Support Support Downloads Knowledge Base Juniper Support Portal Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

OSPF Neighbors with Virtual Link stuck in Exstart State



Article ID: KB9886 KB Last Updated: 24 Jun 2010Version: 2.0
Virtual Link between Juniper firewall and Cisco 6509 shows up, but OSPF neighbor stops at Exstart state on Juniper firewall and Exchange state on Cisco 6509.
In the following network topology, an OSPF neighbor relationship was created between the NS-5GT and Cisco using a virtual link. 

Area 10-----NS-5GT----VPN Area 2------ISG-2000-----Area2------Cisco---Area 0

The Cisco was stuck in the Exchange state.
The NS-5GT was stuck in the Ex-start state.
In reviewing the packet capture on the Cisco side, the Cisco was sending a DBD packet with the size of 1494 bytes.

However, the NS-5GT had the following ScreenOS command configured:
set zone "Untrust" screen block-frag
Therefore, the DBD packet sent from the Cisco, which was fragmented by the ISG2000, was dropped by the NS-5GT because of the 'block-frag' screen setting.

Disabling the 'block-frag' screen setting on the NS-5GT permitted the fragmented packet ,and then the OSPF neighbor state changed to Full.
Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search