Networking · Concept · 10 min read

The RIP Protocol, and Why You Still Meet It

The whole protocol fits on a page, which is why it is still taught and still shipped on small firewalls. The two things that ended it are visible in one drawing.

Written by Marko Ristic, Editor Updated Sep 8, 2026
15Hops maximum, which caps the size of any network it serves
30sBetween updates, each carrying the entire routing table
3minRoughly, before a failed link is believed dead everywhere
1Thing the metric measures, and bandwidth is not it
Short answer

The Routing Information Protocol is a distance vector protocol: routers send their whole routing table to their neighbors every thirty seconds and believe what they are told. The metric is hop count alone, fifteen hops is the maximum, and convergence takes minutes.

  • Distance vector, so routers trust neighbors rather than a map
  • Hop count is the only metric, so slow paths win when they are shorter
  • 15 hops maximum, and 16 means unreachable
  • Convergence takes around three minutes, not seconds
  • RIPv2 supports authentication, and without it anyone can inject routes
On this page

How it worksHow the RIP protocol actually works

The mechanism is small enough to describe completely, which is most of its appeal.

Every router announces its whole table. Every thirty seconds, a router running the RIP protocol sends its complete routing table to its neighbors. Not the changes, the whole set of routing information.

Every receiver adds one hop and believes it. A router hearing that a neighbor can reach a network in two hops records that it can reach that network in three, through that neighbor. It has no way to check the information, and it does not try.

The lowest hop count wins. When two neighbors offer the same destination, the smaller number wins. Ties go to whichever was learned first.

This is why distance vector routing is described as routing by rumor. A router running the RIP protocol has no picture of the network at all. It knows what its neighbors claim and how far away they said those networks were, and that routing information is the entire basis of every decision it makes.

Compare that to a link state protocol such as OSPF, where every router builds an identical map of the whole area and computes its own shortest paths. The link state router knows the topology. The RIP router knows only what it was told.

Hop countHop count, which is the whole problem

The metric in the Routing Information Protocol is the number of routers between here and the destination network. Nothing else enters the calculation.

That means a one gigabit path across four routers loses to a ten megabit path across three. RIP will choose the slow link, keep choosing it, and be entirely correct according to its own rules.

On networks where all the links are similar this does not matter. On any network built over time, with a mix of speeds, it produces persistently wrong routing that looks like a fault.

The fifteen hop ceiling is the second consequence. A metric of sixteen means unreachable, so no destination can be more than fifteen routers away. That number was chosen because the loop prevention depends on counting to infinity quickly, and infinity had to be small enough to reach in a reasonable time.

The versionsRIPv1, RIPv2 and RIPng

Three versions exist and only two of them should be seen.

RIPv1 is classful. Its updates carry no subnet mask, so every router assumes the mask that matches the address class. That makes variable length subnet masking impossible and rules out most modern addressing. It broadcasts its updates to every device on the segment, whether or not they route. There is no reason to run it.

RIPv2 carries the subnet mask, which makes it classless and compatible with CIDR. It multicasts updates to 224.0.0.9 rather than broadcasting, so devices that are not routers ignore them, and it supports authentication so a router will not accept updates from anything that cannot prove itself. This is the only version worth configuring.

RIPng is the RIP protocol for IPv6, on UDP port 521. Same distance vector behavior, the same routing information every 30 seconds, the same fifteen hop limit, a different address family.

The authentication in RIPv2 deserves a specific mention. Without it, anything on the segment can inject routing information and be believed, because believing neighbors is the entire protocol. Configuring authentication is not optional security hardening, it is the difference between a routing protocol and an open invitation.

Loops and timersLoop prevention, and the timers nobody remembers

Distance vector protocols create routing loops naturally, because a router that hears its own information back from a neighbor cannot tell that it is its own. Three mechanisms address that, and they are the reason convergence is slow.

Split horizon. A router never advertises a route back out the interface it learned it on. This stops the simplest two-router loop entirely and costs nothing.

Route poisoning. When a route fails, the router advertises it with a metric of sixteen rather than withdrawing it silently. Sixteen means unreachable, so the news travels as a positive statement instead of an absence, which propagates far faster.

Hold-down timers. After hearing that a route is unreachable, a router refuses further updates about that network for a period, so stale routing information circulating in the network cannot resurrect it.

Those timers are why the RIP protocol converges in minutes rather than seconds. The defaults on most implementations are a 30 second update, a 180 second invalid timer, a 180 second hold-down and a 240 second flush. A link that fails can take three minutes to be believed dead everywhere, and during those minutes traffic is going to a router that cannot deliver it.

Where it survivesWhere you still meet it

The RIP protocol is not dead, and it survives in four places.

Small firewalls and edge devices. Many firewalls speak the RIP protocol and not much else, because implementing it is trivial. Where a firewall and a router need to exchange a handful of routes, RIP is the protocol they both already have.

Legacy equipment nobody will replace. A switch or a router from a decade ago in a network that works. Nobody is going to introduce OSPF to it for three routes.

Very small networks. Under a handful of routers with similar links, hop count is a perfectly adequate metric and the RIP configuration is two lines.

Lab and study environments. The RIP protocol is where routing gets taught, because the whole thing fits on a page.

What it is not suitable for is a network with more than a few routers, mixed link speeds, or a requirement to reconverge quickly. That covers almost every real business network, which is why OSPF is the default answer among interior routing protocols.

PitfallsWhere people go wrong

Running RIPv1 without noticing. Some devices default to it. Classful behavior breaks any sensible addressing plan, and the symptom is routes that appear with the wrong mask.

Leaving authentication off. Anything on the segment can inject routing information and be believed. This is the single most important line of security configuration in a RIP deployment.

Expecting fast reconvergence. Three minutes is normal after a failure. If the network needs seconds, this protocol is the wrong choice and no amount of timer tuning fixes it properly.

Assuming the best path was chosen. It chose the fewest hops. Whether that path is fast is not a question the protocol asks.

Hitting the fifteen hop limit and diagnosing it as a fault. A destination at sixteen hops is unreachable by design. The routing table is correct and the network is too big for the protocol.

Redistributing RIP into OSPF carelessly. Hop counts and OSPF costs are not comparable, and redistributing routing information between the two protocols without a deliberate metric produces results that surprise everyone.

HOP COUNT IS THE ONLY METRIC, AND THIS IS WHAT THAT COSTSSOURCEDEST3 hops, 10 Mb links. RIP chooses this one.4 hops, gigabit links. RIP never considers it.THE SLOW PATH WINS, AND THE PROTOCOL IS BEHAVING EXACTLY AS DESIGNED30sinvalid 180shold-down 180sflush 240sUpdate, invalid, hold-down and flush, to scale. A failed link takes three minutes to be believed dead.Fifteen hops is the maximum. A metric of sixteen is how this protocol says unreachable.
The purple path is the one RIP picks, and it is the wrong one. Nothing is misconfigured here; the metric simply does not know what bandwidth is.

ComparisonFour ways to fill a routing table, and the row that ended one of them

CriterionRIPOSPFEIGRPStatic
TypeDistance vectorLink stateAdvanced distance vectorNone
MetricHop countBandwidth-based costBandwidth and delayWhatever you set
Maximum hops15No practical limitNo practical limitNo limit
ConvergenceMinutesSecondsSecondsManual
Configuration effortTwo linesModerateModeratePer route, by hand
Vendor supportEverythingEverythingCisco, mostlyEverything
Right for a business networkNoYesWhere it fitsSmall and stable

The convergence row is what ended it. Everything else on this page is a design characteristic, and three minutes of black-holed traffic after a link fails is an outage that a routing protocol was supposed to prevent.

FAQFrequently asked questions

What is the RIP protocol?

The Routing Information Protocol, a distance vector routing protocol in which routers advertise their whole routing table to neighbors every thirty seconds and choose paths through the network by hop count.

What metric does RIP use?

Hop count, and only hop count. The number of routers between here and the destination, with no consideration of bandwidth, delay or reliability.

What is the maximum hop count in RIP?

Fifteen. A metric of sixteen means unreachable, which is how the protocol expresses infinity and caps the size of a network it can serve.

What is the difference between RIPv1 and RIPv2?

RIPv1 is classful and broadcasts, so it cannot carry subnet masks. RIPv2 is classless, carries masks, multicasts its updates and supports authentication. Only RIPv2 is worth running.

What is distance vector routing?

Routing based on what neighbors report rather than on a map of the network. Each router adds its own distance to what it was told and passes it on, which is why it is called routing by rumor.

How often does the RIP protocol send updates?

Every thirty seconds, and each update carries the entire routing table rather than only the information that changed.

What port does RIP use?

UDP port 520 for RIP and RIPv2, and UDP port 521 for RIPng on IPv6.

What is split horizon?

A rule that a router never advertises a route back out of the interface it learned it on, which prevents the simplest routing loop between two routers.

What is route poisoning?

Advertising a failed route with a metric of sixteen, meaning unreachable, rather than simply dropping it. The bad news then travels as an announcement rather than as silence.

Why is RIP convergence so slow?

Because of the timers that make its loop prevention work. An update every 30 seconds, a 180 second invalid timer and a 180 second hold-down mean a failed route can take around three minutes to be believed everywhere.

Is the RIP protocol still used?

Yes, in small networks, on firewalls and edge devices that support few other routing protocols, and on legacy equipment. It is not appropriate for a business network of any size.

Should I use RIP or OSPF?

OSPF, in almost every case. It converges in seconds, uses a bandwidth-based metric and has no practical hop limit. RIP is for cases where the other end supports nothing else.

Does RIP support authentication?

RIPv2 does, and it should always be enabled. Without it any device on the segment can inject routes that every router will believe.

Read next · Routing What Is BGP? The other end of the scale: the protocol that runs between networks rather than inside one. Open this next12 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.