We are running OSPF; we have PIX 525 protecting our server farm. OSPF process is running fine on PIX. PIX have established adjacencies with switches and routers on the same segment and show full neighbor relationships with all devices.

The problem is PIX is showing all the subnets in OSPF database received from other network devices, but no other network device is showing the IP subnets of server farms.

So, I understand you have a advertisement issue from your PIX to the rest of your network.

There are many factors that could be causing issues as this. And it really depends on your settings.

How are you advertising this routes? Are you using network ? or redistributing (connected or static)? Are you a Border-Router?

Is there any kind of routing filters? distribute-list, route-maps?


OSPF Neighbor Is Not Advertising Routes

The most common possible causes of this problem are as follows:

OSPF is not enabled on the interface that is supposed to be advertised.

The advertising interface is down.

The secondary interface is in a different area than the primary interface.

OSPF Neighbor (ABR) Not Advertising the Summary Route

The most common possible causes of this problem are as follows:

An area is configured as a totally stubby area.

An ABR is not connected to area 0.

A discontiguous area 0 exists.

OSPF Neighbor Is Not Advertising External Routes

The most common possible causes of this problem are as follows:

The area is configured as a stub or NSSA.

The NSSA ABR is not translating Type 7 into Type 5 LSA."

So,please give us more details of your network.

Hope this help,

All Interfaces belongs to same area, the advertising interface is outside, it cannot be down because all traffic is going through. I am also attaching the config of PIX for your review.

These both networks are directly connected to the PIX on layer2.

router ospf 1

network area 101

network area 101

network area 101

network area 101




I think its a security issue with the function of ASA.As u r outside interface has the lower security level then the inside for this to function i think u need to open the conduit to allow the traffic to come inside from a lower security interface to higher security interface.



no Mahmood, because PIX is getting all the external routes and the neighbors are established, it is not sending internal network out to other OSPF devices. All other traffic is fine.

See the show ospf nei output.

Neighbor ID Pri State Dead Time Address Interface 1 FULL/BDR 0:00:35 outside 1 FULL/DR 0:00:34 outside

can you please post the output of sh run | inc address

Please also note that other devices in the same area are showing PIX in there neighbor list and PIX is also showing them in its neighbor list.

Output of show run | inc adder

ip address ccsrv

ip address intf2

ip address inside

ip address outside

failover ip address ccsrv

failover ip address intf2

failover ip address inside

failover ip address outside

