skip to content

How does RIPng for IPv6 differ from RIPv2 in its port, multicast group, route entries, next hops and authentication?

level: middleimportance: nice to knowfreq 8%

answer

  1. same algorithm, new address family
  2. one port number higher
  3. the all-rip-routers group
  4. prefix length instead of a mask
  5. metric 0xFF marks a next hop

basics

~20 s

RIPng (RFC 2080) keeps RIP's hop-count distance-vector design but runs on UDP 521 and multicasts to ff02::9. Entries carry a 128-bit prefix and prefix length, next hops are separate link-local entries, and there is no authentication field: it relies on IPsec.

solid answer

~50 s

RIPng is RIP adapted to IPv6 by RFC 2080: hop count, 1 to 15 with 16 as infinity, and the same distance-vector behaviour. It uses UDP port `521` (RIPv1 and RIPv2 use 520) and sends updates to `ff02::9`, the all-rip-routers group, from a link-local source address. Its 20-octet route entry is a 16-octet IPv6 prefix, a 2-octet route tag, a 1-octet prefix length (0 to 128) and a 1-octet metric: no address family and no mask, since a prefix length is unambiguous. A next hop is not a field in every entry; a special entry with metric `0xFF` names a link-local next hop for the entries after it. There is no authentication entry; RIPng relies on the IPv6 Authentication Header and ESP. Receivers also accept periodic and triggered updates only with a hop limit of 255.

go deeper

for a junior

Recall that RIPng is RIP for IPv6, on UDP 521 with group ff02::9, and that it still uses hop count with 16 as unreachable.

for a middle

Explain the RIPng route entry (prefix, tag, prefix length, metric), the next-hop entry marked by metric 0xFF, and why authentication was left to IPsec.

for a senior

Be ready to explain what proves a RIPng update came from an on-link neighbour, the link-local source and hop limit 255, and why that is not authentication.

for a principal

Use RIPng to discuss porting a protocol to a new address family: which parts are address-specific, and the cost of delegating security to IPsec configuration.

## Same protocol, new address family **RIPng** ("RIP next generation", **RFC 2080**, Standards Track, 1997) is RIP for **IPv6**. Its algorithm is RIP's: a **distance-vector** protocol that counts hops, with metrics from 1 to 15 and **16 meaning unreachable**, regular and triggered updates, and the same loop-prevention mechanisms. RFC 2080 describes **version 1** of RIPng, with two commands, Request and Response. What changed is everything tied to the address family. ## Side by side | | RIPv2 (RFC 2453) | RIPng (RFC 2080) | |---|---|---| | Transport | UDP port **520** | UDP port **521** | | Update destination | `224.0.0.9` | `ff02::9`, the all-rip-routers group | | Destination field | 4-octet IPv4 address + 4-octet subnet mask | 16-octet IPv6 prefix + 1-octet **prefix length** (0 to 128) | | Metric field | 4 octets | 1 octet | | Address family field | yes (AFI) | none | | Next hop | 4-octet field in every entry | separate **next-hop entry**, link-local only | | Authentication | first entry with AFI `0xFFFF` | none in the message: **IPsec** | | Entries per message | 1 to 25 | limited by the link MTU | ## The route entry Every RIPng **route table entry (RTE)** is 20 octets: - **IPv6 prefix**, 16 octets; - **route tag**, 2 octets, with the same meaning as in RIPv2: preserved and re-advertised, typically to mark external routes; - **prefix length**, 1 octet, the number of significant bits from 0 to 128; - **metric**, 1 octet. Because the prefix length always travels with the prefix, RFC 2080 notes that the distinction between network, subnet and host routes does not need to be made: an IPv6 prefix is unambiguous. There is no classful inference of any kind. A prefix length of zero designates the **default route**. The message is not capped at 25 entries. RFC 2080 computes the number of RTEs from the medium's MTU minus the IPv6 headers, the UDP header and the RIPng header, divided by the RTE size, since an unsolicited update is never forwarded past a router. ## Next hops as their own entry RIPv2 has a next-hop field in every entry. RFC 2080 observes that a 16-octet IPv6 next hop in every entry would nearly double its size, so RIPng uses a **next-hop RTE** instead: 1. The entry's **metric is `0xFF`**, which marks it as a next hop, not a route. 2. Its prefix field holds the **next-hop address**, which must be a **link-local** address. Route tag and prefix length are zero. 3. The next hop applies to every following route entry until the end of the message or the next next-hop RTE. 4. A next hop of `::` (all zeros) means "via the originator of this advertisement"; a next hop that is not link-local is treated as `::`. As in RIPv2, the next hop is advisory: ignoring it gives a possibly longer but valid path. ## Checks that rely on IPv6 link-local addressing - A Response must come from the RIPng port, and its **source address must be link-local**. - Periodic updates must be sent with a **hop limit of 255**, and a receiver checks that multicast updates from the RIPng port, periodic or triggered, arrive with 255. Any router in between would have decremented it, so this guarantees the sender is on the link. - Link-local addresses must never appear as destinations in an RTE, and prefixes that are multicast are rejected. ## Authentication moved out of the protocol RIPv2 carries authentication inside the message. RIPng has **no authentication entry or field**: RFC 2080's security section says that, since RIPng runs over IPv6, it relies on the **IP Authentication Header** and the **IP Encapsulating Security Payload** for integrity, authentication and confidentiality. The hop-limit check proves a sender is on the link, not who it is. ## Why it is asked RIPng is rarely deployed, so interviewers use it to see whether a candidate can carry a protocol's design across address families: what had to change (port, group, prefix length, next-hop encoding, security) and what did not (hop count, infinity of 16, distance-vector behaviour).

  • Why does RIPng put next hops in a separate entry instead of a field in each route entry like RIPv2?
    An IPv6 next hop is 16 octets, so a per-entry field would nearly double every route entry. RFC 2080 instead uses an entry with metric `0xFF` whose prefix field holds a link-local next hop that applies to all following entries until another next-hop entry or the end of the message. All zeros means use the sender.
  • What does RIPng's hop limit of 255 check prove, and what does it not?
    Periodic updates must be sent with hop limit 255, and receivers check multicast updates from the RIPng port for 255, so a packet that crossed any router would fail: the sender must be on the link. It says nothing about which device on the link sent it, so it does not replace authentication, which RIPng leaves to IPsec.

saying these in an interview costs you the question

  • RIPng uses UDP port 520, the same as RIPv2.
  • RIPng carries a subnet mask field like RIPv2.
  • RIPng raised the hop-count limit beyond 15 for larger IPv6 networks.
  • RIPng next hops may be any global unicast IPv6 address.
  • RIPng has its own authentication entry, like RIPv2's 0xFFFF entry.
  • RIPng messages are capped at 25 route entries.