skip to content

In RIP with split horizon and poisoned reverse enabled, how can three routers still forward a failed prefix in a loop, and what clears it?

level: seniorimportance: nice to knowfreq 9%

answer

  1. the lie arrives from a third party
  2. each router poisons only its next hop
  3. the loop runs the other way
  4. three added per lap

basics

~20 s

Split horizon only stops a route going back to the neighbour it came from; among three routers a stale advertisement can travel around the triangle instead. The loop lasts until the metric reaches 16; triggered updates make it unlikely, not impossible.

solid answer

~50 s

Put `10.20.30.0/24` on `R3`, with `R1` and `R2` both reaching it through `R3` at metric 2. The network fails and `R3` poisons it; `R1` hears the poison, but `R2` has not yet and sends a regular update offering metric 2. `R1` installs the route via `R2` at 3 and, since that route did not come from `R3`, advertises it to `R3`, which installs it via `R1` at 4 and passes it to `R2` at 5 — `R2`'s next hop was `R3`, so it must believe it. Now `R1` points at `R2`, `R2` at `R3`, `R3` at `R1`. Each router poisons only toward its own next hop, while the stale route travels the other way, so split horizon never fires. The metric rises three per lap until it reaches 16 and every router deletes the route — RFC 2453 says split horizon "cannot stop such a loop".

go deeper

for a junior

Recall that split horizon only stops a route from going straight back where it came from, so loops through three or more routers remain possible.

for a middle

Trace the triangle step by step and point out at each step which neighbour each router poisons and which it advertises to normally.

for a senior

Map each loop-prevention mechanism to the loops it stops, explain the race that starts this one, and estimate how long it runs at triggered and regular update rates.

for a principal

Use the residual three-router case to judge whether a distance-vector protocol's guarantees are acceptable for a network, and what holddown's safety would cost in failover time.

## The setup Three RIP routers are connected in a triangle, every link at cost 1, all running split horizon with poisoned reverse and triggered updates. The prefix `10.20.30.0/24` is directly connected to `R3` only. In steady state `R1` and `R2` both reach it via `R3` at metric 2. Each also hears the other offer the prefix at 2 — a worse path at 3, which it ignores — and each sends `R3` a poisoned reverse entry at 16. ## The trace The network on `R3` fails. `R3` poisons it in a triggered update. `R1` receives it; `R2`'s copy is delayed or lost. | Step | What happens | R1 | R2 | R3 | |---|---|---|---|---| | 0 | steady state | via R3, 2 | via R3, 2 | connected, 1 | | 1 | the network fails; R3 poisons it; only R1 hears in time | 16 | via R3, 2 | 16 | | 2 | R2's regular update offers the prefix to R1 at 2 | via R2, 3 | via R3, 2 | 16 | | 3 | R1 advertises 3 to R3 (and 16 to R2, its next hop) | via R2, 3 | via R3, 2 | via R1, 4 | | 4 | R3 advertises 4 to R2, whose next hop is R3 | via R2, 3 | via R3, 5 | via R1, 4 | | 5 | R2 advertises 5 to R1, whose next hop is R2 | via R2, 6 | via R3, 5 | via R1, 4 | | ... | +1 per hop, +3 per lap | 9, 12, 15 | 8, 11, 14 | 7, 10, 13 | | end | R1 sends 15 to R3, which computes 16 and poisons; the 16 reaches R2, then R1 | 16 | 16 | 16 | From step 4 forwarding is a ring: `R1` sends to `R2`, `R2` to `R3`, `R3` to `R1`. Packets for the prefix circle until their TTL expires. ## Why split horizon never fires Split horizon and poisoned reverse both ask one question: did this route come from the neighbour I am about to tell? Here the answer is always no: - `R1` learned the route from `R2` and tells `R3`. - `R3` learned it from `R1` and tells `R2`. - `R2` learned it from `R3` and tells `R1`. Each router dutifully poisons toward its own next hop — the opposite direction from the one the stale route travels. RFC 2453 describes exactly this pattern ("A may believe it has a route through B, B through C, and C through A") and concludes: "Split horizon cannot stop such a loop. This loop will only be resolved when the metric reaches infinity." RIP updates carry only a destination and a metric, never the path, so no router can see itself in the loop. ## Which fix stops which loop | Mechanism | Two-router loop | This three-router loop | |---|---|---| | Simple split horizon | prevents the echo that forms it | no effect | | Poisoned reverse | breaks it on the next update | no effect | | Route poisoning and triggered updates | shrink the race window | shrink the race window; cannot close it | | Holddown (an implementation mechanism, not in RFC 2453) | blocks stale offers | `R1` would refuse `R2`'s 3, worse than the 2 it lost, so the loop never forms | | Infinity of 16 | bounds it | bounds it — the only guarantee | Holddown buys its protection by also refusing genuine but worse paths for as long as it runs, so it is a trade, not a free fix. ## How long and how bad 1. From `R1`'s 3, the count needs 13 more advertisements (4 through 16) to reach infinity at `R3`. 2. Each change is sent as a triggered update, spaced by a random 1 to 5 seconds, so the loop lasts very roughly 13 to 65 seconds; if every step waited for a 30-second regular update it would run for minutes. 3. Meanwhile every packet for the prefix crosses the ring repeatedly until its TTL expires, consuming capacity on all three links. In an operational trace the signature is distinctive: the prefix's metric rising by three per lap at every router, next hops forming a ring, and a burst of TTL-expired traffic for one destination. Nothing is misconfigured — this is the protocol's known residual case, and the small infinity is what keeps it short.

  • Why doesn't poisoned reverse catch the stale route when R1 advertises it to R3?
    Poisoned reverse only changes what `R1` tells the neighbour its own route goes through — `R2`. `R3` is not `R1`'s next hop for the prefix, so `R1` advertises a normal metric to it. The rule checks only the neighbour a route came from, not the whole path, and RIP updates carry no path that could be checked.
  • How long does this three-router loop last in practice?
    Each hop adds one, so from `R1`'s 3 it takes 13 more advertisements to reach 16. With triggered updates spaced by a random 1 to 5 seconds that is very roughly 13 to 65 seconds; if each step waited for a 30-second regular update it would take minutes. That is the time-versus-bandwidth trade RFC 2453 describes.

saying these in an interview costs you the question

  • Split horizon with poisoned reverse prevents all routing loops in RIP.
  • A three-router RIP loop never clears unless an operator removes the routes.
  • Holddown is part of the RIPv2 standard and stops every such loop.
  • A RIP loop after a failure always means one router is misconfigured.
  • RIP updates carry the full path, so a router can spot itself and refuse the route.