4.4.1. Neighbor Adjacencies
OSPF routers are paranoid—they won't trust a router and share their link-state database until they've verified that router is legitimate and compatible. This verification process creates a neighbor relationship that progresses through several states before reaching full adjacency.
Why neighbors matter: If routers can't become neighbors, they can't exchange routes. Neighbor issues are the #1 OSPF troubleshooting problem. When OSPF "isn't working," the first command is always show ip ospf neighbor.
Neighbor Requirements (ALL must match):
- Area ID: Both routers must be in the same OSPF area
- Hello/Dead intervals: Must match exactly (default: 10/40 seconds on broadcast networks)
- Authentication: If enabled, both sides need the same password
- Subnet: Routers must be on the same IP subnet
- MTU: Mismatched MTU prevents reaching FULL state (this one's sneaky)
Do not need to match: the OSPF process ID (locally significant) and interface bandwidth or cost. The Router ID must be different on each router; a duplicate is an error.
What happens when requirements don't match: A mismatched area, subnet, hello/dead timer or authentication setting makes the router discard the neighbor's hellos, so the neighbor never appears in show ip ospf neighbor at all. Init means hellos are arriving in one direction only, typically because an ACL or filter on one side drops the OSPF hellos sent to multicast 224.0.0.5. Mismatched MTU = stuck in ExStart/Exchange. The state tells you where to look.
Adjacency Formation States:
| State | What's Happening | Troubleshooting Hint |
|---|---|---|
| Down | No Hello received | Check Layer 1/2, ACLs blocking OSPF |
| Init | Hello received but not bidirectional | One-way hellos, e.g. an ACL on one side dropping OSPF multicast |
| 2-Way | Bidirectional communication confirmed | DR/BDR election happens here |
| ExStart | Master/slave negotiation for DB exchange | MTU mismatch stops progress here |
| Exchange | Database Description packets exchanged | Still checking MTU |
| Loading | Requesting missing LSAs | Almost there |
| Full | Databases synchronized | Normal operating state |
⚠️ Exam Trap: On broadcast/multi-access networks, not all neighbors reach FULL state. Non-DR/BDR routers (DROthers) stay in 2-Way with each other—that's normal. They only form FULL adjacency with the DR and BDR.
When an established neighbor is lost: every Hello received from a neighbor resets its dead timer. If no Hello arrives for a whole dead interval (40 seconds by default on broadcast links), the router drops the neighbor to Down and logs %OSPF-5-ADJCHG ... Neighbor Down: Dead timer expired. The reason text matters: dead-timer expiry means the neighbor's Hellos stopped arriving, whereas an interface going down or a configuration change on the local router is logged with a different reason.