skip to content

How does a first-hop redundancy protocol such as VRRP keep a LAN's static default gateway working when one router fails?

level: juniorimportance: must knowfreq 58%

answer

  1. hosts never change their config
  2. one address shared by routers
  3. virtual MAC that stays put
  4. only the Active Router forwards
  5. Backup takes over on silence

basics

~20 s

Routers share one virtual gateway IP and one virtual MAC; an election makes one Active, which answers ARP and forwards. If its advertisements stop, a Backup claims the same addresses, so hosts keep their configured gateway unchanged.

solid answer

~50 s

Hosts configured with a static default gateway, or one handed out by DHCP, cannot detect a dead router themselves, so that gateway is a single point of failure. A first-hop redundancy protocol makes several routers present one **virtual router**: a virtual IP that hosts use as their gateway, and a virtual MAC that the forwarding router returns in ARP replies. In VRRP (RFC 9568) the routers elect an **Active Router** by priority; it alone forwards frames sent to the virtual MAC and multicasts an advertisement to `224.0.0.18` every interval. Backup Routers stay silent and listen. When advertisements stop for about three intervals, the highest-priority Backup becomes Active, claims the same virtual MAC and starts forwarding. Because the IP-to-MAC binding in each host's ARP cache never changes, hosts carry on unaware; only the switches relearn which port the virtual MAC sits behind.

go deeper

for a junior

Recall the picture: one virtual IP and one virtual MAC shared by two routers, one Active forwarding and one Backup listening, and hosts that never notice the swap.

for a middle

Explain why the virtual MAC keeps host ARP caches valid, how a Backup decides the Active Router is gone, and why switches must relearn the MAC's port.

for a senior

Show what the protocol does not cover: a live router with a dead uplink, Accept_Mode surprises when monitoring by ping, and two Active Routers when the pair cannot hear each other.

for a principal

Place the FHRP inside a gateway-resilience budget: its failover time, the upstream routing convergence that must follow it, and when routing at the access layer removes the need for it.

## The problem: a default gateway is a single point of failure Most hosts on a LAN send every off-subnet packet to one **default gateway**, an address that is either typed in statically or handed out by DHCP. The host keeps that one address and has no way to tell that the router behind it has died: it keeps resolving the same address and keeps sending frames into a void. RFC 9568, the VRRP specification, opens with exactly this problem: a manually configured default route is popular because it costs the host nothing, but losing the default router isolates every host that cannot detect an alternate path. Running a routing protocol on every host would solve it, but adds configuration, processing and security exposure to every endpoint. IPv6 Neighbor Unreachability Detection can switch routers, but RFC 9568 notes that with default parameters it can take more than 10 seconds. A **first-hop redundancy protocol** (FHRP) fixes the problem on the router side instead, so the hosts change nothing. ## The virtual router The routers that can act as the gateway run the protocol together and present one **virtual router** to the hosts: - a **virtual IP address**, configured on the hosts as their default gateway; - a **virtual MAC address**, which the router currently forwarding returns in its ARP replies (IPv4) or Neighbor Advertisements (IPv6); - a **Virtual Router Identifier** (VRID, 1-255) that names the group on the LAN. In VRRP the virtual MAC is derived from the VRID: `00-00-5E-00-01-{VRID}` for IPv4 and `00-00-5E-00-02-{VRID}` for IPv6, from a block IANA allocated to the protocol. VRID 10 on an IPv4 LAN therefore uses `00-00-5E-00-01-0A`. Whichever router holds the role, the MAC stays the same. ## Election and failover, step by step 1. Each router has a **priority** for the virtual router. In VRRP, 1-254 is for routers backing the address up (the default is 100), and 255 is reserved for the router that owns the virtual address as a real interface address. 2. The highest priority becomes the **Active Router**. It answers ARP for the virtual IP with the virtual MAC, forwards every frame addressed to that MAC, and sends an advertisement to `224.0.0.18` (IPv4) or `ff02::12` (IPv6) every advertisement interval, 1 second by default. 3. The other routers are **Backup Routers**. They must not answer ARP for the virtual IP and must discard frames sent to the virtual MAC, but they listen to the advertisements. 4. If a Backup hears nothing for its `Active_Down_Interval` (three advertisement intervals plus a small priority-based skew, about 3.6 seconds with defaults), it declares the Active Router dead, becomes Active and announces the virtual MAC. 5. The hosts' next frames to the gateway reach the new Active Router; only the switches had to relearn where the virtual MAC lives. A router shutting down gracefully does better: it sends an advertisement with priority 0, and the Backups take over after only the skew time instead of the full interval. ## What hosts and switches see | Component | Before failover | After failover | |---|---|---| | Host default gateway | virtual IP | unchanged | | Host ARP cache entry | virtual IP -> virtual MAC | unchanged | | Switch MAC table | virtual MAC behind router A's port | relearned behind router B's port | | Forwarding router | router A (Active) | router B (new Active) | The switches relearn because the Active Router sources its advertisements from the virtual MAC and announces the address when it takes over; that announcement, a gratuitous ARP in IPv4, is a subject of its own. The point of the design is that nothing in the host is touched. ## The protocols in this family - **VRRP**, the IETF standard. Version 3 (RFC 9568, which obsoletes RFC 5798) covers IPv4 and IPv6 and renamed the old "Master" role **Active**; version 2 (RFC 3768) is IPv4 only. - **HSRP**, a vendor protocol documented in Informational RFC 2281. It elects an **active** and a **standby** router, and its virtual address must differ from every router's interface address. - **GLBP**, another vendor protocol with no RFC. It keeps one virtual IP but hands different virtual MACs to different hosts so that several routers forward at once. ## What an FHRP does not do It protects the first hop only. If the Active Router is alive but its uplink is dead, a plain FHRP keeps sending hosts to it; implementations add priority **tracking** for that case. It does not choose how traffic leaves the routers upstream, which is the routing protocols' job, and it does not replace DHCP, which merely tells hosts which gateway address to use.

  • Why does VRRP use a virtual MAC address instead of letting the new Active Router answer ARP with its own MAC?
    If each router answered with its own MAC, every host's ARP cache would still hold the dead router's MAC after a failover and keep sending there until the entry was replaced. With a virtual MAC the IP-to-MAC binding in hosts never changes; only the switches relearn the port. RFC 9568 says the Active Router MUST NOT answer ARP with its physical MAC for exactly this reason.
  • In VRRP, why can a ping to the virtual gateway IP go unanswered after a failover even though forwarding through it works?
    RFC 9568's `Accept_Mode` defaults to False: an Active Router that is not the address owner forwards frames sent to the virtual MAC but must not accept packets addressed to the virtual IP itself, so ICMP echo to the gateway goes unanswered. Forwarding is unaffected. Deployments that monitor the gateway by pinging it set `Accept_Mode` to True.
  • How do IPv6 hosts learn a VRRP virtual router as their default gateway?
    IPv6 hosts normally learn default routers from Router Advertisements. Under RFC 9568 the Active Router sends Router Advertisements for the virtual router, whose first address must be a link-local address, and Backup Routers must not send them. On takeover the new Active Router sends unsolicited Neighbor Advertisements mapping the virtual address to `00-00-5E-00-02-{VRID}`.

A virtual gateway is like a shop's published phone number that rings whichever clerk is on duty: customers never learn a clerk's personal number, so when one clerk leaves, the next answers the same line and nobody has to dial anything new.

saying these in an interview costs you the question

  • Hosts must be reconfigured with the backup router's address after a gateway failure.
  • The new Active Router answers ARP with its own physical MAC address.
  • Every router in a VRRP group forwards traffic for the virtual IP at the same time.
  • Backup Routers send advertisements too, so each router's liveness is monitored.
  • VRRP notices a dead uplink on the Active Router by itself, without tracking.