Can OSPF run without a "true" area 0

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Can OSPF run without a "true" area 0

L0 Member

I've started working for a new company who uses only static routing. We just turned up a second ISP at one site, but I noticed an issue with failover which is expected. When ISP 1 fails, local traffic at the site routes out ISP 2, but site to site traffic doesn't failover because of the metrics on the site-to-site VPNs at the other sites.

 

At my last job we used OSPF routing, so I didn't have these issues. My problem here is that we aren't really hub and spoke to a data center, more so just spokes interconnecting sites with VPNs for communication between the sites when needed. Our traffic is mainly internet traffic.

 

Since we don't really have an area 0 to pass through, can I instead put each site network, for example 192.168.1.0, area 1, 192.168.2.0, area 2, 192.168.3.0, area 3 etc.. and have the tunnel interfaces tunnel.1, tunnel.2 tunnel.3 in area 0. Sort of the idea placing everything physical in a site based area, but the interconnecting tunnel interfaces in area 0.

 

It's a strange idea/concept, but I'm not sure how else to achieve separate areas. I could put everything in big area, but I feel like that's worse and less flexible for down the road where we might have a daca center with centralized resources.

 

I also found this option below, but it'll be a lot of administrative overhead to set up:

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Fi...

 

Would love to hear some feedback and suggestions!

1 REPLY 1

L7 Applicator

Your solution to put all the tunnel interfaces into area 0 for the interconnections could potentially work.  You do want to be careful then that area zero is able to connect to and see all other areas and there are no isolated area 0 interfaces because of your topology.  Typically as you noted, we have a hub site that is in area 0 with all the tunnels then connected there to insure area 0 integrity.

 

The other option is to just put everything into area 0.  If you have less than 50 sites there should be no problem with the database size or the ability of the devices to keep track of updates.  This would be simpliest if the site count and number of routes can be handled.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center
  • 1918 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!