7.3 First Hop Redundancy Protocols: HSRP and VRRP Implementation and Failover
Key Takeaways
First Hop Redundancy Protocols (FHRPs) eliminate single points of failure for client default gateways by binding multiple physical routers into a single logical gateway sharing a Virtual IP (VIP) and Virtual MAC (VMAC).
Hot Standby Router Protocol (HSRP / RFC 2281) transitions through six finite states (Initial, Learn, Listen, Speak, Standby, Active), electing one Active router to forward data plane traffic and one Standby router to provide hot failover.
HSRPv1 is limited to 256 groups and uses MAC 0000.0c07.acXX with multicast 224.0.0.2, whereas HSRPv2 scales to 4,096 groups, uses MAC 0000.0c9f.fXXX with multicast 224.0.0.102 (IPv6 FF02::66), and supports millisecond timers.
Preemption allows a recovering primary router with higher priority to reclaim the Active forwarding role, but must be configured with preemption delay (standby preempt delay minimum) to prevent blackholing traffic while routing protocols converge.
Virtual Router Redundancy Protocol (VRRP / RFC 5798) is an open standard that elects a Master and Backup routers using virtual MAC 0000.5e00.01XX, enables preemption by default, and assigns priority 255 to an IP Address Owner.
First Hop Redundancy Protocols: HSRP and VRRP Implementation and Failover
In standard enterprise campus networks, endpoint devices (such as workstations, access points, IP phones, and medical systems) are statically configured or assigned via DHCP with a single IPv4 default gateway address. If the physical switch or router hosting that gateway interface fails, all outbound traffic from that subnet is halted—even if a fully functional secondary uplink or redundant router exists on the same local segment.
First Hop Redundancy Protocols (FHRPs) eliminate this single point of failure by sharing a Virtual IP (VIP) and a Virtual MAC (VMAC) address across two or more physical routers. Endpoints target the shared VIP as their default gateway. The active router responds to client ARP queries with the VMAC and forwards egress data frames. If the primary gateway fails, the backup router takes ownership of the VIP and VMAC within seconds or milliseconds without requiring endpoint reconfiguration.
Hot Standby Router Protocol (HSRP) Architecture
Hot Standby Router Protocol is a Cisco-proprietary gateway redundancy mechanism defined in RFC 2281 (for HSRPv1). HSRP assigns distinct operational roles to participating routers within a redundancy group:
- Active Router: The primary router currently forwarding data packets sent to the virtual MAC address. The Active router responds to host ARP requests for the virtual IP and transmits periodic Hello packets to signal health.
- Standby Router: The designated secondary router that continuously monitors Hello packets from the Active router. If the Active router ceases transmitting hellos before the hold timer expires, the Standby router promotes itself to Active.
- Listen / Other Routers: In topologies with three or more gateways in the same group, additional routers remain in the Listen state. They do not send hello packets, but track state to replace the Standby router if it promotes to Active.
[Enterprise Core / WAN]
| |
+------------+ +------------+
| |
+--------------------------+ +--------------------------+
| ROUTER 1: Active Gateway | | ROUTER 2: Standby Gateway|
| Priority: 110 (Preempt) | | Priority: 100 |
| IP: 10.1.1.2 | | IP: 10.1.1.3 |
+--------------------------+ +--------------------------+
\ /
\ Virtual IP: 10.1.1.1 /
\ Virtual MAC: 0000.0c9f.f00a/
+-------------+------------+
|
[Layer 2 Access Switch]
|
[Client Endpoint (PC)]
Default Gateway: 10.1.1.1
The HSRP Finite State Machine (FSM)
An HSRP-enabled interface transitions through six distinct states during initialization and election:
- Initial (Init): The starting state. The interface has just booted, was un-shut, or HSRP configuration was applied. The state machine is not yet operational.
- Learn: The router has not yet determined the virtual IP address because it was not statically configured on the local interface. It waits to hear a Hello packet from the active router to learn the VIP.
- Listen: The router knows the virtual IP address. It is neither the Active nor Standby router; it listens for Hello packets from other routers.
- Speak: The router transmits periodic Hello packets and actively participates in the election of the Active and Standby routers.
- Standby: The router is the candidate to become the next Active router. It transmits periodic Hello messages. Exactly one router per group resides in the Standby state.
- Active: The router is currently forwarding traffic sent to the virtual MAC address and responding to ARP requests. It transmits periodic Hello messages. Exactly one router per group resides in the Active state.
HSRP Version 1 vs. HSRP Version 2
HSRPv2 introduced critical enhancements over legacy HSRPv1 to support high-density multi-VLAN campus environments, IPv6 routing, and sub-second convergence.
HSRPv1 vs. HSRPv2 Comparison Matrix
| Architectural Feature | HSRP Version 1 (RFC 2281) | HSRP Version 2 |
|---|---|---|
| Group Number Range | 0 to 255 (8-bit) | 0 to 4,095 (12-bit, matching 802.1Q VLAN IDs) |
| IPv4 Virtual MAC Address | 0000.0c07.acXX ( = 2-digit hex group) | 0000.0c9f.fXXX ( = 3-digit hex group) |
| IPv6 Virtual MAC Address | Unsupported | 0005.73a0.0XXX ( = 3-digit hex group) |
| Multicast Destination IP | 224.0.0.2 (All-Routers multicast) | 224.0.0.102 (HSRPv2-specific multicast) |
| IPv6 Multicast Address | Unsupported | FF02::66 |
| Transport Layer Port | UDP port 1985 | UDP port 1985 |
| Timer Granularity | Seconds (Default: Hello 3s / Hold 10s) | Milliseconds (e.g., Hello 200ms / Hold 600ms) |
| Packet Format | Fixed byte structure | Type-Length-Value (TLV) format |
| CGMP Conflict | Yes (Shares 224.0.0.2 with CGMP) | No (Uses dedicated 224.0.0.102) |
Example: An interface configured in HSRPv1 Group 10 () generates virtual MAC 0000.0c07.ac0a. An interface configured in HSRPv2 Group 10 generates virtual MAC 0000.0c9f.f00a.
Priority, Election, Preemption, and Preempt Delay
Election Rules
When multiple routers participate in an HSRP group, election of the Active router is governed by two deterministic criteria:
- Highest Priority Wins: Priority ranges from 1 to 255 (default is 100).
- Tie-Breaker: If priority values are identical, the router with the highest configured physical IPv4 address on the participating interface becomes Active.
Preemption Mechanics
By default, HSRP preemption is disabled. If Router 1 (priority 110) fails, Router 2 (priority 100) assumes the Active role. When Router 1 reboots and returns to service, it will not reclaim the Active role unless configured with standby <group> preempt. Without preemption, Router 1 remains in Standby despite possessing higher priority.
The Critical Role of Preempt Delay
Enabling immediate preemption introduces severe packet blackholing risks during system recovery:
Router Reboot ---> Interface Links UP ---> HSRP Preempts to Active (IMMEDIATE)
| |
v v
[IGP Adjacency Forming (OSPF / BGP)] [Traffic Arriving at Router]
| |
v v
[CEF Hardware FIB Not Yet Populated] [Packets Dropped / Blackholed!]
When a modular switch or router boots, its physical interfaces link up and HSRP transitions to Active in seconds. However, upstream interior gateway protocols (OSPF, EIGRP, BGP) require tens of seconds to exchange database descriptions, compute shortest path trees, and push routing tables into Cisco Express Forwarding (CEF) hardware ASICs.
If the recovering router immediately preempts the Active role, it begins receiving all client outbound traffic before its upstream routing paths exist, dropping packets into a black hole. To prevent this, engineers configure preempt delay:
standby 10 preempt delay minimum 60 reload 180
This command forces the router to wait 60 seconds after interface recovery (or 180 seconds after a chassis reload) before initiating preemption, guaranteeing complete routing table convergence.
Interface Tracking with Enhanced Object Tracking (EOT)
HSRP monitors health through hello packets on the local client-facing LAN interface. However, if the Active router experiences a complete failure of its upstream WAN or core uplink, it continues transmitting HSRP hellos to the LAN, remaining Active while unable to route packets toward the enterprise core.
Enhanced Object Tracking (EOT) links HSRP priority to upstream interfaces, IP routes, or IP SLA probes:
! Define tracking object on upstream core link
track 1 interface GigabitEthernet0/0/1 line-protocol
!
! Apply tracking to LAN interface
interface GigabitEthernet0/0/0
description Client LAN Gateway
ip address 10.1.1.2 255.255.255.0
standby version 2
standby 10 ip 10.1.1.1
standby 10 priority 110
standby 10 preempt delay minimum 60
standby 10 track 1 decrement 20
If GigabitEthernet0/0/1 goes down, Track 1 transitions to down, and HSRP automatically decrements Router 1's priority by 20 (). Because Router 2 possesses priority 100 and preemption enabled, Router 2 immediately promotes to Active, maintaining end-to-end client connectivity.
Virtual Router Redundancy Protocol (VRRP)
VRRP is an open-standard First Hop Redundancy Protocol defined by the IETF in RFC 3768 (VRRPv2 for IPv4) and RFC 5798 (VRRPv3 for IPv4 and IPv6). VRRP operates similarly to HSRP with several distinct protocol variations:
- Roles: VRRP elects one Master Router and one or more Backup Routers.
- Virtual MAC Address: Formatted as
0000.5e00.01XXfor IPv4 ( is the 2-digit hex group) and0000.5e00.02XXfor IPv6. - Multicast Transport: Transmits advertisements to 224.0.0.18 using native IP protocol number 112.
- Default Preemption: Unlike HSRP, preemption is enabled by default in VRRP.
- Timers: Default advertisement interval is 1 second. Backup routers calculate the Master Down Interval as:
- IP Address Owner: VRRP allows the virtual IP address to match the real physical interface IP address configured on a router. When this occurs, that router is designated the IP Address Owner, and its priority is locked at 255 (the maximum possible priority). An IP Address Owner always preempts all other routers.
Comparison: HSRP vs. VRRP
| Protocol Feature | Cisco HSRP (v1 / v2) | IETF VRRP (v2 / v3) |
|---|---|---|
| Standardization | Cisco Proprietary (RFC 2281) | Open IETF Standard (RFC 5798) |
| Router Roles | Active, Standby, Listen | Master, Backup |
| Default Preemption | Disabled (Requires explicit configuration) | Enabled by default |
| Virtual MAC (IPv4) | v1: 0000.0c07.acXX / v2: 0000.0c9f.fXXX | 0000.5e00.01XX |
| Virtual MAC (IPv6) | 0005.73a0.0XXX | 0000.5e00.02XX |
| Multicast Address | v1: 224.0.0.2 / v2: 224.0.0.102 | 224.0.0.18 (IP Protocol 112) |
| Timer Intervals | Default: 3s Hello / 10s Hold | Default: 1s Advertisement / ~3s Master Down |
| IP Address Owner | Virtual IP should not match physical IP | Can match physical IP (Priority locked at 255) |
CLI Configuration and Verification Walkthrough
Cisco IOS-XE VRRPv3 Configuration
interface GigabitEthernet0/0/0
description LAN Gateway Interface
ip address 10.1.1.2 255.255.255.0
fhrp version vrrp v3
vrrp 1 address-family ipv4
priority 120
preempt delay minimum 30
track 1 decrement 30
address 10.1.1.1 primary
Operational Verification Commands
Router# show standby brief
P indicates configured to preempt.
|
Interface Grp Pri P State Active Standby Virtual IP
Gi0/0/0 10 110 P Active local 10.1.1.3 10.1.1.1
Router# show standby
GigabitEthernet0/0/0 - Group 10 (version 2)
Local state is Active, priority 110 (configured 110), may preempt
Preemption delay min 60 secs, reload 180 secs
Hellos sent 1492, received 218
Virtual IP address is 10.1.1.1
Active router is local
Standby router is 10.1.1.3, priority 100 (expires in 8.412 sec)
Virtual MAC address is 0000.0c9f.f00a (v2 default)
Tracking 1 object, state Up, decrement 20
Router# show vrrp brief
Interface Grp A-F Pri Time Own Pre State Master addr Group addr
Gi0/0/0 1 IPv4 120 1000 N Y MASTER 10.1.1.2 10.1.1.1
What is the Virtual MAC address and destination multicast IP address utilized by a Cisco router participating in HSRP Version 2 Group 16 (0x010 in hexadecimal)?
Virtual MAC 0000.0c07.ac10 and Multicast 224.0.0.2
Virtual MAC 0000.0c9f.f010 and Multicast 224.0.0.102
Virtual MAC 0000.5e00.0110 and Multicast 224.0.0.18
Virtual MAC 0000.0c9f.fac1 and Multicast 224.0.1.1
Following a power outage, an enterprise router configured with HSRP priority 120 and preemption enabled reboots. Immediately upon interface link-up, client outbound Internet access fails intermittently for two minutes even though the router reports its state as Active. Which configuration modification prevents this issue?
Decrease HSRP priority from 120 to 100 so the peer router retains the Active role permanently
Change the HSRP group number to force all client workstations to clear their ARP cache entries
Configure HSRP MD5 authentication to ensure routing protocol packets are prioritized over HSRP hellos
Configure 'standby preempt delay minimum' so routing and CEF converge before the router preempts
In a Virtual Router Redundancy Protocol (VRRP) implementation, what specific condition assigns a router a fixed priority of 255?
The router is configured with the virtual IP address matching its own physical interface IP address as the IP Address Owner
The router has the highest physical MAC address among all participating routers in the broadcast domain
The router is configured with object tracking linked to a functioning upstream BGP peering session
The router is operating in VRRPv3 millisecond timer mode while preemption is administratively disabled
Sections you finish are checked off in the contents.