CCNA OSPF Explained

OSPF is the biggest routing-protocol topic on the CCNA 200-301 blueprint, and the exam loves its fiddly details: what makes two routers become neighbours, how the DR is elected, how cost is calculated. This guide explains CCNA OSPF — single-area OSPF plus OSPFv3 for IPv6 — in plain, exam-focused language. When you're done, verify it stuck with a free CCNA mock test.

OSPF Fundamentals

OSPF is the link-state routing protocol the exam cares about most. Instead of gossiping about routes like distance-vector protocols, each OSPF router builds an identical link-state database describing the whole area, then independently runs the SPF (Dijkstra) algorithm to compute the shortest path to every destination. When a link changes, only the change is flooded — fast convergence, no hop-count limits, no loops.

OSPF organises networks into areas to bound that flooding: the backbone is always area 0, and every other area must touch area 0 (directly or via a virtual link). The CCNA blueprint covers single-area OSPF — everything in area 0 — so focus there. Every router needs a unique Router ID, a 32-bit number in dotted-decimal form chosen as: manually configured router-id first, else the highest loopback IP, else the highest active physical interface IP. Always set loopbacks or a manual router-id so the RID is stable and predictable.

Basic configuration uses wildcard masks (the inverse of subnet masks — /24 becomes 0.0.0.255):
router ospf 1
router-id 1.1.1.1
network 10.0.0.0 0.0.0.255 area 0
The process ID (1) is locally significant — neighbours don't need to match it, but they must share the area number. Verify with show ip ospf neighbor, show ip ospf interface brief and show ip protocols.

Key exam points

  • OSPF = link-state; every router holds the full area database and runs SPF (Dijkstra) independently.
  • Single-area design: everything in area 0. Process ID is local; area number must match.
  • Router ID: manual router-id → highest loopback → highest active interface IP. Set it deliberately.
  • network statements use wildcard masks (/24 → 0.0.0.255). Verify with show ip ospf neighbor.

OSPF Neighbourship Requirements

Two OSPF routers become neighbours (and then adjacent, exchanging full databases) only when a checklist matches on the connecting interfaces. Memorise it — "why won't these two form an adjacency?" is one of the exam's favourite troubleshooting questions. The requirements: same area number, same hello and dead timers (10 s / 40 s on broadcast and point-to-point by default), same authentication type and password (or none on both), compatible MTU (or ip ospf mtu-ignore), unique router IDs, and the same network type so subnet masks agree.

Watch the states in show ip ospf neighbor: Down → Init → 2-Way → ExStart → Exchange → Loading → Full. 2-Way means "we see each other's hellos" — a neighbour, but not yet exchanging routes. Full means the databases are synchronised. On broadcast segments, routers only go Full with the DR and BDR; with everyone else they stop at 2-Way. A neighbour stuck in ExStart/Exchange almost always means an MTU mismatch.

Two more practical points. passive-interface stops OSPF hellos on a LAN interface (good security practice) while still advertising the network — use it on every interface facing end users. And hellos are multicast to 224.0.0.5 (all OSPF routers), with DR/BDR listening on 224.0.0.6 — an ACL blocking those will silently kill adjacencies.

Key exam points

  • Adjacency checklist: same area, same hello/dead timers, same auth, matching MTU, unique RIDs.
  • States: 2-Way = neighbour; Full = databases synced. Stuck in ExStart = MTU mismatch.
  • On broadcast networks, routers go Full only with DR/BDR; 2-Way with the rest.
  • passive-interface stops hellos but keeps advertising the network — use on user-facing interfaces.

DR, BDR and OSPF Cost

On broadcast multi-access networks (Ethernet), OSPF elects a Designated Router (DR) and Backup DR (BDR) so every router doesn't have to form adjacencies with every other router — they all peer with the DR/BDR instead, and the DR generates the network LSA describing the segment. The election: highest OSPF priority wins (default 1, set with ip ospf priority), ties broken by highest router ID. A priority of 0 means never DR/BDR. Crucially, election is not preemptive: if a better router boots later, it waits until the DR or BDR fails.

On point-to-point links there is no election — just two routers, straight to Full. Set the network type explicitly with ip ospf network point-to-point on serial-style links to skip the DR/BDR process entirely.

OSPF picks paths by cost: cost = reference bandwidth ÷ interface bandwidth, with the default reference at 100 Mbps. That makes a FastEthernet link cost 1 — and a Gigabit link also cost 1 (0.1 rounds up), so by default OSPF can't tell them apart. Fix it with auto-cost reference-bandwidth 1000 (in Mbps) under the OSPF process when Gigabit+ links exist. Verify per-interface cost with show ip ospf interface, and remember the lowest total cost to the destination wins.

Key exam points

  • DR/BDR elected on broadcast networks only; highest priority wins (0 = never), ties → highest RID. Not preemptive.
  • Point-to-point links skip DR/BDR entirely.
  • Cost = reference BW (default 100 Mbps) ÷ interface BW; minimum cost is 1.
  • With default settings FastEthernet and Gigabit both cost 1 — raise with auto-cost reference-bandwidth.

Verifying Single-Area OSPF

OSPF verification is heavily tested, so build a command reflex. show ip ospf neighbor is first: you want FULL in the state column (FULL/DR, FULL/BDR or FULL/ - on point-to-point). Anything else — INIT, EXSTART, EXCHANGE, LOADING — tells you where it's stuck. show ip ospf interface brief shows each interface's area, cost, state (DR/BDR/DROTHER/P2P) and neighbour count at a glance.

show ip protocols is the configuration sanity check: it lists the process ID, router ID, networks being advertised, passive interfaces, and the AD (110). show ip route ospf filters the routing table to OSPF routes — confirm the expected networks appear with sensible next hops. For interface detail (timers, priority, DR/BDR addresses, cost), use show ip ospf interface g0/0.

Run the standard troubleshooting flow on a broken adjacency: (1) is OSPF enabled on both interfaces and in the same area? (2) do hello/dead timers, MTU and authentication match? (3) are the RIDs unique? (4) is one side passive? (5) does an ACL block 224.0.0.5? Nine times out of ten the answer is in that list.

Key exam points

  • show ip ospf neighbor: want FULL (or FULL/DR, FULL/BDR). Stuck states diagnose the fault.
  • show ip ospf interface brief: area, cost, DR/BDR state per interface at a glance.
  • show ip protocols: RID, advertised networks, passive interfaces, AD. show ip route ospf: learned routes.
  • Adjacency debug order: area → timers/auth/MTU → unique RIDs → passive-interface → ACLs on 224.0.0.5.

OSPFv3 for IPv6

OSPFv3 is OSPF for IPv6, and the concepts transfer almost one-to-one: same areas, same router IDs (still 32-bit dotted decimal, even though the addresses are 128-bit), same DR/BDR election, same cost logic, same hello/dead timers. The differences are mechanical: OSPFv3 runs per-link rather than per-subnet, so neighbours can even be in different subnets, and adjacencies form using link-local addresses — which is why every interface needs its auto-configured fe80:: address working.

Configuration differs from OSPFv2. Enable IPv6 routing globally, create the process, then enable OSPF on each interface rather than with network statements:
ipv6 unicast-routing
ipv6 router ospf 1
  router-id 1.1.1.1
interface g0/0
  ipv6 ospf 1 area 0
(Newer IOS versions use an address-family syntax under router ospfv3; the exam generally shows the classic form above.)

Verification mirrors OSPFv2 with ipv6 in the commands: show ipv6 ospf neighbor, show ipv6 ospf interface brief, show ipv6 route ospf. The adjacency checklist is identical — area, timers, MTU, authentication (now via IPsec), unique RIDs — so if you can troubleshoot OSPFv2, you can troubleshoot OSPFv3.

Key exam points

  • OSPFv3 = OSPF for IPv6; same areas, RIDs, DR/BDR, cost, timers. Router ID is still 32-bit dotted decimal.
  • Runs per-link: adjacencies use link-local addresses, so fe80:: must work.
  • Classic config: ipv6 router ospf + router-id, then ipv6 ospf 1 area 0 on each interface.
  • Verify with show ipv6 ospf neighbor; same adjacency troubleshooting checklist as OSPFv2.

Related CCNA study guides

Frequently asked questions

What are the key CCNA exam points for OSPF Fundamentals?

For the CCNA 200-301 exam, remember: OSPF = link-state; every router holds the full area database and runs SPF (Dijkstra) independently. Single-area design: everything in area 0. Process ID is local; area number must match. Router ID: manual router-id → highest loopback → highest active interface IP. Set it deliberately. network statements use wildcard masks (/24 → 0.0.0.255). Verify with show ip ospf neighbor.

What are the key CCNA exam points for OSPF Neighbourship Requirements?

For the CCNA 200-301 exam, remember: Adjacency checklist: same area, same hello/dead timers, same auth, matching MTU, unique RIDs. States: 2-Way = neighbour; Full = databases synced. Stuck in ExStart = MTU mismatch. On broadcast networks, routers go Full only with DR/BDR; 2-Way with the rest. passive-interface stops hellos but keeps advertising the network — use on user-facing interfaces.

What are the key CCNA exam points for DR, BDR and OSPF Cost?

For the CCNA 200-301 exam, remember: DR/BDR elected on broadcast networks only; highest priority wins (0 = never), ties → highest RID. Not preemptive. Point-to-point links skip DR/BDR entirely. Cost = reference BW (default 100 Mbps) ÷ interface BW; minimum cost is 1. With default settings FastEthernet and Gigabit both cost 1 — raise with auto-cost reference-bandwidth.

What are the key CCNA exam points for Verifying Single-Area OSPF?

For the CCNA 200-301 exam, remember: show ip ospf neighbor: want FULL (or FULL/DR, FULL/BDR). Stuck states diagnose the fault. show ip ospf interface brief: area, cost, DR/BDR state per interface at a glance. show ip protocols: RID, advertised networks, passive interfaces, AD. show ip route ospf: learned routes. Adjacency debug order: area → timers/auth/MTU → unique RIDs → passive-interface → ACLs on 224.0.0.5.

What are the key CCNA exam points for OSPFv3 for IPv6?

For the CCNA 200-301 exam, remember: OSPFv3 = OSPF for IPv6; same areas, RIDs, DR/BDR, cost, timers. Router ID is still 32-bit dotted decimal. Runs per-link: adjacencies use link-local addresses, so fe80:: must work. Classic config: ipv6 router ospf + router-id, then ipv6 ospf 1 area 0 on each interface. Verify with show ipv6 ospf neighbor; same adjacency troubleshooting checklist as OSPFv2.