LECTURE 10

Dynamic Routing

Duration: 113 min of teaching Level: bachelor, year III - no prior knowledge assumed Course: Local Area Networks Related lab: Laboratory 05 PDF: download the notes RO versiunea română

A static route is exact, predictable and never changes - including when the link it describes went down ten minutes ago. In a network with three routers you can live like that. In one with twenty, each with three exits, the number of lines to configure quickly exceeds what a person can hold in mind, and every unplugged cable calls for manual intervention. This lecture presents the protocols that maintain the routing table by themselves: how routers discover their neighbours, how they build a shared map of the network, and how each computes, for itself, the shortest paths. The emphasis falls on the link-state family and on its standard representative, OSPF.

1Recap4 min

What to keep in mind
  • A route is the triple destination, direction, distance.
  • The administrative distance says how much the router trusts the source of the route.
  • The metric says how good the route is, within the same source.
  • The decision is made by longest prefix match: the longer prefix wins, whatever the AD.
  • A static route has AD 1; a directly connected one, 0.

Today we fill the table differently. The new sources of routes - RIP, OSPF, EIGRP - each have their own administrative distance and their own metric, and the router must compare them all. The order of comparison is exactly the one from lecture 6, and it is worth having fresh in mind.

Learning outcomes

  • Explain why static routes do not scale and what exactly a dynamic protocol solves
  • Distinguish between distance-vector, link-state and path-vector
  • Describe the loop problem in distance-vector and the mechanisms that mitigate it
  • List the four steps of a link-state protocol
  • Apply Dijkstra to a small topology and obtain the shortest-path tree
  • Calculate the OSPF cost of a link and know when the formula gives wrong results
  • Explain why a DR and a BDR are elected and how the election proceeds
  • Configure single-area OSPF and troubleshoot an adjacency that will not form

2Why static routes are not enough7 min

The administrator's arithmetic

In a network with n routers, each must know the way to the others' networks. If each router has two local networks, there are roughly 2n destinations, and each of the n routers needs one line for every destination that is not its own.

For 5 routers: about 40 lines. For 20 routers: about 760. Written by hand, in both directions, without mistakes.

And every time a new network is added anywhere, all the routers must be changed.

What happens when a link fails
Static routingDynamic routing
Configuration effortgrows with the square of the sizea few lines per router, whatever the size
Reaction to faultsmanualautomatic, within seconds
Resource consumptionzeroprocessor, memory, bandwidth
Predictabilitytotaldepends on the state of the network
Securitynothing to forgethe announcements can be forged; authentication is needed
Where it is usedsmall networks, default routes, backup linksany network of medium size upwards

The two do not exclude each other. Even in an entirely OSPF network, the default route towards the provider is almost always static - because there is nobody to negotiate it with.

3The families of protocol8 min

Convergence time after a link failure

The first division concerns where they are used: inside an organisation, or between organisations.

CategoryWhereProtocols
IGP - Interior Gateway Protocolinside an autonomous systemRIP, EIGRP, OSPF, IS-IS
EGP - Exterior Gateway Protocolbetween autonomous systemsBGP
Autonomous system (AS)
A group of networks under a single administration, with a common routing policy. Each AS has a number that is unique worldwide. The Internet is, on the large scale, a network of roughly 75,000 autonomous systems announcing routes to one another through BGP.

The second division, the one that concerns us today, is about what each router knows:

FamilyWhat a router knowsProtocols
Distance-vectoronly the direction and the distance, learned from neighboursRIP, IGRP, EIGRP (hybrid)
Link-statethe complete graph of the topologyOSPF, IS-IS
Path-vectorthe complete list of autonomous systems traversedBGP
Analogy A distance-vector router is like a tourist asking passers-by: "how far is it to the station?" It gets a number and a direction, trusts them and sets off. It never sees the city.

A link-state router has the map of the city in its pocket. Every closed street is reported to it, it crosses that street off the map and recomputes its own route.

A path-vector router receives the complete itinerary: "through Sibiu, then Cluj, then Oradea". It may refuse a road because it passes through a city it does not like - and that is precisely the idea behind BGP.
Distance-vector
  • They know only the vector towards the destination
  • They send the whole routing table, periodically
  • They converge slowly
  • They consume few resources
  • They are easy to configure
  • They are vulnerable to routing loops
Link-state
  • They know the graph of the whole topology
  • They send only what changed, when it changed
  • They converge fast
  • They consume memory and processor
  • They are harder to configure and to design
  • They are immune to the classic loops, by construction
Protocol and characteristic

4Distance-vector and the problem of loops10 min

A distance-vector protocol such as RIP works on a simple principle: each router periodically sends its neighbours its entire routing table, and they add the cost of the link and decide. Nobody sees the topology; each believes what it is told. Hence the nickname that stuck to it for good: routing by rumour.

LimitationWhat it means in practice
ScalabilityRIP considers unreachable any destination more than 15 hops away - a limit that becomes real in a large network
Slow convergencea change propagates from neighbour to neighbour, at every update interval; for a diameter of 3 hops and interval K, propagation takes 3K
Local viewthe router cannot detect a loop it cannot see
Simplistic metrichop count ignores bandwidth entirely: a path over three fibre links looks worse than one over a single modem

Counting to infinity

Counting to infinity

6Dijkstra's algorithm11 min

The idea, in three sentences

We start from our own node, at distance 0. All the others have, provisionally, distance infinity.

At each step we choose the unvisited node with the smallest distance and declare it final - it cannot be reached more cheaply from anywhere. Then, through it, we try to improve the distances of its neighbours.

We repeat until the nodes run out. The result is a tree of shortest paths, with us at the root.

Dijkstra's algorithm on a seven-router topology

Choose which router does the computing and notice that the tree obtained is different for each one: every router places itself at the top. The map is the same; the tree is not.

Then change the cost of a link in the tree and watch the traffic move to another path - exactly what happens in a real network when an administrator adjusts the declared bandwidth of an interface. It is the principal instrument of traffic engineering in OSPF: you do not change the cables, you change the costs.

Worked example

A router has two paths to the same network: one over three links of cost 1 each, the other over a single link of cost 4. Which wins, and why not the hop count?

See the solution

The first path: 1 + 1 + 1 = 3. The second path: 4. The first wins, although it has three times as many hops.

The OSPF cost comes from bandwidth. Cost 1 means 100 Mbps or more; cost 4 means 25 Mbps. So: three fast links beat one slow one.

A classic distance-vector protocol, counting hops, would have chosen exactly the opposite - and would have sent all the traffic over the 25 Mbps link. This is, in two lines, why a bandwidth-based metric replaced hop counting.

7OSPF: the basic characteristics9 min

OSPF (Open Shortest Path First) was developed by the IETF from 1988 onwards, as an open alternative to the proprietary protocols of the day. OSPFv2 (RFC 2328) is the IPv4 version, OSPFv3 (RFC 5340) the IPv6 one.

CharacteristicValue
Transportdirectly over IP, protocol 89 - it uses neither TCP nor UDP
Transmission reliabilityits own acknowledgement mechanism (LSAck)
Administrative distance110
Multicast addresses224.0.0.5 (all OSPF routers), 224.0.0.6 (the DR and BDR)
Metriccost = 10⁸ / bandwidth in bps
Hello / dead timers10 s / 40 s on multi-access and point-to-point networks; 30 s / 120 s on NBMA
Authenticationoptional, with a plain password or MD5 / SHA
The OSPF cost of a link
The problem with the default formula With the default reference of 10⁸ (that is, 100 Mbps), any link of 100 Mbps or faster receives a cost of 1, because the minimum is 1.

A Fast Ethernet link and a 10 Gbps one thus become equivalent, and OSPF can no longer tell them apart. Select Gigabit with the default reference in the calculator above and you will see: cost 1. Then select the reference of 10000 and the difference reappears.

In a modern network the reference is adjusted with auto-cost reference-bandwidth 10000 - the same value on every router in the domain, otherwise the costs become incoherent and the routing unpredictable.
MediumCost with the default reference
Serial 56 kbps1785
T1 (1.544 Mbps)64
Ethernet 10 Mbps10
Fast Ethernet and faster1

8The messages and the adjacency states9 min

MessageRole
Hellodiscovers neighbours and maintains adjacencies
DBD - Database Descriptionan abbreviated list of what the link-state database contains - a kind of table of contents
LSR - Link-State Requestasks for details of an entry seen in the DBD and missing locally
LSU - Link-State Updatethe answer to an LSR; it contains one or more LSAs
LSAckacknowledges receipt of an LSU
Why the whole database is not simply sent

It would be wasteful: the two routers usually have almost the same information.

So the exchange happens in two stages: first the table of contents (DBD), then each asks only for the chapters it lacks (LSR) and receives them (LSU). It is exactly the model of an efficient file synchronisation.

StateWhat has happened
Downno Hello has been received
Initthe router has received a Hello but does not find itself in it
Two-Wayit has received a Hello in which its own Router ID appears - the neighbour can see it. On multi-access networks, this is where the DR and BDR are elected
Ex-Startit is settled who is master and who slave for the database exchange
Exchangethe DBDs are exchanged
Loadingthe missing details are requested and received (LSR, LSU)
Fullthe final state: the link-state databases are identical
The states of an adjacency, in order
Troubleshooting by the state it got stuck in An adjacency forms only if every critical parameter matches: the area number, the hello and dead intervals, the interface MTU, the stub bit and the authentication - and the Router IDs must be different.

Stuck in Init → the Hellos are not arriving in both directions: an ACL, the wrong VLAN, or a passive-interface set by mistake.
Stuck in Two-Way between two DROTHERs → normal, not a problem: on a multi-access segment, two ordinary routers do not form a full adjacency.
Stuck in Exchange or Ex-Start → almost certainly a different MTU at the two ends.
Oscillating between Full and Down → an unstable link or mismatched timers.

9DR and BDR on multi-access networks10 min

On a point-to-point link there is only one possible adjacency and no problem at all. On an Ethernet segment with n routers, if each formed an adjacency with each, there would be n(n−1)/2 relationships - 45 for ten routers, each with its own Hello messages, its own synchronisations and its own retransmissions.

The solution is centralisation: a DR (Designated Router) is elected, which receives and redistributes the updates, and a BDR (Backup DR), which takes over if the DR fails. All the other routers (DROTHER) form an adjacency only with the DR and the BDR. The number of adjacencies falls to 2(n−1).

Routers on the segmentWithout a DRWith DR and BDRSaving
510820%
10451860%
201903880%
5012259892%

The election criteria

  1. The highest priority on the interface (1 by default). The value 0 excludes the router from the election.
  2. On a tie, the highest Router ID.

The Router ID is itself determined in three steps, in strict order:

  1. the value configured by hand with router-id;
  2. the highest IP address on a loopback interface;
  3. the highest IP address on an active physical interface.
The election is not pre-emptive A new router, even with a higher priority, does not take over the DR role. If the DR fails, the BDR takes its place and a new BDR is elected from among the DROTHERs.

A practical consequence: if you want a particular router to be the DR, start it first or force a re-election with clear ip ospf process.

An even more practical consequence: use loopback interfaces for the Router ID. They never go down, so the router's identity does not change when a cable fails.
influencing the election
! the router that must be the DR
R1(config)# interface gigabitEthernet 0/0
R1(config-if)# ip ospf priority 100

! the router that must never be DR or BDR
R3(config)# interface gigabitEthernet 0/0
R3(config-if)# ip ospf priority 0

! a stable Router ID, through an interface that does not go down
R1(config)# interface loopback 0
R1(config-if)# ip address 1.1.1.1 255.255.255.255
R1(config)# router ospf 1
R1(config-router)# router-id 1.1.1.1

! the election is not pre-emptive - it must be forced
R1# clear ip ospf process

10OSPF across several areas10 min

Dijkstra runs the more slowly the larger the graph, and any change in one corner of the network forces every router to recompute everything. The scaling solution is to divide the OSPF domain into areas: each area runs Dijkstra on its own graph, and for destinations outside it merely adds the distance to the border router.

The golden rule of areas Every area must have connectivity to area 0 (the backbone). Traffic between two non-zero areas necessarily passes through the backbone.

When an area cannot be physically connected to area 0, a virtual link is configured - or, more simply and more honestly, a GRE tunnel, as in the last lecture.
Kind of routerPosition
Internal routerall its interfaces in a single area
Backbone routera router with at least one interface in area 0
ABR - Area Border Routerjoins two areas; it keeps the databases of both synchronised
ASBR - Autonomous System Border Routerintroduces external routes into OSPF, for instance by redistribution from another protocol or a default route

The types of LSA

TypeNameGenerated byWhat it describes
1Router LSAevery routerthe state of its own links, within the area
2Network LSAthe DRthe routers the DR has an adjacency with on that segment
3Summary LSAthe ABRthe routes of one area, announced to the others
4ASBR Summary LSAthe ABRhow to reach an ASBR
5External LSAthe ASBRroutes external to the OSPF domain
7NSSA Externalan ASBR in an NSSA areaexternal routes in an area that does not accept type 5

The codes in the routing table

CodeComes fromMeaning
OLSA 1 and 2a route from the same area
O IALSA 3an inter-area route
O E1 / O E2LSA 5external routes; E1 accumulates the internal cost, E2 keeps a fixed cost (20 by default)
O N1 / O N2LSA 7external routes in an NSSA area

When both an E1 and an E2 route exist to the same destination, E1 is preferred: being cumulative, it reflects the real cost of the path more faithfully. E2 is the default precisely because it is simpler - but it is also less accurate.

11Configuration and verification9 min

OSPFv2 in a single area
R1(config)# router ospf 1
R1(config-router)# router-id 1.1.1.1

! which interfaces take part - the mask is a WILDCARD, as with ACLs
R1(config-router)# network 192.168.10.0 0.0.0.255 area 0
R1(config-router)# network 10.0.0.0 0.0.0.3 area 0

! the interface facing hosts: announce the network but send no Hellos
R1(config-router)# passive-interface gigabitEthernet 0/0

! adjusting the reference - THE SAME value on every router
R1(config-router)# auto-cost reference-bandwidth 10000

! the default route to the provider, announced across the OSPF domain
R1(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.1
R1(config-router)# default-information originate
The process number is local router ospf 1 on R1 and router ospf 55 on R2 form an adjacency perfectly well. The number identifies the process on that router, not the routing domain. What must match is the area number.

passive-interface is set on any interface where there is no other router: the network stays announced in OSPF, but no pointless Hello messages are sent towards hosts - which saves bandwidth and closes an avenue of attack.
Terminal: verifying OSPF

Look at the first command: the third line shows 2WAY/DROTHER with priority 0. It is not an error - it is exactly what should happen between two ordinary routers on a multi-access segment. Only the adjacencies with the DR and BDR reach FULL.

And in the routing table the three origins can be read at a glance: O from the same area with cost 2, O IA from another area with cost 12, and O E2 external, with the fixed cost of 20 that does not change however long the internal path may be.

12Common mistakes4 min

  • "The adjacency is stuck in Exchange" The two ends have different MTUs and refuse to synchronise their databases. show ip ospf interface on both, compare the MTU. Or ip ospf mtu-ignore, as an emergency measure.
  • "The neighbours are in Two-Way and go no further" If they are two DROTHERs on a multi-access segment, this is the correct behaviour. Check who the DR is. Full adjacencies exist only with the DR and BDR.
  • "I set reference-bandwidth on one router only" The costs become incoherent: the same path has different values seen from different ends. The same value on every router in the domain. No exceptions.
  • "I used the network mask in the network command" OSPF requires a wildcard, exactly as ACLs do. network 10.0.0.0 0.0.0.3 area 0, not 255.255.255.252.
  • "I forgot passive-interface on the segments with hosts" The router sends Hellos towards users: wasted bandwidth and an open avenue of attack - anybody can start a bogus OSPF process. passive-interface default, then no passive-interface only where neighbours genuinely exist.
  • "The new router does not become DR, although it has priority 200" The election is not pre-emptive. It is not a fault. clear ip ospf process, if you really do need a re-election.
  • "I configured OSPF, but the default route does not reach the others" A static route does not enter OSPF by itself. default-information originate on the edge router.

13Summary and glossary4 min

What should stay with you
  • Static routes do not scale and do not react. A dynamic protocol solves both problems.
  • Distance-vector = rumours from neighbours; link-state = a map of one's own.
  • Counting to infinity is the fundamental problem of DV; split horizon and poison reverse mitigate it.
  • The four link-state steps: adjacencies → flooding → topology → Dijkstra.
  • A link-state router keeps three tables: neighbours, topology, routing.
  • OSPF: protocol 89, AD 110, cost = 10⁸ / bandwidth, multicast 224.0.0.5.
  • An adjacency passes through Init → Two-Way → Ex-Start → Exchange → Loading → Full.
  • DR and BDR reduce the adjacencies from n(n−1)/2 to 2(n−1); the election is not pre-emptive.
  • Every area connects to area 0.
  • In the network command, the mask is a wildcard.
IGP / EGPa protocol inside / between autonomous systems
distance-vectorknows only the direction and the distance, from neighbours
link-stateknows the complete graph of the topology
adjacencythe relationship established between two OSPF neighbours
Helloa periodic discovery and keep-alive message
LSP / LSAthe description of a router's links
floodingretransmitting an LSP to every other neighbour
topology tablethe map of the area, identical on every router
Dijkstra / SPFthe shortest-path algorithm
Router IDthe unique identifier of a router in the OSPF domain
DR / BDRthe designated router and its backup, on a multi-access segment
DROTHERa router that is neither DR nor BDR
areaa subdivision of the OSPF domain, with its own Dijkstra
ABR / ASBRan area / autonomous system border router

14Self-check questions6 min

15Further reading2 min

The next lecture leaves the wire and takes to the air: wireless networks, with their particular medium-access problems - you cannot listen and transmit at the same time, so CSMA/CD does not work - and with a security problem the wired network does not have: the medium is public by definition.

Laboratory 5 configures single-area OSPF on exactly the same topology on which you earlier wrote static routes. The comparison between the two configurations, in number of lines and in reaction to an unplugged cable, is the point of the exercise.

  • RFC 2328 - OSPF version 2
  • RFC 5340 - OSPF for IPv6
  • RFC 3630 - traffic engineering extensions for OSPF
  • RFC 2453 - RIP version 2, for comparison
  • John Moy, OSPF: Anatomy of an Internet Routing Protocol