How to troubleshoot flapping OSPF neighbour adjacency
11426
Created On 09/21/23 04:08 AM - Last Modified 08/19/24 04:26 AM
Objective
To identify and resolve the cause of flapping OSPF adjacency.
Environment
- Palo Alto Firewalls
- PAN-OS
- OSPF
Procedure
- Identify possible OSFP adjacency reachability issue.
- For the physical layer use, How to troubleshoot physical port flap or link down issue.
- Usage of the same IP address on two different devices can lead to an unstable OSPF, check Received conflicting ARP on interface ethernetX/X indicating duplicate IP Y.Y.Y.Y to resolve such issue.
- Is BFD configured between neighbours, review How to troubleshoot BFD to isolate the problem?
- Check if the aggregated interface using LACP is having issue, explore How to troubleshoot LACP going down or flap issue.
- Incomplete ARP Entry or Firewall Responds To Every ARP Request On The Network.
- Was HA failover triggered?
- Verify that OSPF Graceful restart is configured on both peers.
- Identify possible resource depletion in the Palo Alto firewall.
- If the firewall is monitored by Strata Cloud Manager (formerly known as AIOps), use How to identify high CPU, Packet Buffer, and Packet Descriptor in the firewall with Strata Cloud Manager.
- For non-Strata Cloud Manager monitored firewalls, use the following steps.
- Use HowTo Troubleshoot High Packet Buffer Or Packet Descriptors Usage to check if your firewall is having high dataplane resources usage.
- Determine if the data plane CPU utilization is high.
- Under the firewall's GUI, go to DASHBOARD > Widgets > System > click on System Resources.
- To resolve this issue, use How to Troubleshoot High DataPlane CPU.
- Determine if the management plane CPU utilization is high.
- Under the firewall's GUI, go to DASHBOARD > Widgets > System > click on System Resources.
- To resolve this issue, use TIPS & TRICKS: Reducing Management Plane Load.
- How to troubleshoot OSPF adjacency stuck in INIT or EXSTART or EXCHANGE or LOADING States.
- Search for the errors from routed.log.
> grep pattern "use-values-below" mp-log routed.log
- neighbor does not need to become adjacent.
- Hello packet dropped because source router ID matches local router ID
- Couterfeit packet received