8.1 Multicast Addressing, IGMPv2/v3 Host Membership, and the RPF Check

Key Takeaways

  • Multicast optimizes one-to-many and many-to-many traffic delivery by replicating packets only at branching nodes, dramatically reducing source server utilization and WAN link saturation compared to replicated unicast streams.

  • The IPv4 Class D multicast address space (224.0.0.0/4) spans 224.0.0.0 to 239.255.255.255, encompassing Link-Local Reserved (224.0.0.0/24 with TTL 1), Globally Scoped (224.0.1.0 to 238.255.255.255), Source-Specific Multicast (232.0.0.0/8), and Administratively Scoped private ranges (239.0.0.0/8).

  • Layer 2 Ethernet multicast MAC addresses map the lower 23 bits of a Class D IP address into the prefix 01:00:5E:00:00:00/25 (range 01:00:5E:00:00:00 to 01:00:5E:7F:FF:FF), discarding 5 bits and resulting in a 32-to-1 IP-to-MAC address overlap ambiguity.

  • The Internet Group Management Protocol (IGMP) manages host group membership, advancing from basic query-response timeouts in IGMPv1, to low-latency Leave Group signaling and lowest-IP querier election in IGMPv2, to source-filtering INCLUDE and EXCLUDE modes in IGMPv3.

  • Reverse Path Forwarding (RPF) prevents packet loops and storms by validating that incoming multicast packets arrive on the specific interface the unicast routing table uses to reach the packet source IP address; non-matching packets are discarded.

Last updated: October 2026

Multicast Addressing, IGMPv2/v3 Host Membership, and the RPF Check

Enterprise network infrastructures rely on IP multicast to distribute high-volume, real-time data—such as financial market data feeds, live video broadcasts, software distribution packages, and distributed telemetry—from one or more senders to multiple interested receivers simultaneously. Unlike unicast transmission, which duplicates packets for every individual client and saturates server interfaces and network backbones, multicast transmits a single datagram along shared network paths, replicating packets only at network branching points. Understanding multicast addressing structures, Layer 2 mapping rules, host signaling protocols, and loop-prevention mechanics is essential for managing resilient enterprise networks.

Multicast Fundamentals and Bandwidth Optimization

In a traditional unicast model, if a streaming media server transmits a 5 Mbps high-definition video stream to 500 branch office users, the server network interface card (NIC) and local access switch must generate and forward 500 separate streams totaling 2.5 Gbps of egress traffic. This design leads to severe compute exhaustion on application servers and rapid WAN link congestion. Broadcast transmission solves server duplication by transmitting a single packet to all endpoints, but it forces every device on the broadcast domain—regardless of whether it requested the stream—to interrupt its CPU to process the frame, disrupting non-participating endpoints and creating broadcast domain boundaries that routers refuse to cross.

Multicast resolves both challenges. The source server transmits a single packet addressed to a logical multicast group. Upstream and downstream routers maintain state tables that dynamically replicate the packet only when traversing links that lead to active, verified listeners. Devices that have not requested the traffic do not receive the stream, conserving both network link bandwidth and host processor cycles.

IPv4 Multicast Addressing Architecture (Class D)

IPv4 allocates the Class D address space, spanning 224.0.0.0 through 239.255.255.255 (designated by the high-order bit prefix 1110 in binary, or /4 in CIDR notation), exclusively for multicast groups. Class D addresses do not define individual network hosts; instead, they represent arbitrary group destinations that multiple hosts dynamically join and leave. The Internet Assigned Numbers Authority (IANA) partitions Class D into distinct functional blocks:

  • Link-Local Reserved Multicast (224.0.0.0/24): Reserved for control plane protocols operating within a single local broadcast domain. Network routers must never forward packets destined for this block outside the local subnet, and they transmit them with an IP Time-to-Live (TTL) value of 1. Notable standard assignments include:
    • 224.0.0.1: All systems (hosts and routers) on the local subnet.
    • 224.0.0.2: All multicast routers on the local subnet.
    • 224.0.0.5: All OSPF routers.
    • 224.0.0.6: All OSPF Designated Routers (DR) and Backup Designated Routers (BDR).
    • 224.0.0.9: RIPv2 routers.
    • 224.0.0.10: EIGRP routers.
    • 224.0.0.13: Protocol Independent Multicast version 2 (PIMv2) routers.
  • Globally Scoped Multicast (224.0.1.0 – 238.255.255.255): Allocated for public multicast services routed globally across the public Internet and private enterprise backbones. Prominent examples include 224.0.1.1 for Network Time Protocol (NTP) and Cisco Auto-RP discovery groups (224.0.1.39 and 224.0.1.40).
  • Source-Specific Multicast (SSM) Block (232.0.0.0/8): Standardized under RFC 4607, this range is dedicated to SSM applications. Receivers specify both the group address within 232.0.0.0/8 and the unicast IP of the source, eliminating the need for shared Rendezvous Points.
  • Administratively Scoped Multicast (239.0.0.0/8): Defined under RFC 2365 as private multicast space, analogous to RFC 1918 private unicast addressing. Enterprises utilize this block for internal business applications, and perimeter boundary filters prevent these addresses from leaking across external autonomous system boundaries.

Multicast Address Allocation Ranges

Multicast Address RangePrefix / CIDROperational ScopeRouting / Forwarding Behavior
224.0.0.0 – 224.0.0.255224.0.0.0/24Link-Local ControlConfined to local subnet; TTL=1; never routed
224.0.1.0 – 231.255.255.255224.0.1.0/24+Globally ScopedRouted across enterprise networks and Internet
232.0.0.0 – 232.255.255.255232.0.0.0/8Source-Specific MulticastRouted via direct Shortest Path Trees with IGMPv3
233.0.0.0 – 238.255.255.255VariousGLOP / ScopedGlobally routed; 233.0.0.0/8 embeds autonomous system numbers
239.0.0.0 – 239.255.255.255239.0.0.0/8Administratively ScopedPrivate enterprise internal use; blocked at WAN/ISP perimeter

Layer 2 MAC Address Mapping and the 32:1 Overlap

Ethernet switches do not interpret Layer 3 IP packet headers during standard switching operations. To deliver multicast frames across local Ethernet segments, Layer 3 Class D IP addresses must map into Layer 2 IEEE 802.3 MAC addresses.

IANA acquired the Organizationally Unique Identifier (OUI) block 01:00:5E:00:00:00 through 01:00:5E:FF:FF:FF for Ethernet multicast. Because the least significant bit of the first octet is 1 (binary 00000001), Ethernet switches recognize the frame as a multicast destination. However, IANA allocated only half of this OUI space for IPv4 multicast mapping. The 25th bit is fixed as a binary 0, establishing the valid MAC address pool as 01:00:5E:00:00:00 to 01:00:5E:7F:FF:FF. This leaves exactly 23 bits of the MAC address available for mapping the IP destination.

IPv4 Class D Address (32 bits):
+---------+-------+-----------------------------------------------+
|  1 1 1 0| 5 Bits|               Lower 23 Bits                   |
| (Class D| Discarded                                             |
+---------+-------+-----------------------------------------------+
    Fixed    Lost                        |
   4 Bits    Bits                        | (Copied directly)
                                         v
Ethernet Multicast MAC Address (48 bits):
+-------------------------------+---+-----------------------------+
|        01 : 00 : 5E           | 0 |       Lower 23 Bits         |
|         (24-Bit OUI)          |Bit|         from IPv4           |
+-------------------------------+---+-----------------------------+

An IPv4 Class D address contains 32 bits, of which the first 4 bits are fixed (1110), leaving 28 variable bits. When mapping these 28 bits into the 23 available MAC address bits, the 5 high-order variable bits of the IP address are discarded:

  • 28 variable bits minus 23 mapped bits equals 5 unmapped bits.
  • 2 raised to the 5th power equals 32.

Because 5 bits are dropped, exactly 32 distinct IPv4 multicast addresses map to the exact same Layer 2 MAC address. For example:

  • 224.1.1.1
  • 224.129.1.1
  • 225.1.1.1
  • 239.1.1.1

All four addresses translate to MAC address 01:00:5E:01:01:01. Consequently, a host network interface card (NIC) listening to 224.1.1.1 will accept frames destined for 239.1.1.1 at Layer 2. The host operating system network stack must inspect the Layer 3 IP header and discard irrelevant packets, incurring minor host CPU overhead.

Internet Group Management Protocol (IGMP) Versions

The Internet Group Management Protocol (IGMP) operates between client hosts and their local last-hop multicast router (LHR) across an access LAN, enabling hosts to join, maintain, and leave multicast groups.

  • IGMPv1 (RFC 1112): Employs a basic query-response mechanism. Routers transmit periodic General Queries to 224.0.0.1 (every 60 or 125 seconds). Hosts reply with a Membership Report for each group they wish to receive. To prevent report storms, hosts use a randomized response timer; if another host sends a report first, adjacent hosts suppress their own reports. IGMPv1 lacks an explicit leave message. When a host exits a group, it simply stops reporting. The router continues forwarding traffic until the group membership timeout (typically 3 minutes) expires without receiving a report. In IGMPv1, the querier router is selected by the active multicast routing protocol (such as the PIM Designated Router).
  • IGMPv2 (RFC 2236): Introduces major performance enhancements:
    • Explicit Leave Group Message: Hosts transmit a Leave Group message to 224.0.0.2 (all routers) when exiting a group.
    • Group-Specific Query: Upon receiving a Leave Group message, the router immediately broadcasts a Group-Specific Query addressed to that specific group to determine if any remaining hosts require the stream.
    • Tunable Timers: The router sets the Last Member Query Interval (default 1 second) and Last Member Query Count (default 2), reducing leave latency from minutes down to 2–3 seconds.
    • Native Querier Election: Subnets with multiple routers automatically elect the router with the lowest numerical IP address as the active IGMP querier.
  • IGMPv3 (RFC 3376): Introduces source filtering, enabling hosts to request streams from specific source IP addresses:
    • INCLUDE Mode: The host requests traffic destined for group G only from the specified source list (INCLUDE {S1, S2}).
    • EXCLUDE Mode: The host requests traffic destined for group G from all sources except those specified (EXCLUDE {S3}).
    • SSM Enablement: IGMPv3 is mandatory for Source-Specific Multicast. Hosts send reports directly to 224.0.0.22 (all IGMPv3 routers).

Comparison of IGMP Protocol Versions

FeatureIGMPv1 (RFC 1112)IGMPv2 (RFC 2236)IGMPv3 (RFC 3376)
Querier ElectionOutsourced to PIM DRNative; lowest numerical IP addressNative; lowest numerical IP address
Query Destination224.0.0.1 (All systems)224.0.0.1 (General), Group IP (Specific)224.0.0.1 (General), Group IP (Specific)
Report DestinationGroup multicast addressGroup multicast address224.0.0.22 (All IGMPv3 routers)
Leave MechanismNone; silent timeout (3 mins)Explicit Leave Group to 224.0.0.2Explicit Leave via state report
Group Leave LatencyHigh (~3 minutes)Low (2–3 seconds via Group Query)Low (immediate source-state update)
Source FilteringNo support (Any-Source)No support (Any-Source)Supported (INCLUDE / EXCLUDE)
Primary Use CaseLegacy networksStandard PIM-SM (*, G) groupsSource-Specific Multicast (SSM)

Layer 2 Multicast Optimization: IGMP Snooping

Because Ethernet switches operate at Layer 2, they treat multicast frames whose MAC addresses are unrecorded in their Content Addressable Memory (CAM) tables as unknown unicast/broadcast traffic, flooding them out all ports within the VLAN. This floods non-participating access ports and exhausts endpoint bandwidth.

IGMP Snooping resolves this issue. The switch inspects (snoops) IGMP control frames passing between hosts and upstream routers. By parsing IGMP Membership Reports and Leave messages, the switch maps specific physical switch ports to individual multicast MAC and IP addresses in its Layer 2 forwarding table. Multicast streams are forwarded strictly to ports with active, validated listeners and to ports identified as connecting to multicast routers (mrouter ports).

Reverse Path Forwarding (RPF) Check Mechanics

In unicast routing, a router forwards a packet based entirely on its destination IP address, oblivious to where the packet originated. In multicast forwarding, routers face a fundamentally different challenge: multicast packets are sent to an abstract group address, not a physical endpoint. If a router forwarded multicast packets using only destination lookups, loops would duplicate packets indefinitely, crashing the network.

To eliminate loops, all multicast routing protocols enforce the Reverse Path Forwarding (RPF) check. Multicast routing dictates that a packet is only accepted and forwarded if it arrives on the specific interface used by the router's unicast routing table to reach the source of the packet.

       [Multicast Source: 10.1.1.50]
                     |
                     v
             +---------------+
             |   Router R1   |
             +---------------+
              /             \
  (Gi0/1)    /               \    (Gi0/2)
  Primary   /                 \   Alternate
  Unicast  /                   \  Path
  Path    v                     v
     +-------------------------------+
     |           Router R2           |
     |  Unicast Route to 10.1.1.50:  |
     |    Next-Hop via Gi0/1         |
     +-------------------------------+
       | Packet on Gi0/1: RPF PASS -> Forward to OIL
       | Packet on Gi0/2: RPF FAIL -> Silently Drop Packet

Step-by-Step RPF Lookup Walkthrough

  1. A multicast packet with source IP 10.1.1.50 and destination group 239.10.10.1 arrives on Router R2 interface GigabitEthernet0/1.
  2. Router R2 extracts the source address 10.1.1.50 and executes a unicast routing lookup in its Routing Information Base (RIB) or Cisco Express Forwarding (CEF) table.
  3. The routing table indicates that the best path to reach 10.1.1.50/32 is via next-hop 192.168.12.1 exiting interface GigabitEthernet0/1.
  4. Router R2 compares the incoming interface (GigabitEthernet0/1) with the unicast egress interface (GigabitEthernet0/1). Because they match, the RPF check passes.
  5. Router R2 replicates the packet and forwards it out all interfaces in the Outgoing Interface List (OIL) for (10.1.1.50, 239.10.10.1).
  6. If an identical packet arrives on GigabitEthernet0/2, R2 evaluates the source. Because GigabitEthernet0/2 does not match the unicast path back to 10.1.1.50, the RPF check fails. The packet is immediately dropped, and the RPF drop counter increments.

Diagnosing and Resolving RPF Failures

RPF failures commonly arise from asymmetric routing topologies, where outbound unicast paths differ from inbound paths, or where static default routes mask more specific transit interfaces. Network engineers diagnose RPF status in Cisco IOS XE using the command:

Router2# show ip rpf 10.1.1.50
RPF information for ? (10.1.1.50)
  RPF interface: GigabitEthernet0/1
  RPF neighbor: ? (192.168.12.1) - Directly connected
  RPF route/mask: 10.1.1.0/24
  RPF type: unicast (ospf 1)
  Doing distance-preferred lookups across tables
  RPF topology: IPv4 Multicast Base, pass

If an asymmetric unicast path prevents multicast packets from arriving on the expected interface, administrators configure a static multicast route (ip mroute) to override the unicast RIB for RPF validation:

Router2(config)# ip mroute 10.1.1.0 255.255.255.0 192.168.22.1

This command instructs the multicast forwarding engine to treat 192.168.22.1, reached through GigabitEthernet0/2, as the RPF neighbor for traffic originating from subnet 10.1.1.0/24, resolving the failure without altering unicast traffic patterns.

Test Your Knowledge

How many IPv4 Class D multicast addresses map to a single Ethernet multicast MAC address, and what causes this overlap?

A

16 addresses, because 4 bits of the 28-bit Class D address space are omitted during translation

B

32 addresses, because 5 of the 28 variable Class D bits are dropped when 23 bits are copied into the MAC

C

64 addresses, because the lower 6 bits of the OUI are reserved for Token Ring backward compatibility on legacy switches

D

128 addresses, because the first 7 bits of the Class D IPv4 header are replaced by the IANA-assigned OUI prefix

Test Your Knowledge

A network administrator observes significant multicast latency when receivers leave groups on an older network segment running IGMPv1. What operational enhancement in IGMPv2 directly mitigates this delay?

A

IGMPv2 introduces source-filtering INCLUDE and EXCLUDE lists that discard unneeded source streams at the switch port

B

IGMPv2 requires the host to notify upstream rendezvous points directly via unicast PIM Register messages

C

IGMPv2 adds an explicit Leave Group message sent to 224.0.0.2, followed by a Group-Specific Query from the querier

D

IGMPv2 replaces periodic queries with bidirectional forwarding detection keepalives operating at 50-millisecond intervals

Test Your Knowledge

A router receives a multicast packet with source IP 192.168.10.25 on interface GigabitEthernet0/2. The router's unicast routing table lists the next-hop for 192.168.10.0/24 via 10.1.1.1 on interface GigabitEthernet0/1. What action does the router take with the arriving multicast packet?

A

The router silently drops the packet because it failed the Reverse Path Forwarding (RPF) check

B

The router queues the packet and sends an ICMP Redirect message back to interface GigabitEthernet0/2

C

The router encapsulates the packet into a unicast PIM Register message and forwards it to the Rendezvous Point

D

The router accepts the packet and updates its unicast routing table to point to interface GigabitEthernet0/2

Sections you finish are checked off in the contents.