IS-IS (Intermediate System to Intermediate System) is a link-state interior gateway protocol (IGP). It is the IGP of choice in most large service-provider and hyperscale networks, and it is gaining ground in data centers and enterprise cores. This post covers the protocol from the ground up: its history, addressing, hierarchy, packet formats, adjacencies, flooding, metrics, SPF, extensions, configuration and troubleshooting.
Table of Contents
- History and Standards
- Terminology
- Encapsulation: IS-IS Does Not Run Over IP
- NSAP and NET Addressing
- Levels, Areas and Hierarchy
- PDU Types
- TLVs: The Secret to IS-IS Extensibility
- Adjacency Formation
- The Designated IS (DIS) and Pseudonodes
- LSPs, Flooding and Database Synchronization
- ATT, Overload and Partition Bits
- Metrics: Narrow vs Wide
- SPF, iSPF and PRC
- Inter-Area Routing and Route Leaking
- Authentication
- IPv6 and Multi-Topology
- Modern Extensions: TE, SR, Flex-Algo, BFD, GR
- IS-IS vs OSPF
- Configuration Examples (IOS-XE, IOS-XR, FRR)
- Verification Commands
- Troubleshooting Checklist
- Design Best Practices
- Key RFCs and References
1. History and Standards
IS-IS was designed in the 1980s by Digital Equipment Corporation (DEC) as part of DECnet Phase V, and was later standardized by the ISO as ISO/IEC 10589 — the routing protocol for the OSI Connectionless Network Service (CLNS). Its original job was to route CLNP packets, not IP.
When the Internet grew, the IETF published RFC 1195 (1990) — “Use of OSI IS-IS for Routing in TCP/IP and Dual Environments”. This became known as Integrated IS-IS (or Dual IS-IS): one protocol instance that can carry OSI and IP reachability. Today virtually every deployment is IP-only, but the OSI heritage remains visible in the addressing (NETs) and terminology.
In the early-to-mid 1990s, large ISPs chose IS-IS over OSPF because the Cisco implementation was more mature and stable at scale at the time, and because the protocol was simple and extensible. That installed base, plus IS-IS’s easy extensibility through TLVs, is why IS-IS remains dominant in Tier-1 carrier networks.
2. Terminology
| Term | Meaning | Rough OSPF equivalent |
|---|---|---|
| IS (Intermediate System) | A router | Router |
| ES (End System) | A host | Host |
| Domain | The whole IS-IS routing domain | Autonomous system |
| Area | A group of routers sharing an area address | Area |
| Level-1 (L1) | Intra-area routing | Non-backbone/totally stubby area |
| Level-2 (L2) | Inter-area (backbone) routing | Area 0 |
| L1/L2 router | Router doing both levels | ABR |
| PDU (Protocol Data Unit) | A packet | Packet |
| IIH (IS-IS Hello) | Hello packet | Hello |
| LSP (Link State PDU) | Link state advertisement packet | LSA (each LSP is closer to a router’s full set of LSAs) |
| CSNP (Complete Sequence Number PDU) | Full database summary | DBD |
| PSNP (Partial Sequence Number PDU) | Request or acknowledge LSPs | LSR / LSAck |
| DIS (Designated IS) | Router representing a LAN segment | DR (no BDR in IS-IS) |
| Pseudonode | Virtual node representing a LAN | Network LSA (Type 2) |
| SNPA (Subnetwork Point of Attachment) | Layer 2 address (MAC, DLCI) | — |
| NSAP / NET | OSI network address / router’s address | Router ID + area ID |
| System ID | Unique 6-byte identifier of a router | Router ID |
3. Encapsulation: IS-IS Does Not Run Over IP
This is the single most important architectural difference from OSPF. OSPF is IP protocol 89. IS-IS runs directly over the data link layer. On Ethernet, IS-IS frames use an 802.3 length field with an LLC header of DSAP=0xFE, SSAP=0xFE, Control=0x03 (the OSI network layer SAP).
Consequences:
- Protocol-agnostic: IS-IS can carry IPv4, IPv6, CLNS or anything else encoded in a TLV, without needing one protocol to bootstrap another. This is why adding IPv6 to IS-IS was just a matter of new TLVs, while OSPF needed a whole new version (OSPFv3).
- Security: IS-IS packets cannot be routed. You cannot attack IS-IS from a remote IP host; an attacker must be directly attached at layer 2.
- No IP subnet dependency in principle: adjacencies are formed at L2. (Cisco IOS still checks that IPv4 neighbors are on the same subnet on broadcast links; this can be relaxed on point-to-point links with
unnumberedinterfaces.) - Requires multicast MAC support on LAN segments and cannot traverse a routed hop (you need a GRE tunnel or similar to run IS-IS across an IP cloud).
Destination multicast MAC addresses:
| Address | Name | Used by |
|---|---|---|
01:80:C2:00:00:14 |
AllL1ISs | Level-1 PDUs on LANs |
01:80:C2:00:00:15 |
AllL2ISs | Level-2 PDUs on LANs |
09:00:2B:00:00:04 |
AllESs | ES-IS (OSI) |
09:00:2B:00:00:05 |
AllISs | ES-IS (OSI) |
Every IS-IS PDU starts with an 8-byte common header whose first byte is the Intradomain Routing Protocol Discriminator, 0x83, followed by header length, version, ID length, PDU type, version, reserved and maximum area addresses. Wireshark filter: isis (or llc.dsap == 0xfe).
4. NSAP and NET Addressing
Even in an IP-only network, every IS-IS router needs an OSI address called a NET (Network Entity Title). A NET is simply an NSAP address whose final byte (the NSEL, selector) is 00, meaning “the router itself”.
NSAPs are variable length, 8 to 20 bytes. Cisco and most vendors interpret the NET simply as:
49.0001.1921.6800.1001.00
| | | |
| | | +-- NSEL (1 byte) : always 00 for a NET
| | +----------------- System ID (6 bytes): unique per router in the domain
| +---------------------- Area ID (variable): 0001
+------------------------- AFI (1 byte) : 49 = private/local addressing
- AFI 49 is the “private” authority and format identifier — the IS-IS equivalent of RFC 1918. Nearly everyone uses it.
- Area address = everything to the left of the System ID (here
49.0001). Two routers are in the same area if they share at least one area address. A router can have up to 3 area addresses by default (useful for area migrations/merges). - System ID is always 6 bytes and must be unique within the domain (L1 routers must be unique in the area; L2 routers across the whole L2 backbone — in practice, make it globally unique).
- NSEL must be
00on a NET.
A common trick is to encode the loopback IPv4 address in the System ID. For loopback 192.168.10.1, pad each octet to three digits (192.168.010.001), concatenate (192168010001), and regroup into 4-digit blocks (1921.6801.0001). Resulting NET: 49.0001.1921.6801.0001.00. Other people use the router’s MAC or a simple sequence (0000.0000.0001).
Because System IDs are not human-friendly, enable dynamic hostname (TLV 137, RFC 5301) — it’s on by default on Cisco — so show commands display router hostnames instead of System IDs.
5. Levels, Areas and Hierarchy
IS-IS uses a two-level hierarchy:
- Level-1 routers know the full topology of their own area only. To reach anything outside the area, they follow a default route to the nearest L1/L2 router (like an OSPF totally stubby area).
- Level-2 routers form the backbone and exchange inter-area routes. The L2 backbone must be contiguous (there is no virtual-link concept in practice; partition repair from ISO 10589 was never widely implemented).
- Level-1/Level-2 routers participate in both and maintain two separate link-state databases.
Key difference from OSPF: in OSPF, the area boundary sits inside the ABR (each interface is in an area). In IS-IS, each router belongs entirely to one area and the area boundary falls on the link between routers. The L2 backbone is not an area — it is simply the set of L2-capable routers and the L2 adjacencies between them, which may span many areas.
Area 49.0001 Area 49.0002
+---------------------+ +---------------------+
| | | |
| R1 (L1) ---- R2 (L1/L2) ==L2== R3 (L1/L2) ---- R4 (L1)
| | | |
+---------------------+ +---------------------+
L1 adjacency L2 adjacency L1 adjacency
Adjacency rules:
| Router A | Router B | Same area | Different area |
|---|---|---|---|
| L1 | L1 | L1 adjacency | None |
| L1 | L1/L2 | L1 adjacency | None |
| L1/L2 | L1/L2 | L1 and L2 adjacency | L2 adjacency |
| L2 | L1/L2 | L2 adjacency | L2 adjacency |
| L2 | L2 | L2 adjacency | L2 adjacency |
| L1 | L2 | Never | |
Cisco routers default to is-type level-1-2, which means both L1 and L2 adjacencies are formed on every link within an area — two hellos, two databases, two SPF runs. In a flat design, it is common to set everything to is-type level-2-only and treat the whole network as a single L2 domain; this scales to many hundreds of routers on modern hardware.
6. PDU Types
| Type # | PDU | Purpose |
|---|---|---|
| 15 | L1 LAN IIH | Level-1 hello on broadcast links |
| 16 | L2 LAN IIH | Level-2 hello on broadcast links |
| 17 | P2P IIH | Hello on point-to-point links (one PDU for both levels) |
| 18 | L1 LSP | Level-1 link-state PDU |
| 20 | L2 LSP | Level-2 link-state PDU |
| 24 | L1 CSNP | Level-1 complete database summary |
| 25 | L2 CSNP | Level-2 complete database summary |
| 26 | L1 PSNP | Level-1 request/ack |
| 27 | L2 PSNP | Level-2 request/ack |
That is the entire protocol: hellos, LSPs and two kinds of sequence number PDUs. Compare this to OSPF’s five packet types and eleven-plus LSA types. Everything else in IS-IS is expressed as TLVs inside these PDUs.
7. TLVs: The Secret to IS-IS Extensibility
Every piece of information in an IS-IS PDU (after the fixed header) is a Type-Length-Value triplet. Routers silently ignore (but still flood) TLVs they don’t understand. This means new features can be introduced incrementally without a protocol version change — the main reason IS-IS absorbed IPv6, TE, Segment Routing, SRv6 and Flex-Algo so smoothly.
| TLV | Name | Notes |
|---|---|---|
| 1 | Area Addresses | Areas this router belongs to |
| 2 | IS Reachability (narrow) | Neighbors with 6-bit metric (legacy) |
| 6 | IS Neighbors | MAC addresses of neighbors heard on LAN (used for 2-way check) |
| 8 | Padding | Pads hellos to MTU size |
| 10 | Authentication | Clear-text or HMAC-MD5 |
| 22 | Extended IS Reachability | Wide metrics (24-bit) + TE sub-TLVs (RFC 5305) |
| 128 | IP Internal Reachability | IPv4 prefixes, narrow metric (RFC 1195) |
| 129 | Protocols Supported | NLPIDs, e.g. 0xCC = IPv4, 0x8E = IPv6 |
| 130 | IP External Reachability | Redistributed IPv4, narrow metric |
| 132 | IP Interface Address | IPv4 addresses of the router |
| 134 | TE Router ID | Stable router ID for TE |
| 135 | Extended IP Reachability | IPv4 prefixes with 32-bit metric, up/down bit, sub-TLVs (SR prefix-SID) |
| 137 | Dynamic Hostname | Maps System ID to hostname |
| 222 | MT IS Reachability | Multi-topology neighbors |
| 229 | Multi-Topology | Topologies this router participates in |
| 232 | IPv6 Interface Address | RFC 5308 |
| 235 | MT IP Reachability | Per-topology IPv4 prefixes |
| 236 | IPv6 Reachability | RFC 5308 |
| 237 | MT IPv6 Reachability | Per-topology IPv6 prefixes (RFC 5120) |
| 240 | P2P Three-Way Adjacency | RFC 5303 |
| 242 | Router Capability | SR capabilities (SRGB), Flex-Algo definitions, etc. |
8. Adjacency Formation
Network types
IS-IS only has two network types: broadcast (LAN) and point-to-point. There is no NBMA/point-to-multipoint mode like OSPF.
Hellos and timers
- Default hello interval: 10 seconds; hello multiplier: 3 → hold time 30 s. The hold time is advertised in the hello, so neighbors do not need matching timers (unlike OSPF).
- The DIS sends hellos three times faster (3.33 s) so that DIS failure is detected quickly.
- Hellos are padded to the full interface MTU (TLV 8). This detects MTU mismatches up front: if one side’s padded hello cannot be received, the adjacency never comes up. On links with a known-good MTU, padding can be disabled after the adjacency is up (
isis hello paddingvariants) to save bandwidth.
Requirements for an adjacency
- Compatible levels (see the table above) and, for L1, a common area address.
- Unique System IDs (duplicate System IDs cause adjacency flaps and “duplicate system ID” errors).
- Matching authentication, if configured.
- Matching MTU (because of hello padding).
- Same interface network type on both ends (broadcast vs P2P mismatch is a classic failure).
- On Cisco, IPv4 addresses on the same subnet (broadcast links) and matching supported protocols / topologies (e.g. both running IPv6 in single-topology mode).
LAN adjacencies
On a LAN, a router lists the MAC addresses of neighbors it has heard in TLV 6. When a router sees its own MAC in a neighbor’s hello, two-way communication is confirmed and the adjacency goes Init → Up. Separate L1 and L2 hellos (and adjacencies) are maintained.
Point-to-point adjacencies and the 3-way handshake
The original ISO spec used a 2-way handshake on P2P links, which could leave an adjacency up in one direction only. RFC 5303 added TLV 240 for a three-way handshake with states Down → Initializing → Up, and it is the default on all modern implementations.
Tip: Most Ethernet links between two routers are really point-to-point. Configure isis network point-to-point (RFC 5309) on them: no DIS election, no pseudonode, no CSNP flooding every 10 s, a smaller LSDB, and faster convergence.
9. The Designated IS (DIS) and Pseudonodes
On a broadcast segment, IS-IS elects a Designated Intermediate System, separately for L1 and L2. The DIS:
- Creates a pseudonode LSP representing the LAN. All routers on the LAN advertise a link to the pseudonode instead of to each other, reducing n(n−1)/2 links to n.
- Periodically multicasts CSNPs every 10 seconds to keep LAN databases in sync.
Election:
- Highest interface priority (0–127, default 64). Unlike OSPF, priority 0 does not prevent a router from becoming DIS; it just makes it least preferred.
- Tie-breaker: highest SNPA (MAC address). (On P2P-over-LAN or other media, highest System ID.)
Differences from the OSPF DR:
| OSPF DR | IS-IS DIS |
|---|---|
| Non-preemptive | Preemptive — a better router immediately takes over |
| Has a BDR | No backup — re-election is fast and cheap |
| DROthers only become FULL with DR/BDR | All routers form adjacencies with all others on the LAN |
| Flooding goes through the DR | LSPs are multicast to everyone; DIS only ensures sync via CSNPs |
The pseudonode is identified by a LAN ID: the DIS’s System ID plus a one-byte non-zero circuit ID, e.g. R2.03. Non-pseudonode (real router) LSPs always have .00.
10. LSPs, Flooding and Database Synchronization
LSP identity
Each LSP is identified by an LSP ID of the form SystemID.PseudonodeID-FragmentNumber:
1921.6801.0001.00-00 (router LSP, fragment 0)
1921.6801.0001.00-01 (router LSP, fragment 1)
1921.6801.0002.03-00 (pseudonode LSP created by DIS for circuit 3)
A router generates one LSP per level describing everything it knows (neighbors, prefixes, capabilities). If it doesn’t fit in one PDU (default max LSP size is 1492 bytes), it is split into fragments, up to 256 fragments (0–255). Compare this to OSPF, where a router originates many different LSA types.
LSP header fields
- Sequence number (32-bit): incremented on every change; the higher number wins.
- Remaining lifetime: counts down (OSPF’s LS age counts up). Default max lifetime 1200 s, refreshed every 900 s. In large networks, set lifetime to 65535 s and refresh to ~65000 s to reduce churn.
- Checksum (covers everything except remaining lifetime).
- P / ATT / OL bits and the IS type (L1 or L2).
Flooding mechanics
Implementations keep two flags per LSP per interface:
- SRM (Send Routing Message): this LSP must be sent on this interface.
- SSN (Send Sequence Number): a PSNP acknowledging/requesting this LSP must be sent.
On point-to-point links, flooding is reliable: every LSP is explicitly acknowledged with a PSNP; unacknowledged LSPs are retransmitted (default 5 s). CSNPs are exchanged once when the adjacency comes up.
On broadcast links, LSPs are not individually acknowledged. Instead, the DIS sends a CSNP every 10 s listing every LSP ID, sequence number, checksum and lifetime. A router that sees a newer entry than its own sends a PSNP to request it; a router that has a newer LSP than the CSNP lists simply floods it.
Purging
When an LSP’s remaining lifetime reaches zero, or when the originator wants to withdraw it, a purge is flooded: the LSP header with lifetime 0 and no TLVs. Routers keep it for ZeroAgeLifetime (60 s) so the purge propagates. RFC 6232 adds the Purge Originator Identification TLV (13) so you can see who purged an LSP — invaluable when troubleshooting.
Mesh groups
In dense full-mesh topologies, flooding every LSP out every interface is wasteful. Mesh groups (RFC 2973) let you mark interfaces so an LSP received on a member interface is not re-flooded to other members of the same group.
11. ATT, Overload and Partition Bits
- ATT (Attached) bit: set in the L1 LSP by an L1/L2 router that has L2 connectivity to another area. L1 routers install a default route (0.0.0.0/0) toward the closest L1/L2 router with ATT set. Can be suppressed with
set-attached-bit/ignore-attached-bitcontrols. - OL (Overload) bit: tells others “don’t use me for transit”. Other routers still reach the router’s directly connected prefixes but will not route through it. Extremely useful for:
- Maintenance: set overload, traffic drains, work on the box, clear overload.
- Startup:
set-overload-bit on-startup wait-for-bgpkeeps a rebooting router out of the transit path until BGP has converged, preventing blackholes.
- P (Partition repair) bit: indicates support for L1 partition repair via virtual L2 links. Practically unimplemented.
12. Metrics: Narrow vs Wide
IS-IS metrics are not bandwidth based. On Cisco, every interface defaults to a metric of 10, regardless of speed. Without tuning, IS-IS effectively does hop count × 10. Always set metrics deliberately (many operators use a reference-bandwidth scheme, e.g. 100G = 10, 10G = 100, 1G = 1000, or latency-based metrics).
| Narrow (original) | Wide (RFC 5305) | |
|---|---|---|
| Interface metric | 6 bits: 1–63 | 24 bits: 1–16,777,215 |
| Total path metric | 10 bits: max 1023 | 32 bits: max 0xFE000000 (4,261,412,864) |
| TLVs | 2, 128, 130 | 22, 135 |
| Supports TE / SR / Flex-Algo | No | Yes |
ISO 10589 also defined optional delay, expense and error metrics (for TOS routing) — never implemented by Cisco and effectively dead.
Always use metric-style wide on every router. If migrating a live network, use metric-style transition (advertise and accept both), migrate all routers, then switch to wide. Mixing narrow-only and wide-only routers causes routers to ignore each other’s reachability information and blackholes traffic.
Prefixes also carry an internal/external distinction. With narrow metrics, TLV 128 is internal and TLV 130 external, with an I/E bit. With wide metrics (TLV 135), there is no internal/external distinction in the TLV itself; redistributed prefixes are simply prefixes (RFC 7794 adds an X flag to mark them).
13. SPF, iSPF and PRC
Each router runs Dijkstra’s SPF separately for each level. A key design point makes IS-IS efficient: IP prefixes are leaves of the SPF tree, not nodes. The topology graph consists of routers and pseudonodes only.
- Full SPF runs when topology changes (a router or adjacency is added/removed, or a link metric changes).
- PRC (Partial Route Calculation) runs when only prefix information changes (a loopback added, a redistributed route flaps). The router re-evaluates the affected prefixes without recomputing the tree — much cheaper. OSPF achieves something similar only for Type 3/5 LSAs; a change to an intra-area stub network in an OSPF Router LSA traditionally triggers a full SPF.
- iSPF (incremental SPF) recomputes only the affected portion of the tree after a topology change.
Throttling timers (Cisco syntax: max-wait initial-wait second-wait in ms):
router isis CORE
spf-interval 5 50 200
prc-interval 5 50 200
lsp-gen-interval 5 50 200
Exponential backoff lets IS-IS react in tens of milliseconds to an isolated event while dampening a storm of events. Combined with BFD and LFA/TI-LFA, sub-50 ms convergence is achievable.
Route selection
Cisco administrative distance for IS-IS is 115. Within IS-IS, preference order (RFC 5302):
- L1 intra-area routes (
i L1) - L2 routes (
i L2) - L1 routes leaked from L2 (inter-area,
i ia) - External routes, by level
Equal-cost multipath is supported (Cisco default: 4 paths; configurable with maximum-paths).
14. Inter-Area Routing and Route Leaking
By default:
- L1 → L2: L1/L2 routers automatically advertise all L1 prefixes of their area into L2 (optionally summarized with
summary-address). - L2 → L1: nothing is advertised. L1 routers only get a default route via the ATT bit.
This is simple but can cause suboptimal routing: if an area has two L1/L2 exits, an L1 router picks the one closest to itself, not the one closest to the destination. It also breaks things that need specific routes — for example, MPLS LDP requires a /32 route to each PE loopback (a default route is not enough to build an LSP).
Route leaking (RFC 5302) selectively redistributes L2 prefixes into L1. To prevent loops, leaked prefixes have the up/down bit set. An L1/L2 router will never re-advertise a prefix with the up/down bit set back into L2.
! Cisco IOS-XE: leak all PE loopbacks from L2 into L1
ip prefix-list PE-LOOPBACKS seq 10 permit 10.255.0.0/16 ge 32
!
route-map L2-TO-L1 permit 10
match ip address prefix-list PE-LOOPBACKS
!
router isis CORE
redistribute isis ip level-2 into level-1 route-map L2-TO-L1
15. Authentication
IS-IS authentication is applied in two independent places:
- Interface/hello authentication — protects IIHs, controlling who can form adjacencies.
- Area (L1) / domain (L2) authentication — protects LSPs, CSNPs and PSNPs, ensuring the database content is authentic.
Methods:
- Clear text (ISO 10589, TLV 10 type 1) — avoid.
- HMAC-MD5 (RFC 5304) — widely supported.
- HMAC-SHA-1/256/384/512 (RFC 5310, “generic cryptographic authentication”) — preferred where supported; uses key IDs, enabling hitless key rollover.
key chain ISIS-KEYS
key 1
key-string S3cr3tKey
cryptographic-algorithm hmac-sha-256
!
router isis CORE
authentication mode md5
authentication key-chain ISIS-KEYS
!
interface GigabitEthernet0/0/0
isis authentication mode md5
isis authentication key-chain ISIS-KEYS
(Syntax for SHA varies by platform/release; IOS-XR and Junos support hmac-sha directly.)
16. IPv6 and Multi-Topology
RFC 5308 added IPv6 with two TLVs (232 and 236) — no new protocol required.
Single topology (default on Cisco IOS)
One SPF computation for both IPv4 and IPv6. Every link and router must be dual-stacked with identical topology; if IPv4 and IPv6 are not configured on the same interfaces, adjacencies fail or traffic is blackholed.
Multi-topology (RFC 5120)
Separate topologies (MT-ID 0 = IPv4 unicast, MT-ID 2 = IPv6 unicast, MT-ID 3 = IPv4 multicast, etc.) with separate SPF runs, using TLVs 222, 229, 235 and 237. IPv4 and IPv6 can have different topologies and metrics. Recommended for anything beyond a lab, and required for incremental IPv6 rollout.
router isis CORE
address-family ipv6
multi-topology
exit-address-family
17. Modern Extensions
- Traffic Engineering (RFC 5305, RFC 7810, RFC 8570): sub-TLVs in TLV 22 carry max/reservable/unreserved bandwidth, admin groups (affinities), TE metric, and delay/loss/jitter for RSVP-TE and SR-TE.
- Segment Routing (RFC 8667): SR capability and SRGB in TLV 242, Prefix-SIDs as sub-TLVs of TLV 135/236, Adjacency-SIDs in TLV 22. IS-IS becomes the label distribution protocol, replacing LDP.
- SRv6 (RFC 9352): advertising SRv6 locators and SIDs.
- TI-LFA: topology-independent loop-free alternate, precomputed backup paths for ~50 ms protection.
- Flexible Algorithm (RFC 9350): define additional constraint-based SPF computations (e.g. “minimize delay, avoid red links”) inside the IGP, with their own Prefix-SIDs — network slicing without a controller.
- BFD (
isis bfd): sub-second failure detection, with IS-IS registering as a BFD client. - Graceful Restart / NSF (RFC 5306) and NSR: preserve forwarding during control-plane restarts.
- Router Capability TLV (RFC 7981), Admin Tags (RFC 5130), prefix attributes (RFC 7794).
- Dynamic flooding / flooding reduction (RFC 9667): reduces flooding in dense data-center Clos fabrics.
- BIER and RIFT-adjacent work also build on IS-IS concepts.
18. IS-IS vs OSPF
| Aspect | IS-IS | OSPFv2 |
|---|---|---|
| Standard | ISO 10589, RFC 1195 | RFC 2328 |
| Transport | Directly over Layer 2 | IP protocol 89 |
| Address families | IPv4, IPv6, CLNS in one instance | IPv4 only (OSPFv3 for IPv6; AF extensions exist) |
| Area boundary | On the link | Inside the ABR |
| Backbone | Contiguous set of L2 routers, spanning areas | Area 0 |
| Area types | L1 (behaves like totally stubby), L2 | Standard, stub, totally stubby, NSSA, totally NSSA |
| Packet/LSA types | 4 PDU classes; 1 LSP per router per level | 5 packet types; 11+ LSA types |
| Extensibility | TLVs, very easy | Opaque LSAs; OSPFv3 later added TLV extensions |
| Timer matching | Not required | Hello/dead must match |
| DR/DIS | Preemptive, no backup | Non-preemptive, BDR |
| Default metric | 10 per interface | Reference bandwidth / interface bandwidth |
| Prefix change | PRC only (no full SPF) | May trigger full SPF |
| Network types | Broadcast, P2P | Broadcast, NBMA, P2P, P2MP, virtual links |
| Cisco AD | 115 | 110 |
| Typical deployment | Service providers, hyperscalers, DC fabrics | Enterprises |
Neither is “better” in absolute terms. OSPF offers richer area types and is more familiar to enterprise engineers. IS-IS offers a simpler protocol with fewer moving parts, better stability at scale, clean multi-protocol support, and faster adoption of new features.
19. Configuration Examples
Lab topology:
Area 49.0001 Area 49.0002
Lo0 10.255.0.1 Lo0 10.255.0.2 Lo0 10.255.0.3 Lo0 10.255.0.4
+------+ 10.0.12.0/30 +------+ 10.0.23.0/30 +------+ 10.0.34.0/30 +------+
| R1 |----------------| R2 |==============| R3 |--------------| R4 |
| L1 | Gi1 Gi1 | L1/L2| Gi2 Gi2 | L1/L2| Gi1 Gi1 | L1 |
+------+ +------+ +------+ +------+
Cisco IOS-XE
! ---------- R1 (Level-1 only) ----------
hostname R1
interface Loopback0
ip address 10.255.0.1 255.255.255.255
ipv6 address 2001:db8:255::1/128
ip router isis CORE
ipv6 router isis CORE
isis circuit-type level-1
!
interface GigabitEthernet1
ip address 10.0.12.1 255.255.255.252
ipv6 address 2001:db8:12::1/64
ip router isis CORE
ipv6 router isis CORE
isis network point-to-point
isis circuit-type level-1
isis metric 100
isis bfd
!
router isis CORE
net 49.0001.0000.0000.0001.00
is-type level-1
metric-style wide
log-adjacency-changes
passive-interface Loopback0
set-overload-bit on-startup 300
spf-interval 5 50 200
prc-interval 5 50 200
lsp-gen-interval 5 50 200
max-lsp-lifetime 65535
lsp-refresh-interval 65000
address-family ipv6
multi-topology
exit-address-family
! ---------- R2 (Level-1/Level-2) ----------
hostname R2
interface Loopback0
ip address 10.255.0.2 255.255.255.255
ip router isis CORE
!
interface GigabitEthernet1
description to R1 (L1)
ip address 10.0.12.2 255.255.255.252
ip router isis CORE
isis network point-to-point
isis circuit-type level-1
isis metric 100
!
interface GigabitEthernet2
description to R3 (L2, other area)
ip address 10.0.23.2 255.255.255.252
ip router isis CORE
isis network point-to-point
isis circuit-type level-2-only
isis metric 100
!
router isis CORE
net 49.0001.0000.0000.0002.00
is-type level-1-2
metric-style wide
log-adjacency-changes
passive-interface Loopback0
summary-address 10.0.0.0 255.255.0.0 level-2
Notes:
passive-interfacein IS-IS means “advertise this interface’s prefix but send no hellos”. On IOS-XE,passive-interfaceunder the router process also enables IS-IS on that interface.isis circuit-typerestricts which adjacencies form on an interface;is-typerestricts the whole router.- Use
advertise passive-onlyto advertise only loopbacks (passive interfaces), keeping transit link prefixes out of the RIB — a common SP practice that shrinks the routing table and the attack surface.
Cisco IOS-XR
router isis CORE
is-type level-2-only
net 49.0002.0000.0000.0003.00
nsr
log adjacency changes
lsp-refresh-interval 65000
max-lsp-lifetime 65535
address-family ipv4 unicast
metric-style wide
segment-routing mpls
!
address-family ipv6 unicast
metric-style wide
single-topology
!
interface Loopback0
passive
address-family ipv4 unicast
prefix-sid index 3
!
!
interface GigabitEthernet0/0/0/2
point-to-point
bfd minimum-interval 50
bfd multiplier 3
bfd fast-detect ipv4
address-family ipv4 unicast
metric 100
fast-reroute per-prefix
fast-reroute per-prefix ti-lfa
!
!
!
segment-routing
global-block 16000 23999
FRRouting (Linux)
FRR’s isisd brings IS-IS to any Linux box — perfect for home labs, containerlab and Raspberry Pis. Enable it in /etc/frr/daemons (isisd=yes), restart FRR, then in vtysh:
! /etc/frr/frr.conf on R4 (Level-1)
frr defaults traditional
hostname R4
!
interface lo
ip address 10.255.0.4/32
ip router isis CORE
isis passive
!
interface eth1
ip address 10.0.34.2/30
ip router isis CORE
isis circuit-type level-1
isis network point-to-point
isis metric 100
isis hello-interval 3
isis hello-multiplier 3
!
router isis CORE
net 49.0002.0000.0000.0004.00
is-type level-1
metric-style wide
log-adjacency-changes
lsp-gen-interval 1
spf-interval 1
!
Remember that the kernel must permit forwarding (sysctl -w net.ipv4.ip_forward=1) and that IS-IS frames are LLC, so some virtual switches/bridges and cloud networks drop them. Linux bridges pass them fine, and containerlab/veth links work well.
20. Verification Commands
| Cisco IOS-XE | FRR (vtysh) | What it shows |
|---|---|---|
show isis neighbors |
show isis neighbor |
Adjacencies, level, state, hold time |
show clns neighbors detail |
show isis neighbor detail |
Area addresses, IPs, uptime, topologies |
show clns interface / show isis interface |
show isis interface detail |
Circuit type, DIS, metrics, timers |
show isis database |
show isis database |
LSP list per level, seq numbers, ATT/P/OL |
show isis database detail R2.00-00 |
show isis database detail R2.00-00 |
TLV contents of a specific LSP |
show isis topology |
show isis topology |
SPF result: next hop and metric per router |
show ip route isis |
show ip route isis |
Installed IS-IS routes |
show isis spf-log |
show isis spf-delay-ietf |
SPF runs and triggers |
show isis hostname |
show isis hostname |
System ID to hostname mapping |
debug isis adj-packets |
debug isis adj-packets |
Hello exchange, adjacency problems |
debug isis update-packets |
debug isis update-packets |
LSP flooding |
Sample output (IOS-XE on R2):
R2# show isis neighbors
Tag CORE:
System Id Type Interface IP Address State Holdtime Circuit Id
R1 L1 Gi1 10.0.12.1 UP 27 00
R3 L2 Gi2 10.0.23.3 UP 29 00
R2# show isis database
Tag CORE:
IS-IS Level-1 Link State Database:
LSPID LSP Seq Num LSP Checksum LSP Holdtime/Rcvd ATT/P/OL
R1.00-00 0x00000005 0x8A1C 65201/65535 0/0/0
R2.00-00 * 0x00000007 0x3F2E 65312/* 1/0/0
IS-IS Level-2 Link State Database:
LSPID LSP Seq Num LSP Checksum LSP Holdtime/Rcvd ATT/P/OL
R2.00-00 * 0x00000006 0x51D0 65300/* 0/0/0
R3.00-00 0x00000006 0xB7C4 65290/65535 0/0/0
R1# show ip route isis
10.0.0.0/8 is variably subnetted
i*L1 0.0.0.0/0 [115/100] via 10.0.12.2, GigabitEthernet1
i L1 10.255.0.2/32 [115/100] via 10.0.12.2, GigabitEthernet1
Note R2’s L1 LSP has ATT = 1, so R1 installs the default route i*L1 0.0.0.0/0 toward R2. The * after an LSP ID marks the router’s own LSP.
21. Troubleshooting Checklist
Adjacency won’t come up
- Level mismatch: L1 vs L2-only, or
circuit-typedoesn’t match on both ends. - Area mismatch on L1: L1 adjacencies require a common area address.
- Network type mismatch: one side P2P, the other broadcast. Symptom: the adjacency is stuck in
INITor never appears. - MTU mismatch: padded hellos dropped. Check
show interfaceandclns mtu. Symptom: one side sees the neighbor, the other doesn’t. - Authentication mismatch: key, mode or key ID.
debug isis adj-packetsshows “authentication failed”. - Duplicate System ID: log messages
%CLNS-3-BADPACKETor “Duplicate system ID detected”. - IPv4 subnet mismatch (Cisco LAN): “IP address not in the same subnet”.
- Topology mismatch: single-topology IPv6 on one side, IPv4-only on the other.
- L2 transport issue: LLC/multicast frames filtered by a switch, hypervisor vSwitch, or cloud provider.
Adjacency up but routes missing
- Metric-style mismatch: narrow vs wide — the classic silent killer.
- Interface not enabled for IS-IS (
ip router isismissing) or not passive for loopbacks. advertise passive-onlyhiding transit links you expected to see.- L1 router expecting specific inter-area routes without route leaking.
- Overload bit set (
OL = 1) — the router is excluded from transit. - LSP authentication (area/domain password) mismatch: adjacency is up but LSPs are rejected. Check
show isis database— the LSPs will be missing. - Better AD from another protocol (e.g. OSPF at 110) winning in the RIB.
Instability
- Watch
show isis spf-logfor frequent SPF runs and their triggering LSP. - Look for LSP sequence numbers incrementing rapidly — often a duplicate System ID or a flapping link.
- Use the Purge Originator ID TLV to find who is purging LSPs.
22. Design Best Practices
- Use
metric-style wideeverywhere, and define a metric policy (bandwidth- or latency-based). Don’t rely on the default of 10. - Go flat L2 first. A single L2 domain with a few hundred routers is fine on modern hardware; introduce L1 areas only when there’s a real scaling or failure-domain reason. If you do, make edge routers
level-1and corelevel-2-onlyto avoid the double-database overhead of L1/L2 everywhere. - Set
isis network point-to-pointon all router-to-router Ethernet links. - Advertise loopbacks only (
advertise passive-only) when running BGP/MPLS on top, keeping the IGP small. - Use hierarchical System IDs derived from loopback IPs and enable dynamic hostname.
- Set the overload bit on startup (
wait-for-bgp) on routers that carry BGP transit traffic. - Increase LSP lifetime/refresh (65535/65000) to reduce background flooding.
- Tune SPF/PRC/LSP-gen throttling and add BFD + TI-LFA for fast convergence.
- Use multi-topology for IPv6.
- Authenticate hellos and LSPs with HMAC (SHA where available).
- Leak loopbacks from L2 into L1 in MPLS networks so LDP/SR has end-to-end /32s.
- Summarize at L1/L2 boundaries where possible (but never summarize PE loopbacks in MPLS-LDP networks).
23. Key RFCs and References
- ISO/IEC 10589:2002 — IS-IS intra-domain routing protocol (also published as RFC 1142)
- RFC 1195 — Use of OSI IS-IS for routing in TCP/IP and dual environments
- RFC 2973 — IS-IS Mesh Groups
- RFC 5120 — M-ISIS: Multi-Topology Routing in IS-IS
- RFC 5301 — Dynamic Hostname Exchange
- RFC 5302 — Domain-wide Prefix Distribution (route leaking, up/down bit)
- RFC 5303 — Three-Way Handshake for P2P Adjacencies
- RFC 5304 — IS-IS Cryptographic Authentication (HMAC-MD5)
- RFC 5305 — IS-IS Extensions for Traffic Engineering (wide metrics)
- RFC 5306 — Restart Signaling for IS-IS (graceful restart)
- RFC 5308 — Routing IPv6 with IS-IS
- RFC 5309 — Point-to-Point Operation over LAN
- RFC 5310 — IS-IS Generic Cryptographic Authentication (HMAC-SHA)
- RFC 6232 — Purge Originator Identification TLV
- RFC 7794 — IS-IS Prefix Attributes
- RFC 7981 — IS-IS Router Capability TLV
- RFC 8570 — IS-IS TE Metric Extensions
- RFC 8667 — IS-IS Extensions for Segment Routing
- RFC 9350 — IGP Flexible Algorithm
- RFC 9352 — IS-IS Extensions for SRv6
- RFC 9667 — Dynamic Flooding on Dense Graphs
- Book: IS-IS: Deployment in IP Networks — Russ White & Alvaro Retana
- Book: The Complete IS-IS Routing Protocol — Hannes Gredler & Walter Goralski
Summary: IS-IS is a small, robust link-state protocol. It runs directly over Layer 2, identifies routers by OSI NETs, and organizes the network into Level-1 areas and a contiguous Level-2 backbone, with area borders on links. Its type-length-value (TLV) encoding has let it absorb IPv6, traffic engineering, Segment Routing, SRv6 and Flex-Algo without major redesign. Configure wide metrics, use point-to-point links, keep the design flat, and use the overload bit — and IS-IS will scale reliably.