What this note covers
Before any routing information is exchanged, two OSPF routers must
become neighbors and then form an adjacency. This happens
through Hello packets and a defined progression of states. Not every
neighbor becomes a full adjacency.
Neighbor vs adjacency — not the same thing
The distinction
- A neighbor is a router you’ve exchanged Hellos with and agreed
on parameters (reached Two-Way).- An adjacency is a neighbor with which you’ve fully synchronized
databases (reached Full).- On multi-access networks, a router forms full adjacencies only
with the DR and BDR. With other DROTHERs it stays at Two-Way —
they are neighbors, but not adjacent.
Parameters that must match to become neighbors
A mismatch in any of these blocks the adjacency
- Area ID
- Hello and Dead intervals
- Subnet / mask (must be on the same logical network)
- Authentication parameters
- Stub area flag (the E-bit)
- MTU (must match, or the process stalls in ExStart/Exchange)
These are carried in the Hello packet (except MTU, which is checked
during DBD exchange).
Router ID (RID)
How the Router ID is chosen (in order)
- Manually configured RID — always wins if set.
- Highest IP address among active loopback interfaces.
- Highest IP address among active physical interfaces.
Two things that trip people up
- The RID does not need to be reachable or even be a routable
address — it’s just a 32-bit identifier in dotted-decimal form.- The RID does not change automatically if a higher loopback
appears later. It only re-evaluates when the OSPF process is
restarted (or cleared). This is exactly why best practice is to
set it manually or dedicate a loopback.
The 8 neighbor states
Full progression
State What happens Down No Hello received yet. Router begins sending Hellos. Attempt (NBMA only) No Hello received from a manually configured neighbor, but the router keeps sending unicast Hellos to it. Init A Hello was received, but the router did not see its own RID in it — one-way only. Two-Way The router sees its own RID in the neighbor’s Hello → bidirectional confirmed. DR/BDR election happens here (on multi-access). DROTHERs stop here with each other. ExStart Master/Slave negotiation with empty DBDs. Highest RID becomes Master and controls the sequence numbers. Exchange Routers exchange DBD packets (LSDB summaries). Loading Each router sends LSR for missing/newer LSAs; neighbor replies with LSU, confirmed by LSAck. Full LSDBs synchronized → full adjacency. SPF now runs.
Why Attempt makes it 8, not 7
The “classic” CCNA list shows 7 states and omits Attempt,
because Attempt only exists on NBMA networks where neighbors are
defined manually and Hellos are unicast. On broadcast and
point-to-point links you’ll never see it. Counting it gives 8.
Master / Slave — clarification
Both routers send DBD packets. The Master (higher RID) simply
controls the DBD sequence numbering so the exchange stays ordered —
it is not the only one sending.
Troubleshooting — why an adjacency won’t form
Added — the practical checklist
When two routers refuse to become neighbors (or get stuck), check in
this order:
- Mismatched subnet/mask — interfaces not on the same network.
- Mismatched Hello/Dead timers — often from a network-type
mismatch on one side.- Mismatched Area ID.
- MTU mismatch — a classic cause of getting stuck in ExStart
or Exchange specifically.- Authentication mismatch.
- Duplicate Router IDs — two routers with the same RID cannot
form a proper adjacency.- Network-type mismatch — e.g. one side broadcast, the other
non-broadcast → different timers and DR expectations.- Passive interface — an interface set passive sends no Hellos
at all, so no neighbor forms there.A stuck state is a clue: ExStart/Exchange → suspect MTU;
Init on one side → one-way Hello, suspect ACL or unicast/multicast
issue.