explicitly lists the router's own Router ID in the neighbor field. Bidirectional communication is now established.

  • On multi-access broadcast networks (e.g., Ethernet VLANs), the Designated Router (DR) and Backup Designated Router (BDR) election occurs in the 2-Way state.
  • Routers that are neither DR nor BDR (DROthers) form full adjacencies only with the DR and BDR. Between two DROther routers on the same broadcast segment, the neighbor relationship remains permanently in 2-Way state (normal, expected behavior).

4. ExStart State

Routers prepare to exchange their database descriptions. Before transferring data, they establish a Master/Slave relationship and determine the initial sequence number for DBD packets:

  • The router with the numerically higher Router ID becomes the Master.
  • The Master router controls the packet sequence numbers and initiates DBD transmissions, while the Slave router responds.

Exam Troubleshooting Trap: If two neighboring routers have mismatched Maximum Transmission Unit (MTU) sizes on their interconnecting interfaces, they will become stuck in ExStart or Exchange state. The router transmitting the larger DBD packet will have its packets dropped by the neighbor whose interface MTU is smaller.

5. Exchange State

The Master and Slave exchange Database Description (DBD) packets. DBD packets do not contain complete routing information; they contain only LSA headers (LSA Type, Link State ID, Advertising Router, and Sequence Number), functioning as a summary catalog of the router's LSDB.

6. Loading State

Each router compares the received DBD headers against its own local LSDB. If a router discovers that the neighbor has newer, more up-to-date, or missing LSAs, it enters the Loading state:

  • The router sends Link-State Request (LSR) packets specifying the exact LSAs needed.
  • The neighbor responds with Link-State Update (LSU) packets containing the complete LSA data.
  • The requesting router sends a Link-State Acknowledgment (LSAck) to confirm receipt.

7. Full State

The routers have completely synchronized their Link-State Databases. Both switches possess identical topological maps of the area. Each router independently runs the Dijkstra SPF calculation to populate its routing table. Routers in this state are considered fully adjacent.


Mandatory Neighbor Adjacency Requirements

For two OSPFv2 routers to successfully transition from Down to Full adjacency, several operational parameters configured on the interconnecting link must match identically:

ParameterRequirementConsequence of Mismatch
Area IDMust match identicallyHello packet is dropped; routers remain in Down state.
Subnet MaskMust match identically (on broadcast links)Neighbors cannot verify shared IP subnet; stuck in Down or Init.
Hello & Dead TimersMust match identicallyDefault broadcast timers are 10s Hello / 40s Dead. Mismatched timers prevent adjacency.
AuthenticationMust match identicallyType (None, Simple Password, MD5/SHA) and pre-shared key must match. Packets fail authentication check.
Stub Area FlagsMust match identicallyArea options (e.g., Stub, Totally Stubby, NSSA) must agree between both routers.
Interface MTUMust match identicallyPackets pass Hello exchange, but routers become stuck in ExStart / Exchange.
Router IDMust be UNIQUEDuplicate RIDs prevent bidirectional adjacency or trigger continuous LSA flapping.

AOS-CX OSPFv2 Configuration and Verification

The following configuration activates OSPFv2 on an Aruba CX switch, assigns a deterministic Router ID, and enables OSPF on a routed uplink interface and a user SVI:

switch# configure terminal

! Step 1: Create OSPFv2 process and assign a manual Router ID
switch(config)# router ospf 1
switch(config-ospf-1)# router-id 10.0.0.1
switch(config-ospf-1)# area 0
switch(config-ospf-1)# exit

! Step 2: Enable OSPF on a Routed Core Uplink Interface
switch(config)# interface 1/1/48
switch(config-if)# description Core-Uplink-to-Agg1
switch(config-if)# no shutdown
switch(config-if)# routing
switch(config-if)# ip address 10.0.1.1/30
switch(config-if)# ip ospf 1 area 0
switch(config-if)# ip ospf cost 10
switch(config-if)# exit

! Step 3: Enable OSPF on an Access SVI (Passive Interface)
switch(config)# interface vlan 10
switch(config-if-vlan)# ip address 10.10.10.1/24
switch(config-if-vlan)# ip ospf 1 area 0
switch(config-if-vlan)# ip ospf passive
switch(config-if-vlan)# exit

Passive Interface Best Practice: The ip ospf passive command on interface vlan 10 includes the 10.10.10.0/24 subnet in OSPF LSAs so remote switches can reach user workstations, but prevents the switch from sending OSPF Hellos out user-facing ports. This hardens campus security and eliminates unnecessary multicast traffic.

Essential Verification Commands

CommandOutput and Operational Purpose
show ip ospf neighborsDisplays all OSPF neighbors, their Router IDs, operational states (Full, 2-Way), DR/BDR roles, and dead timer counters.
show ip ospf neighbors detailDisplays granular neighbor metrics including state transition counts and interface MTU values.
show ip ospf interfaceShows OSPF-enabled interfaces, process IDs, Area IDs, costs, Hello/Dead intervals, and network types.
show ip ospf databaseDisplays the summary contents of the Link-State Database (Router LSAs, Network LSAs, Summary LSAs).

Common Exam Traps

  • Stuck in 2-Way State: On a broadcast Ethernet segment, observing two neighbor switches in 2-Way/DROTHER is normal operation, not an error. DROthers do not form full adjacencies with each other; they establish Full adjacencies only with the DR and BDR.
  • Stuck in ExStart/Exchange State: The number one cause of routers stuck in ExStart or Exchange on certification exams is an interface MTU mismatch.
  • Timer Proportions: The OSPF Dead interval is four times the Hello interval by default on broadcast networks (10 seconds Hello, 40 seconds Dead). Modifying the Hello timer requires adjusting the Dead timer accordingly on both ends of the link.
  • Network Command vs. Interface Syntax: In AOS-CX, OSPF is enabled directly at the interface level (ip ospf 1 area 0), rather than using network statements under the global router configuration mode found in legacy systems.
Loading diagram...
OSPFv2 Adjacency State Machine and Packet Flow
Test Your Knowledge

A network engineer connects two Aruba CX 6300 switches over a dedicated routed point-to-point link. After configuring OSPFv2, the command 'show ip ospf neighbors' reveals that the neighbor relationship is stuck continuously in the EXSTART state. What is the most probable cause of this issue?

A

The OSPF Area ID configured on Switch A does not match the Area ID on Switch B

B

The switches have been configured with duplicate OSPF Router IDs

C

There is an MTU mismatch between the interconnecting physical interfaces

D

The OSPF Hello and Dead interval timers do not match between the two switches

Test Your Knowledge

Which set of operational parameters must match identically between two neighboring Aruba AOS-CX switches on a multi-access broadcast network to successfully establish an OSPFv2 adjacency?

A

Area ID, primary subnet and subnet mask, Hello and Dead timers, and stub area flags

B

Router ID, Area ID, OSPF priority, and reference bandwidth

C

Router ID, OSPF process ID, interface MTU, and interface cost

D

OSPF process ID, Bridge Priority, IP default gateway, and administrative distance

Test Your Knowledge

During the OSPFv2 neighbor formation process, in which state do two routers establish bidirectional communication and conduct the election of the Designated Router (DR) and Backup Designated Router (BDR)?

A

2-Way state

B

Loading state

C

Init state

D

ExStart state

Sections you finish are checked off in the contents.