03-17-2014 07:33 PM - edited 03-07-2019 06:44 PM
Hi
We have 4 devices are running OSPF (3 cisco routers and 1 Juniper firewall as show in attachment file). In last few months, we got Neighbot Down message almost 1-2 times per day. Network between them interrupt for a short time and even monitoring mechanism does not aware the interruption(down time is too short). Could I have your advice of any possible root cause to this problem?
Timer intervals configured to all devices are same: Hello 10, Dead 40, Wait 40, Retransmit 5
------------------------------------------------------------------------------------------------------------
Neighbor A
Neighbor A#sh ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
172.16.255.128 1 FULL/DROTHER 00:00:34 172.16.108.11 GigabitEthernet0/11
172.16.255.130 1 FULL/DR 00:00:33 172.16.108.2 GigabitEthernet0/11
172.16.255.64 1 FULL/DROTHER 00:00:34 172.16.107.1 GigabitEthernet0/12
172.16.255.128 1 FULL/DROTHER 00:00:38 172.16.107.11 GigabitEthernet0/12
172.16.255.130 1 FULL/DR 00:00:38 172.16.107.7 GigabitEthernet0/12
Neighbor A#show log
Mar 16 06:03:33.159: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.128 on GigabitEthernet0/12 from FULL to DOWN, Neighbor Down: Dead timer expired
Mar 16 06:03:50.137: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.128 on GigabitEthernet0/12 from LOADING to FULL, Loading Done
Mar 16 21:15:05.509: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.64 on GigabitEthernet0/12 from LOADING to FULL, Loading Done
------------------------------------------------------------------------------------------------------------
Neighbor B
Neighbor B#sh ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
172.16.255.128 1 FULL/DROTHER 00:00:36 172.16.108.11 GigabitEthernet0/11
172.16.255.129 1 FULL/BDR 00:00:35 172.16.108.1 GigabitEthernet0/11
172.16.255.64 1 FULL/DROTHER 00:00:39 172.16.107.1 GigabitEthernet0/12
172.16.255.128 1 FULL/DROTHER 00:00:30 172.16.107.11 GigabitEthernet0/12
172.16.255.129 1 FULL/BDR 00:00:35 172.16.107.6 GigabitEthernet0/12
Neighbor B#show log
Mar 16 06:03:33.143: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.128 on GigabitEthernet0/12 from FULL to DOWN, Neighbor Down: Dead timer expired
Mar 16 06:03:50.122: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.128 on GigabitEthernet0/12 from LOADING to FULL, Loading Done
Mar 16 21:14:58.054: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.64 on GigabitEthernet0/12 from LOADING to FULL, Loading Done
Mar 16 21:15:03.800: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.128 on GigabitEthernet0/12 from LOADING to FULL, Loading Done
------------------------------------------------------------------------------------------------------------
Neighbor C
Neighbor C#sh ip ospf neighbor
Neighbor ID Pri State Dead Time Address Interface
172.16.255.129 1 FULL/BDR 00:00:35 172.16.108.1 FastEthernet0/1/0
172.16.255.130 1 FULL/DR 00:00:38 172.16.108.2 FastEthernet0/1/0
172.16.255.64 1 2WAY/DROTHER 00:00:30 172.16.107.1 FastEthernet0/0/1
172.16.255.129 1 FULL/BDR 00:00:35 172.16.107.6 FastEthernet0/0/1
172.16.255.130 1 FULL/DR 00:00:33 172.16.107.7 FastEthernet0/0/1
Neighbor C#show log
Mar 16 06:03:23.571: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.130 on FastEthernet0/0/1 from FULL to DOWN, Neighbor Down: Dead timer expired
Mar 16 06:03:25.479: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.129 on FastEthernet0/0/1 from FULL to DOWN, Neighbor Down: Dead timer expired
Mar 16 06:03:29.415: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.64 on FastEthernet0/0/1 from EXSTART to DOWN, Neighbor Down: Dead timer expired
Mar 16 06:03:50.112: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.129 on FastEthernet0/0/1 from LOADING to FULL, Loading Done
Mar 16 06:03:50.112: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.130 on FastEthernet0/0/1 from LOADING to FULL, Loading Done
Mar 16 21:14:53.740: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.130 on FastEthernet0/0/1 from FULL to DOWN, Neighbor Down: Dead timer expired
Mar 16 21:15:03.793: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.130 on FastEthernet0/0/1 from LOADING to FULL, Loading Done
03-17-2014 09:43 PM
How's the cpu utilization on these routers during the flap?
03-17-2014 10:55 PM
We were not monitor CPU utilization of these routers and I just put them in monitoring. The flap often happens in one minute and I am not sure if it will be monitored. I will provide monitor results after next flap.
03-18-2014 12:36 AM
How did u configure the switch between Router C and Firewall D, since you are forming all the neighbors on F0/0/1 which is between Router C and Firewall
03-18-2014 12:47 AM
On the switch between C and D, 3 ports (to C, to D and to A,B switch) were assigned with same vlan.
Following interfaces are all configured in subnet 172.16.107.0/24:
03-19-2014 07:20 PM
We have interupt this morning and CPU utilization of these routers are quite low.
CPU utilization:
Router A: 5% Router B: 5% Router C: 2%
show log:
Router A
Mar 20 01:40:17.252: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.128 on GigabitEthernet0/12 from LOADING to FULL, Loading Done
Mar 20 01:40:26.203: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.64 on GigabitEthernet0/12 from LOADING to FULL, Loading Done
Router B
Mar 20 01:40:24.597: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.128 on GigabitEthernet0/12 from LOADING to FULL, Loading Done
Router C
Mar 20 01:40:16.163: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.129 on FastEthernet0/0/1 from FULL to DOWN, Neighbor Down: Dead timer expired
Mar 20 01:40:16.179: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.64 on FastEthernet0/0/1 from LOADING to FULL, Loading Done
Mar 20 01:40:17.243: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.129 on FastEthernet0/0/1 from LOADING to FULL, Loading Done
Mar 20 01:40:24.559: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.130 on FastEthernet0/0/1 from FULL to DOWN, Neighbor Down: Dead timer expired
Mar 20 01:40:24.591: %OSPF-5-ADJCHG: Process 1, Nbr 172.16.255.130 on FastEthernet0/0/1 from LOADING to FULL, Loading Done
I am thinking to replace a switch between C and D, any advice? Thanks.
03-17-2014 10:04 PM
Hi
is there any L2 loops happening in network..
03-17-2014 10:46 PM
I think no L2 loops in the network. We have spanning tree configured on switches connecting to router A & B.
03-19-2014 08:53 PM
It looks like the adjacency on multiple interfaces are flapping. Are all these routers connected through a common switch?
03-19-2014 10:37 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide