Description | This article describes the behavior when the database-filter-out option is enabled on a FortiGate OSPF interface. | ||||||||||
Scope | FortiGate (All supported models/firmware). | ||||||||||
Solution |
The database-filter-outOption option suppresses the transmission of LSAs (Link State Advertisements) to the neighbor on that interface. This prevents the neighbor from learning routes—such as external routes or redistributed routes—originating from the advertising router. OSPF adjacency remains fully established, and DBD (Database Description) packets are exchanged, but they do not contain any LSA headers.
Network Setup:
Step 1: Review OSPF Interface Configuration on FGTA.
config router ospf
Step 2: Check OSPF Database on Neighbor (FGTB).
Before enabling 'database-filter-out':
get router info ospf database brief OSPF Router with ID (2.2.2.2) (Process ID 0, VRF 0)
Router Link States (Area 0.0.0.0) Link ID ADV Router Age Seq# CkSum Flag Link count
Net Link States (Area 0.0.0.0) Link ID ADV Router Age Seq# CkSum Flag
AS External Link States Link ID ADV Router Age Seq# CkSum Flag Route Tag
get router info ospf database brief OSPF Router with ID (2.2.2.2) (Process ID 0, VRF 0) Router Link States (Area 0.0.0.0) Link ID ADV Router Age Seq# CkSum Flag Link count
get router info routing-table ospf Packet Capture Analysis on FortiGate A:
Before Enabling 'database-filter-out': LSA Headers Present:
After Enabling 'database-filter-out':
Expected Behavior:
Use Cases:
Additional Notes:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.