cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
499
Views
0
Helpful
6
Replies

OSPF on PIX

umar-rana
Level 1
Level 1

We are running OSPF; we have PIX 525 protecting our server farm. OSPF process is running fine on PIX. PIX have established adjacencies with switches and routers on the same segment and show full neighbor relationships with all devices.

The problem is PIX is showing all the subnets in OSPF database received from other network devices, but no other network device is showing the IP subnets of server farms.

6 Replies 6

vladrac-ccna
Level 5
Level 5

hello,

So, I understand you have a advertisement issue from your PIX to the rest of your network.

There are many factors that could be causing issues as this. And it really depends on your settings.

How are you advertising this routes? Are you using network ? or redistributing (connected or static)? Are you a Border-Router?

Is there any kind of routing filters? distribute-list, route-maps?

Quoting:"

OSPF Neighbor Is Not Advertising Routes

The most common possible causes of this problem are as follows:

OSPF is not enabled on the interface that is supposed to be advertised.

The advertising interface is down.

The secondary interface is in a different area than the primary interface.

OSPF Neighbor (ABR) Not Advertising the Summary Route

The most common possible causes of this problem are as follows:

An area is configured as a totally stubby area.

An ABR is not connected to area 0.

A discontiguous area 0 exists.

OSPF Neighbor Is Not Advertising External Routes

The most common possible causes of this problem are as follows:

The area is configured as a stub or NSSA.

The NSSA ABR is not translating Type 7 into Type 5 LSA."

So,please give us more details of your network.

Hope this help,

if it does please rate this post,

Vlad

All Interfaces belongs to same area, the advertising interface is outside, it cannot be down because all traffic is going through. I am also attaching the config of PIX for your review.

These both networks are directly connected to the PIX on layer2.

router ospf 1

network 172.16.1.0 255.255.255.0 area 101

network 172.16.3.0 255.255.255.0 area 101

network 172.16.103.0 255.255.255.0 area 101

network 172.16.104.0 255.255.255.0 area 101

router-id 192.168.255.84

log-adj-changes

HI

I think its a security issue with the function of ASA.As u r outside interface has the lower security level then the inside interface.so for this to function i think u need to open the conduit to allow the traffic to come inside from a lower security interface to higher security interface.

Thanks

Mahmood

no Mahmood, because PIX is getting all the external routes and the neighbors are established, it is not sending internal network out to other OSPF devices. All other traffic is fine.

See the show ospf nei output.

Neighbor ID Pri State Dead Time Address Interface

192.168.255.83 1 FULL/BDR 0:00:35 172.16.103.249 outside

192.168.255.82 1 FULL/DR 0:00:34 172.16.103.250 outside

can you please post the output of sh run | inc address

Please also note that other devices in the same area are showing PIX in there neighbor list and PIX is also showing them in its neighbor list.

Output of show run | inc adder

ip address ccsrv 172.16.1.252 255.255.255.0

ip address intf2 172.16.104.252 255.255.255.0

ip address inside 172.16.3.252 255.255.255.0

ip address outside 172.16.103.252 255.255.255.0

failover ip address ccsrv 172.16.1.251

failover ip address intf2 172.16.104.251

failover ip address inside 172.16.3.251

failover ip address outside 172.16.103.251

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: