HSRP and VRRP both let two or more routers share one gateway address, so the hosts behind them keep working when a router fails. HSRP is Cisco’s, written up in an informational RFC in 1998; VRRP is the IETF standard, now RFC 9568.
They do the same job with different defaults. At default timers VRRP fails over in about 3.6 seconds and hands the gateway back when the preferred router returns; HSRP waits up to 10 seconds and, unless preemption is configured, leaves the traffic where it landed.
GLBP, also Cisco’s, differs in kind rather than degree: every router in the group forwards at once.
- Hosts point at a virtual IP, and a virtual MAC answers for it
- HSRP: Cisco, hello 3 s, hold 10 s, preemption off by default
- VRRP: IETF standard, 1 s adverts, preemption on by default
- Default priority is 100 in HSRP, VRRP and GLBP
- GLBP: up to four routers forwarding for one address
On this page
- Why one gateway address is a single point of failure
- How two routers share one address
- How long the gateway is gone
- Preemption, the default that decides where traffic lands after a repair
- HSRP priority and tracking, and the tie at 100
- GLBP vs HSRP: both routers forwarding at once
- HSRP version 1 and version 2 do not talk to each other
- Reading them in a packet capture
- Pinging the gateway after a VRRP failover
- Who else can become the gateway
- Which one to use
- Where people go wrong
- Comparison
- FAQ
The problemWhy one gateway address is a single point of failure
Every host on a subnet sends anything bound off the subnet to one address, its default gateway. The host does not look for alternatives. It has one address, and if nothing answers there, the host is cut off from everything beyond its own subnet.
That is fine until the router behind the address fails. A second router on the same subnet does not help on its own, because the hosts are pointed at the first one and have no way of knowing the second exists.
RFC 9568, the current VRRP specification, calls the loss of the default router a catastrophic event for every host that cannot find another path.
Dynamic routing does not solve it either. Routers learn alternate paths from each other, but a laptop, a printer and a phone do not run a routing protocol, and nobody wants them to. What they need is for the one address they already have to keep answering.
That is what a first hop redundancy protocol does, and FHRP is the family name for HSRP, VRRP and GLBP.
The first hop is the gateway, the first router a packet reaches, and router redundancy at that hop is meant to be invisible to the hosts. HSRP vs VRRP vs GLBP is a choice among three answers to that one problem.
All three FHRP protocols run on routers and Layer 3 switches, the network devices that act as the gateway for a LAN. They give the network redundancy at the one hop its hosts cannot route around.
How it worksHow two routers share one address
The trick is two addresses that belong to the group rather than to any one router.
A virtual IP address. The routers agree on one address, say 10.0.0.1, and the hosts are given that address as their gateway. Cisco's configuration guide puts it from the host's side: the hosts are configured with the virtual IP address as their default gateway, never with the address of whichever router happens to be active.
In the usual arrangement neither router has the virtual address on an interface; VRRP also allows one router to own it, which comes up further down.
A virtual MAC address. A host needs a MAC address to send a frame to its gateway, and it learns that address through ARP.
If the gateway's MAC belonged to R1, every host would hold R1's hardware address in its ARP cache, and a failover to R2 would leave them all sending frames to a router that is gone. So the group has its own MAC.
For HSRP version 1 it is 0000.0C07.ACxx, where the last byte is the group number in hexadecimal. For VRRP over IPv4 it is 00-00-5E-00-01 followed by the virtual router ID. RFC 9568 gives the reason in a line: the host always uses the same MAC address, whichever router is active.
One router answers for both. The active router replies to ARP requests for the virtual IP with the virtual MAC, and forwards whatever arrives at it. The others listen to its hellos and wait. When the hellos stop, one of them takes over both addresses.
The switches have to find out. The hosts change nothing, but the switches between them and the gateway have learned the virtual MAC on R1's port.
The new active router fixes that by announcing itself: under RFC 9568 a router that becomes active broadcasts a gratuitous ARP for each virtual address, which moves the entry in every switch's MAC address table to the new port.
Failover timeHow long the gateway is gone
This is the number people get wrong, because the defaults were chosen for stability rather than speed.
HSRP: up to 10 seconds. The active router sends a hello every 3 seconds, and the standby waits for a hold time of 10 seconds without one before it acts. Cisco's FAQ is direct about it: the standby router takes over once the hold time expires.
So at default HSRP timers a dead active router can leave the subnet without a gateway for up to 10 seconds, counted from the last hello that arrived.
VRRP: about 3.6 seconds. The active router advertises once a second. A backup declares it dead after three missed advertisements plus a skew that depends on the backup's own priority, and RFC 9568 gives the formula: the skew is 256 minus the priority, divided by 256, times one interval.
At the default priority of 100 that is 156/256 of a second, or 0.61, so the backup takes over at 3.61 seconds.
The skew is there so the backups do not all move at once. A backup with a higher priority has a smaller skew and times out first, so the best candidate usually wins before anybody else tries. At priority 200 the skew is 56/256 of a second, about 0.22, and that backup would move at 3.22 seconds.
Both can be tuned down, and should be thought about before they are. HSRP version 2 advertises and learns millisecond timers, and VRRP's interval is set in centiseconds.
Shorter timers mean a faster failover, and they also mean a busy router that misses a few hellos can trigger a failover nobody needed. The defaults are a trade somebody already made for you.
PreemptionPreemption, the default that decides where traffic lands after a repair
Failover is half of it. The other half is what happens when the failed router comes back, and here HSRP and VRRP disagree by default.
VRRP takes the gateway back. Preempt mode is on by default in RFC 9568, so when the higher priority router returns, it becomes active again and the traffic moves back to it.
HSRP does not, unless told to. Cisco's guide is explicit: a router without the preempt command will not become active, even when its priority is higher than every other router in the group.
So the same outage ends differently. Take R1 at priority 110 and R2 at 100. R1 fails, R2 takes over, R1 is repaired. Under VRRP the traffic moves back to R1 once it is running again.
Under HSRP without preemption the traffic stays on R2 until R2 fails or somebody intervenes, and that can go unnoticed for months, which matters when R1 is the router with the better uplink.
Preemption is not automatically the better setting. A router that is flapping will take the gateway, lose it and take it again, and each move is a short outage for the whole subnet. HSRP's default leaves the traffic on the router that has been stable. That is a defensible choice, as long as somebody made it on purpose.
Priority and trackingHSRP priority and tracking, and the tie at 100
HSRP priority decides which router is active, and the default is 100 on every router. A group in which nobody set a priority leaves the choice to a tie-break rather than to a decision. Set the router you want active higher, and turn on preemption if you want that preference to survive a failure.
Priority on its own watches the wrong thing. A router whose LAN interface is up and whose uplink is down still sends hellos, still has the highest priority, and stays active while it drops everything the hosts send it.
HSRP tracking is the fix: the router watches an object, such as the uplink, and lowers its own priority when that object goes down. Cisco's default is to lower it by 10.
The default decrement can land on a tie. R1 at 110 with a tracked uplink drops to 100 when the uplink fails, which is exactly R2's default priority.
A tie is settled by the protocol's tie-break rather than by your design, so whether the traffic moves depends on something you did not choose. Set the decrement or the gap so the tracked router falls clearly below its peer: R1 at 110 with a decrement of 20 lands at 90.
Tracking does nothing without preemption on the other router. The decrement makes R2 the higher priority router, but under HSRP a router only takes over from a live active router if it is allowed to preempt.
Tracking without preemption lowers a number and moves no traffic, which is an easy way for an HSRP design to pass every test except the real one.
GLBPGLBP vs HSRP: both routers forwarding at once
HSRP and VRRP leave the standby router idle, so neither protocol does load balancing by default. It holds a copy of the job and forwards nothing until the active router fails, which is paying for two uplinks and using one.
The usual workaround is load sharing across two groups, which is not true load balancing. Half the hosts use one virtual address with R1 active, the other half use a second virtual address with R2 active, and each router backs the other up.
Cisco documents multiple HSRP groups for load sharing, and RFC 9568 shows the same arrangement for VRRP with two virtual routers. It works, and it means handing out two gateway addresses and keeping the split sensible as the network changes.
GLBP puts both routers to work behind one address. One router is elected the active virtual gateway, the AVG. It hands out up to four virtual MAC addresses, one to each router, and answers each host's ARP request for the gateway with one of them.
Each router forwards for the MAC it was given, as an active virtual forwarder. Every host has the same gateway address, and different hosts end up sending to different routers.
The difference in the GLBP vs HSRP choice is load, not failover. Both keep a gateway alive. Only GLBP does load balancing across multiple routers without splitting the hosts into groups.
How the AVG picks a MAC for each host is configurable, as round robin, weighted or host dependent. Like HSRP it is documented by Cisco, and the gateway role does not preempt by default.
HSRP versionsHSRP version 1 and version 2 do not talk to each other
Version 1 is Cisco's default, so it is what runs unless somebody chose otherwise. Version 2 adds three things: group numbers from 0 to 4095 instead of 0 to 255, millisecond timers, and its own multicast address, 224.0.0.102 instead of 224.0.0.2. It also has its own MAC range, 0000.0C9F.F000 to 0000.0C9F.FFFF.
They do not interoperate. Cisco says so outright, and one interface cannot run both. So upgrading one router in a pair to version 2 splits the group: each router stops hearing the other, and each concludes there is no active router but itself.
With the two versions using different MAC ranges, the result is two routers answering for the same gateway address with two different MACs.
Change both routers in the same window, and check the group numbers first. A version 2 group above 255 has no version 1 equivalent to fall back to.
In a captureReading them in a packet capture
The three protocols are easy to tell apart on the wire once you know where each one sends its hellos.
HSRP version 1 sends to 224.0.0.2 on UDP port 1985, with a time to live of 1 so the hellos never leave the subnet. VRRP multicast goes to 224.0.0.18 for IPv4 and FF02::12 for IPv6, and it is not UDP at all: VRRP is its own IP protocol, number 112. GLBP sends to 224.0.0.102 on UDP port 3222.
One address appears twice. HSRP version 2 and GLBP both use 224.0.0.102, so filter on the protocol rather than on the address when both could be present.
Filtering these packets breaks the protocol quietly. An access list or a firewall rule on the router interface that drops this multicast leaves each router unable to hear the other, and each concludes it is the active one.
Accept modePinging the gateway after a VRRP failover
A VRRP detail that catches monitoring out. When the virtual address is a real interface address on one router, that router is the address owner and runs at priority 255.
Any other router standing in for it is governed by a setting RFC 9568 calls Accept_Mode, which decides whether it accepts packets addressed to the owner's address as its own. The default is false.
The practical result: after a failover, a monitoring system that checks the gateway by pinging the virtual IP can report it down while every host is routing through it normally. Check how your vendor exposes the setting and what its default is before trusting a ping to the gateway as a health check.
SecurityWho else can become the gateway
HSRP's default authentication is a known string sent in the clear: the value RFC 2281 recommends spells the word cisco. VRRP version 3 has no authentication at all, and RFC 9568 says so directly.
Either way, a device on the subnet that speaks the protocol with a higher priority can claim the gateway.
That is a conclusion from how both protocols elect a winner rather than a warning either document spells out, and it puts the protection in the switch rather than the protocol: filter these hellos on access ports, so that only the routers can send them.
Which to useWhich one to use
HSRP vs VRRP is mostly a question about the vendors in the network. HSRP and GLBP are Cisco proprietary protocols, and VRRP is the open standard that multiple vendors implement.
An all Cisco network usually already runs HSRP, and replacing a working pair with VRRP buys nothing but a maintenance window.
A mixed vendor network wants VRRP. It is the only one of the three with an IETF standards track specification, which is what lets two routers from different vendors share one gateway.
GLBP is for when the idle standby is the problem, and splitting the hosts across two gateway addresses is not something you want to maintain.
The defaults matter more than the choice. Whatever runs, decide on preemption and tracking deliberately and write the timers down. Most first hop redundancy trouble is a default nobody read rather than the wrong protocol.
PitfallsWhere people go wrong
Configuring priority and forgetting preemption. Under HSRP the higher priority router does not take over from a working active router without it. Under VRRP it is already on, which is why the same design behaves differently on the two.
Tracking with the default decrement. 110 minus 10 is 100, and 100 is where the other router already sits.
Upgrading one side of an HSRP pair to version 2. The versions do not interoperate, and a pair that disagrees splits into two active routers.
Pinging the virtual IP as the health check. Under the RFC's default accept mode a backup standing in for the owner need not answer, while it forwards traffic perfectly well.
Filtering the hellos. An access list that drops the multicast leaves each router alone, and each decides it is active.
Treating the standby as spare capacity. Under HSRP and VRRP it forwards nothing until the active router fails. Load sharing needs two groups, or GLBP.
ComparisonThe three protocols on the values that decide them
| Criterion | HSRP | VRRP | GLBP |
|---|---|---|---|
| Defined by | Cisco, RFC 2281, Informational | The IETF, RFC 9568, standards track | Cisco |
| Routers forwarding at once | One per group | One per virtual router | Up to four per group |
| Default priority | 100 | 100 | 100 |
| Preemption by default | Off | On | Off, for the gateway role |
| Default timers | Hello 3 s, hold 10 s | One advertisement per second | Hello every 3 s |
| Hellos sent to | 224.0.0.2, UDP 1985, in version 1 | 224.0.0.18, IP protocol 112 | 224.0.0.102, UDP 3222 |
| Virtual MAC | 0000.0C07.ACxx, in version 1 | 00-00-5E-00-01 plus the router ID | The 0007.B400 range, one per forwarder |
Two of those rows decide most real designs, preemption and timers, and each has a section below. The rest is what you need when reading a packet capture or a configuration somebody else wrote. The GLBP addresses are given as a range because Cisco's guide shows them by example rather than as a formula.
FAQFrequently asked questions
What is HSRP?
The Hot Standby Router Protocol, Cisco's first hop redundancy protocol. Two or more routers share a virtual IP and a virtual MAC, one of them is active and forwards the traffic, and a standby takes over if the active router stops sending hellos. It is described in RFC 2281, an informational RFC from 1998.
What is VRRP?
The Virtual Router Redundancy Protocol, the IETF's standard answer to the same problem. The current version is VRRP version 3, specified in RFC 9568 from April 2024, which replaced RFC 5798 and covers both IPv4 and IPv6.
What is the difference between HSRP and VRRP?
Who defines them, and the defaults. HSRP is Cisco's; VRRP is a standards track IETF protocol that routers from different vendors can share. At default timers VRRP fails over faster, about 3.6 seconds against up to 10, and it preempts, so traffic returns to the preferred router after a repair. HSRP leaves the traffic where it is unless preemption is configured.
Which is faster, HSRP or VRRP?
VRRP, at default timers: three one second advertisements plus a small skew, which is 3.61 seconds at priority 100, against HSRP's 10 second hold time. Both can be tuned lower, and HSRP version 2 supports millisecond timers.
What is GLBP?
The Gateway Load Balancing Protocol, a Cisco protocol that keeps the gateway redundant and also spreads traffic across up to four routers behind one virtual IP. One router, the active virtual gateway, answers ARP requests with different virtual MACs, so different hosts send to different routers.
What is the default HSRP priority?
100, and it is 100 in VRRP and GLBP as well. The router with the higher priority is preferred as active, but under HSRP it only takes over from a working active router if preemption is configured.
What does preemption do?
It lets a router with a higher priority take the active role from a lower priority router that currently holds it. VRRP enables it by default. HSRP does not, and neither does the gateway role in GLBP.
What is HSRP tracking?
A router watching an object, typically its uplink, and lowering its own HSRP priority when that object goes down, so a router that can no longer reach anything stops being the preferred gateway. Cisco's default decrement is 10, which is worth checking against the gap between the two priorities.
What multicast address does VRRP use?
224.0.0.18 for IPv4 and FF02::12 for IPv6, as IP protocol number 112 rather than over TCP or UDP. HSRP version 1 uses 224.0.0.2 on UDP port 1985, and HSRP version 2 and GLBP both use 224.0.0.102.
What is the VRRP virtual MAC address?
00-00-5E-00-01 followed by the virtual router ID in hex for IPv4, and 00-00-5E-00-02 followed by the ID for IPv6. HSRP version 1 uses 0000.0C07.ACxx, where xx is the group number.
Why does older documentation call the VRRP active router the master?
Because RFC 5798 did. RFC 9568 changed the term to Active Router to match the IETF's inclusive terminology, so newer material says active and backup where older material says master and backup.
Does a first hop redundancy protocol need anything on the hosts?
No. The hosts are given the virtual IP as their default gateway, by DHCP or by hand, and that is all. Everything else happens between the routers.
Keep readingRelated concepts
Read next · Addressing Default Gateway The one address every host sends off-network traffic to, and the thing this page keeps alive. Open this next10 min- Fundamentals · 13 min ARP Explained, and the One Thing Everyone Gets Wrong About It How a host learns the MAC behind its gateway, which is why a virtual MAC is the whole trick.
- Switching · 9 min Inter VLAN Routing, and Why Two VLANs Cannot Talk Without It Where the gateway addresses these protocols protect usually live, one per VLAN.
- Routing · 9 min BFD, the Fast Way to Notice a Link Has Failed A protocol that BFD can drive to switch gateways quickly.