The Routing Information Protocol is a distance vector protocol: routers send their whole routing table to their neighbors every thirty seconds and believe what they are told. The metric is hop count alone, fifteen hops is the maximum, and convergence takes minutes.
- Distance vector, so routers trust neighbors rather than a map
- Hop count is the only metric, so slow paths win when they are shorter
- 15 hops maximum, and 16 means unreachable
- Convergence takes around three minutes, not seconds
- RIPv2 supports authentication, and without it anyone can inject routes
On this page
How it worksHow the RIP protocol actually works
The mechanism is small enough to describe completely, which is most of its appeal.
Every router announces its whole table. Every thirty seconds, a router running the RIP protocol sends its complete routing table to its neighbors. Not the changes, the whole set of routing information.
Every receiver adds one hop and believes it. A router hearing that a neighbor can reach a network in two hops records that it can reach that network in three, through that neighbor. It has no way to check the information, and it does not try.
The lowest hop count wins. When two neighbors offer the same destination, the smaller number wins. Ties go to whichever was learned first.
This is why distance vector routing is described as routing by rumor. A router running the RIP protocol has no picture of the network at all. It knows what its neighbors claim and how far away they said those networks were, and that routing information is the entire basis of every decision it makes.
Compare that to a link state protocol such as OSPF, where every router builds an identical map of the whole area and computes its own shortest paths. The link state router knows the topology. The RIP router knows only what it was told.
Hop countHop count, which is the whole problem
The metric in the Routing Information Protocol is the number of routers between here and the destination network. Nothing else enters the calculation.
That means a one gigabit path across four routers loses to a ten megabit path across three. RIP will choose the slow link, keep choosing it, and be entirely correct according to its own rules.
On networks where all the links are similar this does not matter. On any network built over time, with a mix of speeds, it produces persistently wrong routing that looks like a fault.
The fifteen hop ceiling is the second consequence. A metric of sixteen means unreachable, so no destination can be more than fifteen routers away. That number was chosen because the loop prevention depends on counting to infinity quickly, and infinity had to be small enough to reach in a reasonable time.
The versionsRIPv1, RIPv2 and RIPng
Three versions exist and only two of them should be seen.
RIPv1 is classful. Its updates carry no subnet mask, so every router assumes the mask that matches the address class. That makes variable length subnet masking impossible and rules out most modern addressing. It broadcasts its updates to every device on the segment, whether or not they route. There is no reason to run it.
RIPv2 carries the subnet mask, which makes it classless and compatible with CIDR. It multicasts updates to 224.0.0.9 rather than broadcasting, so devices that are not routers ignore them, and it supports authentication so a router will not accept updates from anything that cannot prove itself. This is the only version worth configuring.
RIPng is the RIP protocol for IPv6, on UDP port 521. Same distance vector behavior, the same routing information every 30 seconds, the same fifteen hop limit, a different address family.
The authentication in RIPv2 deserves a specific mention. Without it, anything on the segment can inject routing information and be believed, because believing neighbors is the entire protocol. Configuring authentication is not optional security hardening, it is the difference between a routing protocol and an open invitation.
Loops and timersLoop prevention, and the timers nobody remembers
Distance vector protocols create routing loops naturally, because a router that hears its own information back from a neighbor cannot tell that it is its own. Three mechanisms address that, and they are the reason convergence is slow.
Split horizon. A router never advertises a route back out the interface it learned it on. This stops the simplest two-router loop entirely and costs nothing.
Route poisoning. When a route fails, the router advertises it with a metric of sixteen rather than withdrawing it silently. Sixteen means unreachable, so the news travels as a positive statement instead of an absence, which propagates far faster.
Hold-down timers. After hearing that a route is unreachable, a router refuses further updates about that network for a period, so stale routing information circulating in the network cannot resurrect it.
Those timers are why the RIP protocol converges in minutes rather than seconds. The defaults on most implementations are a 30 second update, a 180 second invalid timer, a 180 second hold-down and a 240 second flush. A link that fails can take three minutes to be believed dead everywhere, and during those minutes traffic is going to a router that cannot deliver it.
Where it survivesWhere you still meet it
The RIP protocol is not dead, and it survives in four places.
Small firewalls and edge devices. Many firewalls speak the RIP protocol and not much else, because implementing it is trivial. Where a firewall and a router need to exchange a handful of routes, RIP is the protocol they both already have.
Legacy equipment nobody will replace. A switch or a router from a decade ago in a network that works. Nobody is going to introduce OSPF to it for three routes.
Very small networks. Under a handful of routers with similar links, hop count is a perfectly adequate metric and the RIP configuration is two lines.
Lab and study environments. The RIP protocol is where routing gets taught, because the whole thing fits on a page.
What it is not suitable for is a network with more than a few routers, mixed link speeds, or a requirement to reconverge quickly. That covers almost every real business network, which is why OSPF is the default answer among interior routing protocols.
PitfallsWhere people go wrong
Running RIPv1 without noticing. Some devices default to it. Classful behavior breaks any sensible addressing plan, and the symptom is routes that appear with the wrong mask.
Leaving authentication off. Anything on the segment can inject routing information and be believed. This is the single most important line of security configuration in a RIP deployment.
Expecting fast reconvergence. Three minutes is normal after a failure. If the network needs seconds, this protocol is the wrong choice and no amount of timer tuning fixes it properly.
Assuming the best path was chosen. It chose the fewest hops. Whether that path is fast is not a question the protocol asks.
Hitting the fifteen hop limit and diagnosing it as a fault. A destination at sixteen hops is unreachable by design. The routing table is correct and the network is too big for the protocol.
Redistributing RIP into OSPF carelessly. Hop counts and OSPF costs are not comparable, and redistributing routing information between the two protocols without a deliberate metric produces results that surprise everyone.
ComparisonFour ways to fill a routing table, and the row that ended one of them
| Criterion | RIP | OSPF | EIGRP | Static |
|---|---|---|---|---|
| Type | Distance vector | Link state | Advanced distance vector | None |
| Metric | Hop count | Bandwidth-based cost | Bandwidth and delay | Whatever you set |
| Maximum hops | 15 | No practical limit | No practical limit | No limit |
| Convergence | Minutes | Seconds | Seconds | Manual |
| Configuration effort | Two lines | Moderate | Moderate | Per route, by hand |
| Vendor support | Everything | Everything | Cisco, mostly | Everything |
| Right for a business network | No | Yes | Where it fits | Small and stable |
The convergence row is what ended it. Everything else on this page is a design characteristic, and three minutes of black-holed traffic after a link fails is an outage that a routing protocol was supposed to prevent.
FAQFrequently asked questions
What is the RIP protocol?
The Routing Information Protocol, a distance vector routing protocol in which routers advertise their whole routing table to neighbors every thirty seconds and choose paths through the network by hop count.
What metric does RIP use?
Hop count, and only hop count. The number of routers between here and the destination, with no consideration of bandwidth, delay or reliability.
What is the maximum hop count in RIP?
Fifteen. A metric of sixteen means unreachable, which is how the protocol expresses infinity and caps the size of a network it can serve.
What is the difference between RIPv1 and RIPv2?
RIPv1 is classful and broadcasts, so it cannot carry subnet masks. RIPv2 is classless, carries masks, multicasts its updates and supports authentication. Only RIPv2 is worth running.
What is distance vector routing?
Routing based on what neighbors report rather than on a map of the network. Each router adds its own distance to what it was told and passes it on, which is why it is called routing by rumor.
How often does the RIP protocol send updates?
Every thirty seconds, and each update carries the entire routing table rather than only the information that changed.
What port does RIP use?
UDP port 520 for RIP and RIPv2, and UDP port 521 for RIPng on IPv6.
What is split horizon?
A rule that a router never advertises a route back out of the interface it learned it on, which prevents the simplest routing loop between two routers.
What is route poisoning?
Advertising a failed route with a metric of sixteen, meaning unreachable, rather than simply dropping it. The bad news then travels as an announcement rather than as silence.
Why is RIP convergence so slow?
Because of the timers that make its loop prevention work. An update every 30 seconds, a 180 second invalid timer and a 180 second hold-down mean a failed route can take around three minutes to be believed everywhere.
Is the RIP protocol still used?
Yes, in small networks, on firewalls and edge devices that support few other routing protocols, and on legacy equipment. It is not appropriate for a business network of any size.
Should I use RIP or OSPF?
OSPF, in almost every case. It converges in seconds, uses a bandwidth-based metric and has no practical hop limit. RIP is for cases where the other end supports nothing else.
Does RIP support authentication?
RIPv2 does, and it should always be enabled. Without it any device on the segment can inject routes that every router will believe.
Keep readingRelated concepts
Read next · Routing What Is BGP? The other end of the scale: the protocol that runs between networks rather than inside one. Open this next12 min- Routing · 12 min OSPF Explained The link state protocol that replaced this one, where every router holds a map instead of a rumor.
- Routing · 12 min Static vs Dynamic Routing, and the Route That Never Fails Whether a small network needs a routing protocol at all, which is the question before this one.
- Routing · 11 min EIGRP Configuration, and the Feasible Successor Logic That Makes It Work The periodic-update ancestor of EIGRP’s triggered, loop-free distance vector.