Configure OSPF from the CLI
Learn how to configure OSPF (Open Shortest Path First) routing in the firewall using the command-line interface. You can configure a router ID and define networks and areas to establish OSPF neighbor relationships and exchange routing information.
Note
When you apply Global configuration settings through the web admin console, the firewall removes any CLI configurations that conflict with those settings.
Configure OSPF
Configure OSPF settings and define OSPF networks and areas using the following commands.
Basic OSPF settings
Enter OSPF configuration mode and configure the router ID.
-
To enter the OSPF configuration mode, enter the following options:
- For Route configuration: 3
- For Configure unicast routing: 1
You'll see the following prompt:
router# -
Run the following commands:
- Enter the router configuration mode:
router# configure terminal -
Enter the OSPF configuration mode using one of the following commands:
- OSPF:
router(config)# router ospf - OSPFv3:
router(config)# router ospf6
The command prompts show
ospf. The steps are the same for OSPFv3. - OSPF:
-
(Optional) Manually configure the router ID as follows:
router(config-ospf)#ospf router-id <number or IP address>If you don't enter a value, the firewall uses the highest interface IP address of all the configured interfaces as the router ID.
- Use the IPv4 address format, for example,
12.13.14.15. - It doesn't need to be a valid IP address in your routing domain.
- It must be unique within your routing domain.
- You can't use
0.0.0.0.
Warning
If you change the router ID, the firewall resets all OSPF sessions.
- Use the IPv4 address format, for example,
- Enter the router configuration mode:
Network address and area
Specify the network address, subnet mask, and OSPF area for route advertisement and neighbor discovery.
-
Configure the network address, netmask, and area as follows:
router(config-ospf)# network <ip-address/netmask> area <area-id>The area ID defines an area in the network. On the CLI, you can use one of the following options:
- A number from 0 to 4294967295
- IP address format, for example,
1.2.3.4
Note
OSPF is turned on for interfaces belonging to the network's subnets, and neighbor adjacencies are established.
The firewall stores the IP address based on the netmask you specify. For example, if you enter
11.11.11.11/24, it's stored as11.11.11.0/24. -
(Optional) To generate logs when a neighbor becomes available or unavailable without turning on debug mode, do as follows:
log-adjacency-changesWhen you configure OSPF from the web admin console, this command is applied by default.
-
Exit to router mode:
end
Save and exit
Verify the configuration, save the changes, and exit OSPF configuration mode.
-
Verify the OSPF configuration:
show running-configExample
Current configuration: ! frr version 10.5.1 frr defaults traditional log stdout hostname router ! router bgp 2000 bgp router-id 2.2.2.2 neighbor 172.16.16.32 remote-as 65006 ! address-family ipv4 unicast network 10.10.10.0/24 exit-address-family exit ! router ospf ospf router-id 7.6.7.6 log-adjacency-changes network 10.10.10.0/24 area 20 exit ! end -
Save the configuration:
writeThe following message appears:
Integrated configuration saved to /conf/routing/frr.confNote
You must run the
do writecommand to save route configurations made through the CLI so they reflect in the web admin console and persist on a firewall or daemon restart. -
Exit router configuration mode:
exit
Example commands
Example
Example commands are as follows:
router# configure terminal
router(config)# router ospf
router(config-ospf)# ospf router-id 12.13.14.15
router(config-ospf)# network 11.11.11.11/24 area 1000
router(config-ospf)# log-adjacency-changes
router(config-ospf)# end
router# show running-config
router# write
router# exit