skip to content

In RIP, how does simple split horizon differ from split horizon with poisoned reverse, and why is poisoned reverse considered safer?

level: middleimportance: must knowfreq 30%

answer

  1. what you tell your source
  2. omit versus advertise at 16
  3. two routers pointing at each other
  4. bigger updates, faster correction

basics

~20 s

Simple split horizon leaves a route out of updates sent where it was learned; poisoned reverse sends it there with metric 16. That explicit 16 breaks a two-router loop at once rather than after a timeout, but enlarges updates.

solid answer

~50 s

Both rules stop a RIP router from offering a route back to the neighbour it came from, since that neighbour's path cannot run through it without a loop. **Simple split horizon** omits the route from updates sent on that interface; on a broadcast network it omits every route learned from any router on that network. **Split horizon with poisoned reverse** includes those routes but sets their metric to 16, telling the neighbour outright "not through me". RFC 2453 calls poisoned reverse safer: if two routers already have routes pointing at each other, a reverse route at 16 breaks the loop immediately, while with omission the bad routes linger until they time out. The price is update size — on a shared backbone each router must relist every route it learned there, at 16. RFC 1812 requires split horizon and recommends poisoned reverse, allowing an option to turn it off.

go deeper

for a junior

Recall the one-line rule: never advertise a route back where you learned it, and that poisoned reverse sends it back at 16 instead of leaving it out.

for a middle

Explain why omission leaves an existing two-router loop to time out while a 16 from the next hop clears it at once, and how the rule works on a shared segment.

for a senior

Weigh update size against correction speed on a busy shared segment, and show why neither variant catches a loop among three routers.

for a principal

Treat it as a choice between control-plane overhead and convergence safety, and decide when a time-limited hybrid of poisoning and omission is the right default.

## The problem both rules solve In RIP, a router that learned a route from a neighbour has nothing useful to tell that neighbour about it: the neighbour's path cannot run back through the router without forming a loop. Without a rule, the router would advertise the route back anyway, and if the neighbour later lost its own path it could take that echo for an alternative. RFC 2453 calls this "mutual deception" — two routers each claiming to reach a destination through the other. **Split horizon** is the family of rules that stops the echo. ## Simple split horizon **Simple split horizon** omits a route from updates sent to the neighbour it was learned from. - On a point-to-point link, that is one neighbour. - On a broadcast network the rule is per network: every route learned from any router on that segment is left out of the update sent onto it. The other routers there can reach the source directly, so none needs a path through you — which is also why one update can serve the whole segment. - It costs nothing on the wire; updates actually get smaller. Its weakness is that it is passive. If two routers already have routes pointing at each other — after a lost update, say — silence does not correct them. In the RFC's words, if reverse routes "are simply not advertised, the erroneous routes will have to be eliminated by waiting for a timeout." ## Split horizon with poisoned reverse **Poisoned reverse** includes those routes but sets their metric to 16, RIP's infinity. The update now says explicitly: do not use me for this destination. - A neighbour whose route points at you receives 16 from its own next hop, must believe it, and drops the route at once. - RFC 2453 therefore calls it safer: "If two routers have routes pointing at each other, advertising reverse routes with a metric of 16 will break the loop immediately." - The cost is size. The RFC's example is a campus backbone where each building router has a few local networks. With simple split horizon each router advertises only those; with poisoned reverse it must also list every route it learned from the backbone, at 16 — "a large update message, almost all of whose entries indicate unreachable networks." ## Side by side | | Simple split horizon | Split horizon with poisoned reverse | |---|---|---| | Route learned from neighbour N, in the update to N | omitted | sent with metric 16 | | Two routers already pointing at each other | cleared only by a timeout | cleared by the next update | | Update size | smallest | grows with the routes learned on that interface | | RFC 1812 requirement | MUST implement | SHOULD implement; MAY be switchable | ## What the standards ask 1. RFC 1812, the IPv4 router requirements, says a RIP implementation **must** implement split horizon and **should** implement split horizon with poisoned reverse, and may offer an option to choose. 2. It also says an implementation **should** limit how long it sends reverse routes at infinity: its algorithms poison a route for one route lifetime (typically 180 seconds) after the route changes, then fall back to omitting it. 3. RFC 2453 allows hybrids of exactly that kind, and RFC 2080 (RIPng) calls poisoned reverse the preferred method while asking for a per-interface choice between no split horizon, simple split horizon and poisoned reverse. ## The limit of both Both rules look at a single fact: which neighbour a route was learned from. That catches a loop between two routers. It does not catch a loop around three or more, because each router's stale route reaches the next router from a different direction, never back toward its own source. RFC 2453 says so plainly — split horizon "cannot stop such a loop" — and such loops end only when the metric counts up to 16. Triggered updates make them unlikely, not impossible.

  • On a broadcast segment with several RIP routers, how does split horizon decide what to leave out?
    It works per network, not per neighbour. A route learned from any router on that segment is left out of — or, with poisoned reverse, sent at 16 in — the update sent onto that segment. The other routers there can reach the advertising router directly, so none of them ever needs a path through you, and one broadcast or multicast update serves them all.
  • Why does RFC 1812 say a RIP router should limit how long it advertises reverse routes at metric 16?
    Poisoned reverse earns its cost just after a change, when two routers might briefly point at each other. In a stable network the reverse entries carry no new information and only enlarge updates. So a router can poison a reverse route for a while after the route changes — RFC 1812's algorithms use the route lifetime, typically 180 seconds — and then simply omit it.

Split horizon is never telling a neighbour the directions it just gave you. Poisoned reverse goes one step further: you tell that neighbour outright "don't ask me, my way goes through you", so if it ever loses its own way it cannot mistake you for a detour.

saying these in an interview costs you the question

  • Split horizon means a RIP router stops sending updates on an interface altogether.
  • Poisoned reverse is just another name for poisoning a failed route.
  • Split horizon with poisoned reverse prevents every routing loop, however many routers are involved.
  • Poisoned reverse makes updates smaller because poisoned routes are dropped from them.
  • Split horizon is an optional RIP extension that is rarely enabled.