Routelearn.net
Course menu

Course 10: First-Hop RedundancyLesson 1.1 (1 of 1 in this course)66 of 91 in the CCNA series

HSRP, VRRP and GLBP

A virtual gateway shared by two routers: active and standby roles, priority and preemption, with an HSRP configuration and a comparison of the three protocols.

Intermediate · 14 min read

FHRP (First-Hop Redundancy Protocol) is a protocol that lets two or more routers share a virtual IP address and virtual MAC address that hosts use as their default gateway. The routers elect which one answers for the virtual address, and another takes over if it fails. HSRP, VRRP and GLBP are the three common examples.

In simple terms: PCs only know one gateway address. An FHRP lets a backup router quietly take over that same address when the main router dies, so the PCs never notice.

A real-life situation

The office has two routers to the WAN, R1 and R2, so a single failure shouldn't cut everyone off. But every PC has one default gateway: R1's address. One morning R1's power supply dies. R2 is working perfectly, yet nobody can reach anything outside the LAN. The PCs keep sending to an address that no longer answers.

You could change the gateway on every PC by hand, but that is slow and DHCP leases would still hand out the old one. What you need is a gateway address that survives the loss of one router.

What a first-hop redundancy protocol is

A first-hop redundancy protocol (FHRP) lets two or more routers share one virtual IP address (VIP) and one virtual MAC address. Hosts use the virtual IP as their default gateway. The routers agree among themselves which one answers for it. If that router fails, another takes over the same IP and MAC, and the hosts don't notice.

"First hop" means the first router a packet meets when it leaves the LAN. There are three FHRPs on the CCNA exam:

  • HSRP (Hot Standby Router Protocol): Cisco proprietary, one active router.
  • VRRP (Virtual Router Redundancy Protocol): open standard, one master router.
  • GLBP (Gateway Load Balancing Protocol): Cisco proprietary, several routers forward at once.
VIP 192.168.10.1Gi0/1Gi0/1PC1192.168.10.10 · GW .1SW1VLAN 10ActiveR1Gi0/0 .2 · pri 110StandbyR2Gi0/0 .3 · pri 100WAN / Internet203.0.113.0/24
  1. 1. Normal operation. PC1 sends to the gateway 192.168.10.1. ARP gave it the virtual MAC, which R1 (active) owns, so R1 forwards the traffic.
  2. 2. The routers exchange Hellos. Every 3 seconds each router multicasts an HSRP Hello with its priority and state.
  3. 3. R1 fails. R2 hears no Hello from R1 for the hold time (10 s) and becomes active.
  4. 4. R2 takes over the virtual MAC. R2 sends a gratuitous ARP from the virtual MAC so SW1 moves that MAC to R2's port.
  5. 5. Traffic flows through R2. PC1 changed nothing: same gateway IP, same MAC in its ARP cache.

Why it works that way

A host reaches its gateway in two steps: it uses ARP once to learn the gateway's MAC, then it sends every remote frame to that MAC. If a backup router took over the IP but kept its own MAC, every host would keep sending to the dead router's MAC until its ARP entry expired, which can take hours.

That is why FHRPs use a virtual MAC as well as a virtual IP. The MAC moves with the role. The new active router sends a gratuitous ARP (an ARP reply nobody asked for) sourced from the virtual MAC. Switches update their MAC address tables to the new port, and the hosts' ARP caches are still correct.

How HSRP works, step by step

Roles and election

  • The active router answers ARP for the virtual IP and forwards traffic sent to the virtual MAC.
  • The standby router watches the active router and takes over if it disappears. Any other routers in the group stay in the listen state.
  • The router with the highest priority (0–255, default 100) wins. On a tie, the highest interface IP address wins.
  • Preemption is off by default in HSRP. Without it, a router with a higher priority that boots later does not take the active role back. You enable it with standby <group> preempt.

Hellos and failover

Step 1 of 5 · Hello (active, 110)
VLAN 10 · 192.168.10.0/24
R1
192.168.10.2 · pri 110
R2
192.168.10.3 · pri 100
SW1
MAC table
After failover
Active:
R2
Hosts' gateway:
192.168.10.1 (unchanged)
Gateway MAC:
0000.0c9f.f00a (unchanged)
Outage:
About the hold time: up to 10 s
HSRP Hellos and a failover from R1 to R2.

HSRP versions and the virtual MAC

HSRPv1HSRPv2
Multicast address224.0.0.2224.0.0.102
Group numbers0–2550–4095
Virtual MAC0000.0c07.acXX (XX = group in hex)0000.0c9f.fXXX (XXX = group in hex)
IPv6 supportNoYes

Group 10 is 0a in hex, so its virtual MAC is 0000.0c07.ac0a with version 1 and 0000.0c9f.f00a with version 2. Both use UDP port 1985. Version 1 is the default on most IOS releases; both routers must run the same version.

How to configure HSRP on Cisco IOS

⚠️ Commands are based on Cisco IOS / IOS XE documentation and haven't been run on a lab device here. On a Layer 3 switch the same commands go on the SVI (interface Vlan10).

! R1: should be active interface GigabitEthernet0/0 ip address 192.168.10.2 255.255.255.0 standby version 2 standby 10 ip 192.168.10.1 standby 10 priority 110 standby 10 preempt

Group 10 with virtual IP 192.168.10.1. Priority 110 beats R2's default 100, and preempt lets R1 take the role back after it recovers.

! R2: standby interface GigabitEthernet0/0 ip address 192.168.10.3 255.255.255.0 standby version 2 standby 10 ip 192.168.10.1 standby 10 preempt

Same group, same virtual IP, same version. R2 keeps the default priority of 100.

ip dhcp pool VLAN10 network 192.168.10.0 255.255.255.0 default-router 192.168.10.1

Hosts must use the virtual IP as their gateway, never .2 or .3. Wherever DHCP runs, hand out the VIP.

Tracking the uplink (good practice, beyond what the exam requires): if R1's WAN link fails, R1 is still alive and stays active, but it has nowhere to send traffic. Object tracking lowers its priority so R2 can preempt:

track 1 interface GigabitEthernet0/1 line-protocol interface GigabitEthernet0/0 standby 10 track 1 decrement 20

On R1: if Gi0/1 goes down, priority drops from 110 to 90, below R2's 100. R2 takes over because it has preempt configured.

How to verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show standby brief
                     P indicates configured to preempt.
                     |
Interface   Grp  Pri P State   Active          Standby         Virtual IP
Gi0/0       10   110 P Active  local           192.168.10.3    192.168.10.1
R1 is Active ("local" means this router), R2 at .3 is standby, and P shows preemption is on. On R2 the State column shows Standby and the Standby column says local.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show standby GigabitEthernet0/0
GigabitEthernet0/0 - Group 10 (version 2)
  State is Active
    2 state changes, last state change 00:12:41
  Virtual IP address is 192.168.10.1
  Active virtual MAC address is 0000.0c9f.f00a (MAC In Use)
    Local virtual MAC address is 0000.0c9f.f00a (v2 default)
  Hello time 3 sec, hold time 10 sec
    Next hello sent in 1.264 secs
  Preemption enabled
  Active router is local
  Standby router is 192.168.10.3, priority 100 (expires in 9.312 sec)
  Priority 110 (configured 110)
  Group name is "hsrp-Gi0/0-10" (default)
Check the virtual IP and MAC, the timers, who is active and standby, and the priority. If tracking has lowered the priority, the line reads something like "Priority 90 (configured 110)".
Example output · based on Cisco documentation; exact format varies by platform and software version
%HSRP-5-STATECHANGE: GigabitEthernet0/0 Grp 10 state Standby -> Active
The log message on R2 when R1 fails. When R1 comes back with preempt, R2 logs Active -> Speak and then settles in Standby.

What goes wrong and how to troubleshoot it

SymptomLikely causeCheck / fix
Both routers show ActiveThey can't hear each other's Hellos: wrong VLAN, a down trunk, or an ACL blocking UDP 1985show standby brief on both; ping between .2 and .3; check the switch ports.
Two separate groups instead of oneDifferent group numbers or versions on the two routersGroup number, version and virtual IP must match.
R1 recovers but R2 stays activeNo preempt on R1Add standby 10 preempt on the router that should be active.
Hosts lose access when one router failsHosts use a physical address (.2) as gatewayPoint hosts and DHCP default-router at the VIP.
WAN down, but traffic still goes to R1 and is droppedNo tracking: R1 stays activeTrack the uplink and decrement the priority below the standby's.

HSRP vs. VRRP vs. GLBP

HSRPVRRPGLBP
StandardCiscoOpen (RFC 5798)Cisco
RolesActive / standbyMaster / backupAVG + up to 4 AVFs
Who forwardsActive onlyMaster onlyAll AVFs (load balancing)
Virtual MAC0000.0c07.acXX (v1)
0000.0c9f.fXXX (v2)
0000.5e00.01XX0007.b400.XXYY (one per AVF)
Multicast224.0.0.2 (v1) / 224.0.0.102 (v2)224.0.0.18224.0.0.102
TransportUDP 1985IP protocol 112UDP 3222
Preempt by defaultNoYesNo (for the AVG)
Can the VIP be a real interface address?NoYesNo

VRRP works almost like HSRP. Use it when routers from different vendors share a gateway. The basic classic-IOS command is vrrp 10 ip 192.168.10.1; newer IOS XE releases use VRRPv3 with fhrp version vrrp v3 and a slightly different syntax.

GLBP elects one AVG (Active Virtual Gateway). The AVG gives each router, called an AVF (Active Virtual Forwarder), its own virtual MAC. When hosts ARP for the single virtual IP, the AVG replies with a different AVF MAC each time (round robin by default). Every router carries part of the traffic, with no extra groups to plan. Basic command: glbp 10 ip 192.168.10.1.

Common mistakes

  • Forgetting preempt, then wondering why a higher priority router stays standby.
  • Mismatched group numbers or HSRP versions between the routers.
  • Using a virtual IP that is already assigned to a host or an interface.
  • Handing out a physical router address as the default gateway.
  • Thinking HSRP shares load within a group. Only the active router forwards.

Exam tip: CCNA 200-301 asks you to describe FHRPs, not configure all three. Know the purpose (a resilient default gateway), the roles (active/standby, master/backup, AVG/AVF), which ones are Cisco proprietary (HSRP, GLBP) and which is open (VRRP), which one load balances in a single group (GLBP), default priority 100, highest priority wins, and that HSRP needs preempt to take the role back. Recognise the HSRP virtual MAC formats and show standby brief.

Key takeaways

  • An FHRP gives hosts one virtual gateway IP and MAC shared by several routers.
  • HSRP: active forwards, standby waits. Highest priority wins (default 100), preempt off by default.
  • On failover the new active router sends a gratuitous ARP so switches learn the virtual MAC on its port.
  • VRRP is the open-standard equivalent; GLBP load balances with up to four forwarders.
  • Verify with show standby brief and show standby.

Check yourself

Predict · scenario 1

R1 (priority 110) and R2 (priority 100) run HSRP. Neither has preempt. R1 reboots and comes back. Which router is active?

Predict · scenario 2

Which FHRP should you choose to share a gateway between a Cisco router and another vendor's router?

Predict · scenario 3

show standby brief on both routers shows State Active. What is the most likely cause?

Predict · scenario 4

Which FHRP lets several routers forward traffic for the same virtual IP at the same time?

Predict · scenario 5

An HSRPv1 group 10 is configured. Which virtual MAC address does it use?

FAQ

Why not just give hosts two default gateways?
Most hosts use a single default gateway and don't switch to a second one reliably when the first fails. A first-hop redundancy protocol hides the failure instead: the gateway address never changes, only the router answering for it does.
Is HSRP load balancing?
Not within one group: only the active router forwards. You can share load by running two groups on the same VLAN (or different groups on different VLANs) with each router active for one of them, and pointing half the hosts at each virtual IP. GLBP is the protocol that load balances inside a single group.
Which FHRP should I use with other vendors' routers?
VRRP. It is an open standard (RFC 5798 for VRRPv3), while HSRP and GLBP are Cisco proprietary.
Does the virtual IP address need to be in the same subnet as the routers' interfaces?
Yes. The virtual IP must be an unused address in the same subnet as the physical interface addresses, because it is the default gateway hosts on that subnet will use.