What this note covers

Three tools for shaping and scaling an OSPF domain: filtering
(controlling which routes/LSAs propagate), summarization
(collapsing many prefixes into one), and virtual links (repairing
a broken connection to area 0). These are design/manipulation
features, not core protocol mechanics.

Filtering — four mechanisms

What each one does

  • Route filtering (distribute-list)
  • Type 3 LSA filtering (inter-area prefixes)
  • Passive interface
  • Type 5 LSA filtering (external prefixes)

Route filtering (distribute-list)

Key concept — it filters the routing table, not OSPF

  • Uses a distribute-list to stop routes from being installed in
    the routing table, even though the LSAs are still in the LSDB.
  • It does not stop the OSPF process: LSAs are still flooded, the
    LSDB stays intact — only the route installation is blocked.
  • Prefixes are selected with a prefix-list, ACL, or route-map.
  • Anchors: ip prefix-list <name> seq <n> {permit|deny} <prefix>
    then distribute-list prefix <name> {in|out}.

Type 3 LSA filtering

Note

  • Must be implemented on the ABR (that’s what generates Type 3).
  • Actually filters the LSA itself between areas (unlike
    distribute-list, which only hides the route locally).
  • Direction:
    • Outbound — filter prefixes from one area out to all areas.
    • Inbound — filter prefixes from all areas into one area.
  • Anchor: area <area-id> filter-list prefix <name> {in|out}.

Passive interface

Note

  • Stops OSPF from sending Hello packets out a chosen interface,
    so no adjacency forms there — but the interface’s network is
    still advertised into OSPF.
  • Typical use: interfaces facing end users/LANs where there are no
    OSPF neighbors, to avoid wasting Hellos and to reduce attack surface.
  • Anchors: passive-interface <name>, passive-interface default,
    no passive-interface <name>.

Type 5 LSA filtering

Note

  • Controls the propagation of external (Type 5) LSAs into the
    domain, limiting which redistributed routes spread.

Summarization

Where and what

  • Configurable only on ABRs or ASBRs — the boundary points.
  • Internal summarization (ABR): collapses multiple Type 1
    LSAs into a single Type 3 advertised into other areas.
  • External summarization (ASBR): summarizes redistributed
    (external) routes as they enter OSPF.

Benefits and behaviour

  • Reduces processing (smaller LSDB, fewer SPF calculations).
  • Adds stability — a flapping specific network doesn’t ripple
    out, because only the summary is advertised.
  • The summarized network is advertised only if at least one active
    subnet within its range exists
    .
  • The cost of the summary route = the lowest cost among the
    component links that make up the summarized network.

Virtual Links

What a virtual link fixes

  • Problem: Type 3 LSAs received in a non-backbone area are not
    forwarded on to other areas — so an area with no direct
    connection to area 0
    is cut off from inter-area routing.
  • Solution: a virtual link extends area 0 across an
    intermediate area (the transit area) to reach a disconnected
    ABR.

Rules

  • A virtual link must connect to an ABR.
  • The transit area cannot be a stub area (it must carry the
    backbone traffic and full LSA types).
  • Treat it as a repair/last resort, not a design goal — a proper
    physical connection to area 0 is always preferred.
  • Anchor: area <area-id> virtual-link <router-id-neighbor>.