skip to content

In VRRP (RFC 9568), how is the Active Router elected, and what do priority 255, priority 0 and preemption change?

level: middleimportance: must knowfreq 38%

answer

  1. highest priority wins
  2. equal priority does not preempt
  3. 255 means address owner
  4. zero means stepping down
  5. Preempt_Mode defaults to True

basics

~20 s

The highest-priority VRRP router becomes Active; if two Active Routers tie, the higher primary IP wins. Priority 255 marks the address owner, which always preempts; priority 0 signals a graceful exit. Preemption, on by default, lets a strictly higher-priority Backup reclaim the role.

solid answer

~50 s

Each VRRP router has a priority per virtual router: 1-254 for routers backing the address up (default 100), and 255, reserved for the **address owner** whose real interface carries the virtual IP. The owner goes straight to Active at startup; the others start as Backup and become Active only when their `Active_Down_Timer` expires. A Backup with `Preempt_Mode` True (the default) ignores advertisements of lower priority than its own, lets its down timer expire and takes over; the old Active steps down when it hears the higher priority. A Backup never preempts an **equal** priority; the primary-IP tie-break applies only when two Active Routers meet. Priority **0** is a resignation: an Active Router shutting down sends it, and Backups take over after only `Skew_Time`. With preemption off, the first router to become Active keeps the role until it fails, except the owner, which always preempts.

go deeper

for a junior

Remember the three special values: 255 is the router that owns the address, 1 to 254 are backups with 100 as default, and 0 means the Active Router is leaving.

for a middle

Walk the state machine: owner straight to Active, others via Backup and the down timer, how Preempt_Mode treats lower, equal and higher advertisements, and the primary-IP tie-break.

for a senior

Explain why preemption takes a full down interval, why ties never preempt, and why owner configurations make reboots and tracking harder to control.

for a principal

Argue when preemption should be off entirely, trading a deterministic gateway placement against the outages a reclaiming router causes before upstream routing is ready.

## The priority field Every VRRP advertisement carries an 8-bit **Priority**. RFC 9568 gives its values fixed meanings: | Value | Meaning | |---|---| | 255 | The **IPvX address owner**: the router whose real interface address is the virtual IP | | 1-254 | Routers backing the virtual router up; the default is 100 | | 0 | The current Active Router has stopped participating and is handing over | Higher values mean higher preference. This is the opposite direction from spanning tree's bridge ID, where the lowest value wins, and confusing the two is a common slip. ## How the election runs VRRP has only three states (Initialize, Backup and Active) and one message type, the ADVERTISEMENT. From startup: 1. A router whose priority is 255 sends an advertisement, announces the virtual MAC and goes **straight to Active**. Nothing else is compared. 2. Any other router goes to **Backup** and starts its `Active_Down_Timer` at `Active_Down_Interval = 3 x Active_Adver_Interval + Skew_Time`, where `Skew_Time = ((256 - Priority) x Active_Adver_Interval) / 256`. 3. If an advertisement arrives in time, the Backup resets its timer and stays Backup, unless preemption tells it to ignore that advertisement (see below). 4. If the timer fires, the Backup becomes Active and starts advertising. 5. An Active Router that hears an advertisement with a **higher** priority, or an **equal** priority from a higher primary IP address, steps down to Backup. Otherwise it discards the advertisement and immediately re-advertises to assert itself. Because `Skew_Time` shrinks as priority rises, the highest-priority Backup's timer fires first when two start together. At the 1-second default, a priority-200 Backup waits about 3.22 s and a priority-100 Backup about 3.61 s, so the better router wins the race and its advertisement silences the other. ## Preemption `Preempt_Mode` decides what a Backup does with an advertisement of **lower** priority than its own: | Backup's Preempt_Mode | Advertisement priority vs local | Backup's action | |---|---|---| | True (default) | lower | discards it; its timer runs out and it becomes Active | | True | equal or higher | accepts it, resets the timer, stays Backup | | False | any | accepts it, resets the timer, stays Backup | Two consequences follow. Preemption is **not instantaneous**: a priority-150 Backup preempting a priority-100 Active waits its full `Active_Down_Interval`, `300 + 41.41 = 341.41` centiseconds, about 3.41 s, before it claims the role. And a Backup **never preempts on a tie**: equal priority is accepted, so the primary-IP comparison matters only when two routers are Active at once, for example after both started simultaneously. In the Active state `Preempt_Mode` is not consulted: an Active Router always yields to a higher priority it hears. The address owner is the exception: RFC 9568 says it always preempts, independent of `Preempt_Mode`. ## Priority 0: the graceful handover An Active Router that is shutting down cancels its timer and sends one advertisement with **priority 0**. A Backup receiving it sets its timer to `Skew_Time` alone instead of the full interval. For a priority-100 Backup at the default interval that is `(156 x 100) / 256 = 60.94` centiseconds, about 0.61 s, versus 3.61 s for an unannounced failure. The Active Router, if it is still running and hears a priority-0 advertisement from another router, simply sends its own advertisement at once. ## Practical guidance from the RFC - Configure only **one** router per VRID with priority 255; multiple claimants SHOULD be logged. - Give routers **distinct priorities with sufficient gaps**, so lower Backups do not go Active before hearing the best one. - Remember that RFC 9568 renamed RFC 5798's "Master" to **Active**; the mechanics did not change. ## Common misreadings - "Equal priority, higher IP wins" applied to a Backup: wrong, a Backup does not preempt on a tie. - "Preemption off protects us from the owner": wrong, the owner always preempts. - "Priority 0 is just the lowest setting": wrong, it is reserved as a resignation signal, never configured.

  • Two VRRP routers both have priority 100 and preemption on; the one with the higher IP address boots second. Does it take over?
    No. In the Backup state, RFC 9568 accepts any advertisement whose priority is greater than or equal to its own, so an equal-priority Active is never preempted. The primary-IP tie-break applies only when an Active Router hears another Active of equal priority, such as after both started at once. To prefer a router, give it a strictly higher priority.
  • Why might you avoid making a gateway router the VRRP address owner with priority 255?
    The owner always preempts the moment it starts, whatever `Preempt_Mode` says, so a rebooting owner reclaims the gateway before its routing has converged. Its priority must be 255 under RFC 9568, so lowering it on an uplink failure, which is what implementations' tracking does, falls outside the specification. A virtual IP that no router owns, with priorities in 1-254, keeps both preemption and tracking under your control.

saying these in an interview costs you the question

  • The lowest VRRP priority wins the election, as with a spanning-tree bridge ID.
  • A Backup with equal priority and a higher IP address preempts the Active Router.
  • Turning preemption off stops the address owner from reclaiming the gateway.
  • Priority 0 is a valid configured value meaning least preferred.
  • A higher-priority non-owner Backup preempts instantly, without waiting for its down timer.