skip to content

When a RIP router loses a route, how do route poisoning and triggered updates spread the news, and how does poisoning differ from poison reverse?

level: middleimportance: should knowfreq 22%

answer

  1. announce the loss, never go silent
  2. metric 16 kept in updates
  3. send now, but rate-limited
  4. loss versus direction

basics

~20 s

Route poisoning advertises a lost route at metric 16 rather than dropping it silently; triggered updates send that change within seconds, not at the next regular update. Poison reverse instead sends 16 back toward the neighbour a working route came from.

solid answer

~50 s

In RIP, the router that loses a route — its timeout expires, or its next hop reports metric 16 — sets the metric to 16, flags the route as changed and keeps it for a 120-second garbage-collection period, listing it at 16 in every update. That is **route poisoning**: neighbours learn the route is gone instead of waiting out their own timeouts. A **triggered update** carries the change at once rather than at the next 30-second cycle; RFC 1812 requires one when routes are deleted or their metrics rise, rate-limited by a random 1-5 second timer. The poison cascades backwards along every path through the failed router and stops where routes go another way. **Poison reverse** is a different rule: 16 advertised toward the neighbour a *working* route was learned from. Poisoning reports a loss; poison reverse reports direction. Neither makes counting to infinity impossible.

go deeper

for a junior

Recall that RIP announces a lost route at metric 16 instead of going quiet, and sends that news straight away rather than waiting for the next regular update.

for a middle

Walk through the deletion process and the triggered-update rules, explain which neighbours believe the poison, and keep poisoning distinct from poison reverse.

for a senior

Explain the race between a triggered cascade and regular updates, why it can still restart a loop, and what rate limiting trades on slow or crowded links.

for a principal

Judge how much faster convergence is worth in update load and how much residual loop risk a network can tolerate before an extra mechanism such as holddown is justified.

## Silence is the problem A RIP router that simply forgot a failed route would tell no one. Its neighbours would keep the route until their own timeouts expired — 180 seconds without a refresh in RFC 2453 — and meanwhile keep advertising it, giving the network time to rebuild the route out of stale claims. RIP's answer is to **announce the loss**, and to announce it **quickly**. ## Route poisoning: the deletion process "Route poisoning" is the common name for what RFC 2453 calls the deletion process. It starts when a route's timeout expires, or when the current next hop reports the route at 16. Then: 1. The garbage-collection timer is set for 120 seconds. 2. The route's metric is set to 16, infinity, which takes it out of service. 3. The route change flag is set. 4. The output process is signalled to send a triggered update. Until garbage collection expires, the route stays in **every** update at metric 16. If a genuine new route appears meanwhile, it replaces the dying one and the timer is cleared. A poisoned route is information, not silence: every neighbour whose route runs through this router hears from its own next hop that the path is gone, and must believe it. ## Triggered updates A **triggered update** sends a change now instead of at the next 30-second regular update. - RFC 1812 says a router **must** send one when routes are deleted or their metrics increase, and **may** send one when routes are added or improved. - It must be rate-limited: after sending one, a router sets a timer to a random 1 to 5 seconds; changes that occur meanwhile go out together when it expires, and a triggered update may be skipped if a regular update is due by then. - It need carry only the routes whose change flag is set; RFC 2453 calls sending complete tables in triggered updates "strongly discouraged". - Split horizon is applied to triggered updates exactly as to regular ones. ## How the cascade travels When a router poisons prefix P, every neighbour hears it, but only those whose route to P goes **through** that router believe it. For the others it is an offer worse than what they already have, and they ignore it. The believers poison P in turn and send their own triggered updates. The poison therefore propagates **backwards along every path that led through the failure** and stops where the network reaches P another way. ## Poisoning versus poison reverse The two names sound alike and are routinely confused: | | Route poisoning | Poison reverse | |---|---|---| | What prompts it | a route is lost | a standing rule for every learned route | | Who receives it | every neighbour | the neighbour the route was learned from | | What it says | this destination is gone | do not reach it through me | | Does the route still work? | no | yes, via that neighbour | Poison reverse — split horizon with poisoned reverse — is a rule about direction; route poisoning is an event about loss. Both happen to use the same value, 16. ## Why the risk only shrinks RFC 2453 is candid: if the network could "sit still" while the triggered cascade spreads, counting to infinity would never happen. It cannot: - Regular updates keep flowing while triggered ones propagate. - A router that has not yet heard the poison can send a regular update still listing the old route. - A router that has already poisoned the prefix sees an offer better than 16 and installs it, re-establishing what the RFC calls an orphaned remnant of the faulty route. Fast triggered updates make that race unlikely; the metric cap of 16 bounds it when it happens. Many implementations add a holddown period — not defined in RFC 2453 — to refuse such offers for a while after a loss.

  • If a RIP router sends a triggered poison at once, why can counting to infinity still start?
    Because regular updates keep flowing while the triggered cascade spreads. A router that has not yet heard the poison can send a regular update still listing the old route, and a router that has already poisoned the prefix may install that stale offer, since anything beats 16. RFC 2453 notes that counting to infinity would never happen only if the network could sit still during the cascade.
  • Why does RIP rate-limit triggered updates instead of sending every change immediately?
    One failure can set off a cascade of changes, and on slow links or segments with many routers an update per change would swamp them. After a triggered update a router waits a random 1 to 5 seconds, folds any further changes into a single update when the timer expires, and may skip it if a regular update is due by then.

saying these in an interview costs you the question

  • Route poisoning and poison reverse are two names for the same mechanism.
  • A RIP router deletes a failed route at once and stops mentioning it.
  • Triggered updates resend the whole routing table immediately.
  • Triggered updates make counting to infinity impossible.
  • Every neighbour that hears a poisoned route deletes its own route to that prefix.