Summary
- RFC 1587 let an OSPF Not-So-Stubby Area import external routes as area-scoped Type-7 LSAs while still withholding the wider domain’s Type-5 external LSAs from the leaf.
- A P bit and non-zero forwarding address made a Type-7 eligible for translation, but an eligible border translator still had to originate a distinct Type-5. The advertising identity changed at that boundary.
- RFC 3101 later revised translator election, transition stability and security discussion, and exposed a policy paradox: a non-propagating Type-7 could still influence traffic at an NSSA border.
A leaf wanted less information and one exception
An OSPF stub area bought economy by refusing AS-external Type-5 LSAs. Its border supplied a default route instead. A small leaf router did not need to hold every external destination merely to send traffic toward the core.
The bargain became awkward when the leaf itself learned an outside route. RFC 1587 described a site whose internal networks were learned by RIP. An ordinary stub area could not import those routes as OSPF externals. Making the area ordinary again restored import, but also exposed the leaf to the external state it was meant to avoid.
The NSSA was a deliberately uneven answer. It remained stub-like toward the core, but accepted external information originated inside the area. It did not erase the border. It made the border explicit.
The N bit admitted a capability, not a route
RFC 1587 added an N bit alongside OSPF’s E bit. Routers on an NSSA interface had to agree about the area’s external-routing capability. N was set and E was clear on the interface; a mismatch in received Hello options stopped processing, so the adjacency would not form.
That check established a compatibility set. It said the neighbours agreed on the grammar they would use. It did not say that an external route existed, that its source was sound, or that any advertisement would cross the area boundary. A completed adjacency was the beginning of the evidence chain.
External routes entered the NSSA as Type-7 LSAs. They flooded only inside their originating NSSA and lived in that area’s link-state database. By contrast, Type-5 LSAs described AS-external information across all Type-5-capable areas. The two formats were intentionally similar, but their scope and origin were not the same.
Receipt still came before selection
A router receiving a Type-7 did not automatically install it. The calculation had to find the originating AS boundary router through the NSSA. Where the LSA named a forwarding address, an intra-area path to that address also had to exist. Internal OSPF routes outranked external ones; metrics and path types then governed comparison among eligible external paths.
This made three different records easy to confuse: the LSA was in the area database, the route calculation accepted a path, and the forwarding table later carried usable state. RFC 1587 specified relationships among them, not a licence to collapse them.
The P bit asked another router to act
An internal NSSA ASBR set the Type-7 P bit when it wanted the network propagated into the OSPF domain’s wider transit topology. It also supplied a valid non-zero forwarding address. A clear P bit or zero forwarding address stopped normal translation.
P therefore expressed an instruction at one side of a handoff. It was not a receipt from the other side. Translation happened after route calculation and only at an NSSA area border router entitled to translate. Under RFC 1587, the reachable border router with the highest router ID performed the work.
For an unaggregated route, the resulting Type-5 copied destination, mask, metric, path type, forwarding address and external tag. One field necessarily changed: the advertising router became the translator. The original ASBR had authored the Type-7; the ABR authored the Type-5 projection. A route did not pass through the border as one unchanged object.
Default routes exposed a role-specific exception. A Type-7 default originated by an NSSA ABR had to keep P clear and was never translated into Type-5. A Type-7 default originated by an internal NSSA ASBR that was not also an ABR could set P and could be translated. The two originators were not interchangeable.
Range policy could keep known routes private
Type-7 address ranges gave the translator another decision. A range could aggregate several Type-7 networks into one Type-5, or mark them DoNotAdvertise. In the latter case, the component routes could remain known and selected inside the NSSA while no matching Type-5 exposed them to the rest of the autonomous system.
Aggregation also changed the evidence. One wider summary could represent several local routes, with a derived metric and the translator as originator. An observer outside the area could not reconstruct every underlying Type-7 merely from that Type-5.
When a route ceased to qualify, the derived Type-5 had to be flushed or reoriginated from the remaining eligible state. Type-7 and Type-5 lifecycles were coupled, but they were not one lifecycle. The projection could disappear while the local advertisement remained.
The replacement specification made authority stateful
RFC 3101 obsoleted RFC 1587 in January 2003. It did more than polish terminology. It defined NSSATranslatorRole, NSSATranslatorState and a new Nt bit. A border router could be configured to translate Always or enter an election as a Candidate. Candidates considered which border routers were reachable both through the NSSA and through the AS transit topology, then considered Nt and router ID.
A deposed elected translator did not stop instantly. It continued for a default stability interval of forty seconds to avoid needless flushing and reflooding. Translation authority was now an observable state transition with an overlap rule, not merely a deterministic comparison of router IDs.
RFC 3101 also recorded a P-bit policy paradox. A border router could install a non-default Type-7 whose P bit was clear even though it would not translate that route. Traffic arriving from outside the NSSA could then be drawn into the area, contrary to the path expected by its source and arguably contrary to the no-propagation signal. Local installation and external publication were separate, yet the first could still affect traffic from the second domain.
Authentication did not certify the projection
RFC 1587 said security issues were not discussed. RFC 3101 added authentication and denial-of-service analysis. It described OSPF packet authentication, shared-key limitations, advertisement floods and database exhaustion. It also noted that these concerns existed beyond NSSA.
An authenticated OSPF exchange could establish that a packet passed the configured protocol check. It provided no confidentiality. It did not prove that the external source was truthful, the P-bit policy matched operator intent, the elected translator was correctly configured, a summary preserved needed provenance, or remote forwarding succeeded. Those remained separate controls and observations.
Running code revised the paper
RFC 3101 credited the first full known implementation with producing substantive changes to the text. That is a narrow but valuable historical receipt: implementation found enough ambiguity or consequence to alter the replacement specification. It is not evidence of multi-vendor interoperability or broad deployment.
The frozen sources also do not establish current deployment, vendor behaviour or any named operator’s configuration.
The distinction follows the discipline in Heng Lu’s writing on running-code primacy, minimum initial specification and local adoption, and reality rather than advocacy. A specification, an implemented state machine, a locally selected route, a translated advertisement and an observed service result belong in one history only if their boundaries remain visible.
The durable record is a chain: source route, Type-7 origination, NSSA flooding, local calculation, P and range policy, translator state, Type-5 origination, wider flooding, remote selection, forwarding and measured outcome. RFC 1587 made the middle boundary legible. The area could know. The backbone still needed its own evidence.
Sources
- RFC Editor information — RFC 1583
- RFC 1583 — OSPF Version 2
- RFC Editor information — RFC 1587
- RFC 1587 — The OSPF NSSA Option
- RFC Editor information — RFC 2328
- RFC 2328 — OSPF Version 2
- RFC Editor information — RFC 3101
- RFC 3101 — The OSPF Not-So-Stubby Area (NSSA) Option
- Heng Lu — Running-Code Primacy
- Heng Lu — Minimum Initial Specification
- Heng Lu — Why BTW.Media Exists
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
