What Is OSPF (Open Shortest Path First)?

Related problems: Traffic does not fail over to the backup link when the primary goes down; Routing changes across our sites are done by hand and get missed; Need our internal network and our provider's network to share routes

Open Shortest Path First (OSPF) is an interior routing protocol that routers within one routing domain, typically a single organization’s or provider’s network, use to share information about the links they are connected to and calculate the best path to each destination. Each router builds a map of the network from what the others report, so when a link fails or a new subnet is added, the routers update their paths automatically. OSPF is an open standard, widely supported across router and firewall vendors, and common in enterprise networks, data centers and inside service provider networks.

At a glance

  • OSPF is an interior routing protocol: it runs within a routing domain and is not used to exchange routes between networks on the public internet.
  • Each router learns the full map of its area and calculates the shortest path to every destination.
  • It reacts to link failures and changes automatically, shifting traffic to the next-best path.
  • It can use several equal-cost paths at once through ECMP.
  • Routing between autonomous systems on the internet uses BGP instead, though some MPLS and SD-WAN providers run OSPF at the customer handoff.

What problem it solves

A network with more than a few routers needs a way for each one to know where every subnet is and which path to use. Typing those routes in by hand, as static routes, works for very small networks but becomes error-prone as sites, links and subnets grow, and static routes do not react on their own when a link fails.

OSPF automates that. Routers discover their neighbors, share what they know, and recalculate when something changes. Adding a site or a backup link means configuring it locally; the rest of the network learns about it. When a primary link fails, OSPF can move traffic to a backup path without someone logging in to change routes, which is often the difference between a brief disruption and an outage that lasts until someone notices.

How it works

Neighbors. Routers on the same link discover each other with hello messages and form adjacencies. If the hellos stop, the neighbor is considered down.

Link-state database. Each router describes its own links, including their cost, and floods that description to the others in its area. Every router ends up with the same database, effectively a map of the area.

Shortest path. From that map, each router runs a shortest-path calculation (Dijkstra’s algorithm) to find the lowest-cost path to every destination. Cost is usually based on link bandwidth but can be set by hand to steer traffic.

Areas. Larger networks divide routers into areas joined to a backbone area. Routers inside an area know its details; between areas they exchange summaries. This keeps the database and recalculation manageable.

Edges of the network. OSPF often exchanges routes with other protocols at the edge, such as BGP toward the internet, or static routes for a few remote sites. Toward a managed MPLS or SD-WAN provider, the handoff may use OSPF or BGP, depending on the provider.

Routing design and monitoring are often part of a managed WAN or LAN service; see our Managed Network Services solution page.

When it matters for buyers

  • WAN and SD-WAN projects. New edge devices need to exchange routes with your internal network. Confirm which protocol they will use and who configures it.
  • Adding backup links. Redundancy depends on routing: a backup circuit only helps if routing moves traffic onto it when the primary fails.
  • Mergers and network integration. Joining two networks often means merging routing domains, which takes planning to avoid address overlaps and loops.
  • Managed services. If a provider runs your routers, ask how routing changes are requested, approved and documented.

Questions to ask vendors

  • Which routing protocol will run between our sites and your equipment, and why?
  • How are OSPF areas and link costs designed for our network?
  • How quickly does routing fail over when a link drops, and has that been tested?
  • How are routes shared between OSPF and BGP, SD-WAN or MPLS at the edge, and how are loops prevented?
  • Is OSPF authentication enabled between routers?
  • Who can change routing, and how are changes reviewed and documented?

How it differs from BGP

OSPF and Border Gateway Protocol (BGP) both share routes, but they are built for different jobs. OSPF is an interior protocol: it runs within one routing domain, assumes the routers trust each other, and picks paths by link cost to converge quickly. BGP is the exterior protocol of the internet: it exchanges routes between autonomous systems, such as a business and its internet providers, and chooses paths by policy, such as which provider to prefer. The line is not strictly organizational: some managed MPLS and SD-WAN providers run OSPF across the handoff to a customer’s network. Many organizations use OSPF internally and BGP at the edge, and a growing number use BGP internally as well, especially in data centers and SD-WAN designs.

Frequently Asked Questions

Is OSPF used on the internet?
Not to exchange routes between networks on the public internet; that is BGP's job. OSPF is an interior routing protocol, used within a routing domain. Many internet providers run OSPF, or a similar protocol, inside their own networks, and some managed MPLS and SD-WAN providers run OSPF across the handoff to a customer's network.
What is an OSPF area?
An area is a group of routers that share detailed routing information with each other. Larger networks are split into areas connected through a backbone area, which limits how much information each router has to process.
Do SD-WAN and MPLS services use OSPF?
Often, at the edge. Many SD-WAN devices and MPLS handoffs can exchange routes with a customer's internal network using OSPF or BGP. Which one is used depends on the provider and the design.
How fast does OSPF fail over?
With default timers, detecting a failed neighbor can take tens of seconds. With faster timers or a companion failure-detection protocol, many networks bring that down to around a second or less. The result depends on the design and equipment.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.