skip to content

How do VRRP, HSRP and GLBP differ in standards status, election messages, timers and the way they share load across gateways?

level: middleimportance: should knowfreq 34%

answer

  1. standard versus vendor protocols
  2. address owner versus dedicated virtual IP
  3. who sends the periodic messages
  4. one virtual MAC versus several
  5. groups split hosts; ARP splits hosts

basics

~20 s

VRRP is the IETF standard (RFC 9568); HSRP is a vendor protocol in Informational RFC 2281; GLBP is a vendor protocol without an RFC. VRRP and HSRP forward through one router per group; GLBP spreads one virtual IP's hosts across several forwarders.

solid answer

~50 s

**VRRP** version 3 (RFC 9568) is Standards Track for IPv4 and IPv6: IP protocol 112 to `224.0.0.18` or `ff02::12` with TTL 255, only the Active Router advertises, the interval is in centiseconds with a 1-second default, preemption is on by default, and the virtual IP may be one router's own address (the owner, priority 255). **HSRP** is a vendor protocol documented in Informational RFC 2281: UDP port 1985 to `224.0.0.2` with TTL 1, an active and a standby router that both send Hellos, RECOMMENDED Hellotime 3 s and Holdtime 10 s, preemption only when configured, and a virtual IP that must differ from every interface address. Each forwards through one router per group, so using both routers means two groups with hosts split between gateways. **GLBP** is one vendor's protocol with no RFC: hosts share one virtual IP, and ARP replies hand out different virtual MACs so several routers forward at once.

go deeper

for a junior

Know which is the standard: VRRP comes from the IETF, while HSRP and GLBP are vendor protocols, and only GLBP forwards through several routers for one gateway address.

for a middle

Compare the mechanics: transport and multicast group, who sends periodic messages, default timers, preemption defaults, and how multiple groups split hosts between routers.

for a senior

Explain the operational consequences: slower HSRP defaults, per-host rather than per-flow balancing in GLBP, clear-text authentication, and the IPv6 coverage only VRRPv3 brings.

for a principal

Decide which protocol a mixed-vendor or IPv6 network standardises on, and whether static per-group splitting or per-host balancing fits the traffic profile at all.

## Three protocols, three kinds of document The three first-hop redundancy protocols an interviewer names together do not have the same standing, and saying so precisely is half the answer. - **VRRP** (Virtual Router Redundancy Protocol) is an IETF **Standards Track** protocol. Version 3 is RFC 9568, which obsoletes RFC 5798, covers IPv4 and IPv6 and renames the forwarding role from "Master" to **Active**. Version 2, RFC 3768, is IPv4 only. - **HSRP** (Hot Standby Router Protocol) is a **vendor protocol** published as **Informational** RFC 2281 in 1998. The RFC states that it does not specify an Internet standard of any kind; it documents a deployed protocol, and the IETF built VRRP to address the same problem. - **GLBP** (Gateway Load Balancing Protocol) is another **vendor protocol with no RFC** at all; its details are whatever that vendor documents. ## Side by side | Property | VRRP v3 (RFC 9568) | HSRP (RFC 2281) | |---|---|---| | Address families | IPv4 and IPv6 | IPv4 (4-octet virtual address field) | | Transport | IP protocol 112 | UDP port 1985 | | Destination | `224.0.0.18` / `ff02::12` | `224.0.0.2` | | TTL / Hop Limit | must be 255, checked on receipt | 1 | | Who sends periodic messages | Active Router only | active and standby routers | | Message types | ADVERTISEMENT only | Hello, Coup, Resign | | Default timers | 1 s advertisement interval, in centiseconds | Hellotime 3 s, Holdtime 10 s (RECOMMENDED when not configured or learned) | | Virtual IP | may be one router's own address (owner, priority 255) | must differ from every interface address on the LAN | | Preemption | `Preempt_Mode` True by default | only when configured, via a Coup message | | Virtual MAC | `00-00-5E-00-01-{VRID}` / `00-00-5E-00-02-{VRID}` | `00-00-0C-07-AC-{group}` | | Authentication | none in version 3 | 8-octet clear-text password field | ## Election and roles Both protocols elect on a priority where the **higher** value wins. HSRP breaks equal priorities on the higher IP address; VRRP uses the higher primary IP only when two equal-priority Active Routers meet, and a Backup never preempts on a tie. HSRP's state machine runs Initial, Learn, Listen, Speak, Standby and Active, and keeps a named **standby** router: a router in Speak state contends, the winners become active and standby, and the rest sit in Listen. VRRP keeps only three states (Initialize, Backup, Active); every non-Active router is a Backup and the best of them wins the race when the Active falls silent. Preemption differs in default and in mechanics. In HSRP a higher-priority router configured to preempt sends a **Coup** and takes over; the old active sends a **Resign**. In VRRP a preempting Backup ignores the lower-priority advertisements and takes over when its own down timer expires. ## Timers and failure detection - **VRRP**: a Backup declares the Active down after `3 x interval + Skew_Time`, about 3.61 s for priority 100 at the 1-second default. The 12-bit centisecond field allows sub-second intervals. - **HSRP**: a Hello is valid for one Holdtime, which RFC 2281 says SHOULD be at least three Hellotimes; with the RECOMMENDED values a silent active is declared dead after 10 s. ## Load sharing VRRP and HSRP forward through **one router per group**. To use both routers you run two groups, as RFC 9568's second sample network does: 1. Define VRID 1 with virtual IP 10.0.10.1, Active on router A and Backup on router B. 2. Define VRID 2 with virtual IP 10.0.10.2, Active on router B and Backup on router A. 3. Give half the hosts 10.0.10.1 as their gateway and half 10.0.10.2. 4. If either router fails, the other becomes Active for both VRIDs. The split is static and per host: it balances only as well as the host assignment. **GLBP** keeps **one** virtual IP. One router of the group answers ARP requests for it and hands successive hosts different virtual MACs, each owned by a different forwarding router; if a forwarder fails, another router takes over its virtual MAC. Load is still divided per host, by ARP resolution, never per flow. ## Choosing Mixed-vendor networks and IPv6 point to VRRP, the only standard of the three. HSRP and GLBP appear where one vendor's equipment is already the norm. Whatever the protocol, the operational issues are the same: priorities, preemption, tracking of upstream failures and the speed of detection.

  • With VRRP, how do you get both gateway routers forwarding traffic in normal operation?
    Configure two virtual routers on the LAN, for example VRID 1 Active on router A and VRID 2 Active on router B, each backing up the other, and give half the hosts each virtual IP as their gateway, as RFC 9568's second sample network shows. The split is per host and static, so it balances only as well as the host assignment, and DHCP or static configuration must hand out two gateways.
  • Why can GLBP's load sharing still leave one router carrying most of the traffic?
    GLBP balances at ARP time: each host resolves the single virtual IP and receives one virtual MAC, so all of that host's traffic goes to the forwarder owning that MAC until its cache entry changes. One or two heavy hosts can therefore load a single router while the others idle; it spreads hosts, not flows.
  • Why does VRRPv3 carry no authentication when HSRP still has a password field?
    RFC 3768 had already removed VRRP's authentication types, noting they gave no real security and only produced multiple Masters, and RFC 9568 adds that even cryptographic protection cannot stop a hostile node from acting as an Active Router. HSRP's field is an 8-octet clear-text password readable by anyone on the LAN. Protection comes from controlling who can transmit on the segment.

saying these in an interview costs you the question

  • HSRP is the IETF standard and VRRP is one vendor's extension of it.
  • VRRP and HSRP forward through every router in the group at once.
  • HSRP's virtual IP may reuse a router's interface address, like a VRRP owner.
  • GLBP spreads individual flows across routers, the way ECMP does.
  • VRRPv3's advertisement interval is counted in whole seconds, as in VRRPv2.