IGMP is the Internet Group Management Protocol, and it is how a host tells the network that it wants a particular multicast stream. The host sends a join, the router starts forwarding that group onto the segment, and every 125 seconds the router asks again whether anybody still wants it.
Membership is a lease rather than a setting: if nothing on the segment sends those periodic queries, the lease expires 260 seconds later and the traffic stops.
- Lets a host join and leave a multicast group
- Runs directly in IP, protocol number 2, with no transport layer
- Membership expires after 260 seconds unless it is renewed
- IGMP snooping is a Layer 2 switch listening in so it can stop flooding
- Snooping with nothing sending queries is the classic four minute failure
On this page
The protocolWhat IGMP actually does
Multicast sends one copy of the data to many receivers, which is why it exists for video, market data, imaging and discovery. The hard part is not sending the traffic. The hard part is knowing which devices want it, and IGMP is the answer to that question and nothing else.
Three IGMP messages carry the whole protocol. A membership report is a host saying it wants a multicast group. A query is a router asking which hosts still want anything. A leave message is a host saying it is finished, which IGMPv2 added so a router does not have to wait for a timeout to find out.
The direction matters. Hosts do not register with anything centrally and routers do not push a list downward. The router asks the network segment periodically, the hosts answer, and the group state exists only as long as those IGMP messages keep arriving. That is the design decision everything else follows from.
| Version | RFC | What it added |
|---|---|---|
| IGMPv1 | RFC 1112, 1989 | Join and query, no explicit leave |
| IGMPv2 | RFC 2236, 1997 | Leave messages and a querier election |
| IGMPv3 | RFC 9776, 2025 | Source specific filtering, include and exclude lists |
IGMPv3 was specified in RFC 3376 for twenty years, which is what almost every article still cites. RFC 9776 obsoletes it and is the current standard, with clarifications and errata fixes rather than a new protocol, so nothing in a working network changes. It is worth citing the current one anyway.
SnoopingIGMP snooping, and why the switch is where the trouble is
A Layer 2 switch is not supposed to care about IP at all. A multicast frame has a multicast destination address, and the default behavior for a frame a switch has no entry for is to flood the traffic out every port in the VLAN.
On a quiet network nobody notices. On a network carrying a video stream, every device gets the data whether or not it asked.
IGMP snooping is a Layer 2 switch reading the IGMP messages that pass through it anyway, building a table of which ports asked for which multicast group, and forwarding the traffic accordingly.
It is not part of IGMP. It is a switch feature that eavesdrops on IGMP, and RFC 4541 exists to describe how a switch should behave while doing it, because the protocol itself never anticipated being overheard.
Two consequences follow, and both surprise people.
The first is that IGMP snooping depends on hearing queries. No queries on a network segment means no reports in response to them, which means no entries, which means the switch either falls back to flooding the multicast or drops it entirely.
So enabling snooping on a VLAN with no multicast router in it does not improve anything; it introduces a dependency that was not there before.
The second is that vendors legitimately differ on what to do with a group nobody has asked for. RFC 4541 requires a switch to forward an unregistered packet to any port with an IGMP router attached, and says a switch may default to forwarding unregistered packets on all ports.
May, not must. This is why the same configuration produces flooding on one brand and silence on another, and why the answer to what happens to unregistered multicast is genuinely the vendor documentation rather than the standard.
The classic faultThe four minute failure
This is the fault worth being able to recognize on sight, because it is specific and it is common.
The symptom: a stream, a camera feed, a screen or an imaging job works, and then between four and five minutes later the multicast data stops. Restarting the client device fixes it, for another four minutes.
The arithmetic behind it, all from IGMPv2 defaults.
| Timer | Default | What it governs |
|---|---|---|
| Query interval | 125 seconds | How often the querier asks |
| Query response interval | 10 seconds | How long a host may wait to answer |
| Robustness variable | 2 | How many losses the design tolerates |
| Group membership interval | 260 seconds | Robustness times interval, plus one response |
When no IGMP membership report arrives inside the group membership interval, the router concludes the multicast group has no local members and stops forwarding that traffic onto the network. Two times 125 plus 10 is 260 seconds, which is four minutes and twenty seconds, and that is the number the symptom is describing.
The cause is almost always that no device is sending queries. There is no multicast router on that VLAN, or there is one and IGMP is not enabled on the interface, or a Layer 2 switch was expected to act as querier and was never configured to.
The fix is to give the segment a querier, and RFC 4541 notes that a snooping switch sending proxy queries should use an all zeros source address when it is not itself the elected querier.
In the fieldWhere an IT team actually meets IGMP
| Situation | What uses multicast | The usual symptom |
|---|---|---|
| Digital signage and IPTV | The video stream itself | Flooding, or the four minute stop |
| Imaging and deployment | Multicast image delivery | Slow or failed imaging over one VLAN |
| Building systems | Cameras, access control, audio | Traffic on ports that should be quiet |
| Consumer devices at work | Discovery protocols | Wireless slowdowns from flooded frames |
| Market data and trading | The feed | Loss under load, which is the intended use |
The fourth row deserves a note, because it is the one that reaches a help desk without ever being called multicast. Discovery on an office wireless network floods the messages to every associated device, and on a busy access point that is real airtime spent on traffic almost nobody wants.
The fix is usually a filtering feature on the wireless controller rather than IGMP, but the diagnosis starts in the same place: something is flooding, and nothing is limiting who receives it.
PitfallsWhere people go wrong
Enabling IGMP snooping without a querier. The single most common IGMP mistake, and the cause of the four minute failure. Snooping needs a conversation to listen to.
Treating group membership as configuration. It is a lease with a 260 second expiry. Anything that stops the periodic exchange of IGMP messages stops the traffic, on a delay long enough that nobody connects the two events.
Assuming unregistered multicast behaves the same everywhere. RFC 4541 says a switch may flood it. Two switches from two vendors are both compliant and behave differently.
Blaming the application. A stream that dies at a consistent four to five minutes is not an application bug. The interval is a network timer, and its value is printed above.
Confusing IGMP with multicast routing. IGMP works between hosts and their local router on one network segment. Getting multicast data from one segment to another is PIM, which is a separate protocol and a separate configuration.
Turning snooping off to fix flooding. That is backwards. Snooping off is the flooding, and the fix is snooping on with something sending queries.
ComparisonUnicast, broadcast and multicast, side by side
| Criterion | Unicast | Broadcast | Multicast |
|---|---|---|---|
| Recipients | One | Everyone on the segment | Whoever joined |
| Copies sent by the source | One per receiver | One | One |
| Crosses a router | Yes | No | Yes, if routing is configured |
| Who controls delivery | The sender | Nobody | The receivers, through IGMP |
| Scales to many receivers | No | Poorly, it reaches everyone | Yes, this is the point |
| Default switch behavior | Forward to one port | Flood | Flood, unless snooping is on |
The fourth row is the one that explains the protocol. In multicast the receiving devices decide, which is unusual, and IGMP is the entire mechanism by which they do it.
FAQFrequently asked questions
What is IGMP?
The Internet Group Management Protocol. It is how a host tells the router on its network that it wants to receive a particular multicast group, and how the router periodically checks whether anybody still does.
What does IGMP stand for?
Internet Group Management Protocol. The group in the name is a multicast group, and managing membership of those groups is the whole of what it does.
Is IGMP a routing protocol?
No. It works between hosts and the router on their own segment. Moving multicast between segments is done by a multicast routing protocol such as PIM.
What is IGMP snooping?
A Layer 2 switch feature that reads the IGMP messages passing through it and builds a table of which ports asked for which multicast group, so the traffic goes only to those ports instead of being flooded to the whole VLAN.
What is an IGMP querier?
Whatever sends the periodic general queries on a segment, normally the multicast router. Without one, no reports are triggered, membership expires and snooping has nothing to work with.
Why does my multicast stream stop after about four minutes?
Because the group membership interval is 260 seconds by default, and when no report arrives within it the router stops forwarding the group. Something is not sending queries.
How often does IGMP send queries?
Every 125 seconds by default, with hosts allowed up to 10 seconds to respond. Those two numbers, with a robustness value of 2, produce the 260 second expiry.
What is the difference between IGMPv2 and IGMPv3?
IGMPv2 added explicit leave messages and querier election. IGMPv3 added source specific filtering, so a host can ask for a group only from named sources, and it is now specified in RFC 9776.
Which RFC defines IGMP?
RFC 1112 for version 1, RFC 2236 for version 2, and RFC 9776 for version 3, which obsoleted RFC 3376 in 2025. Snooping behavior is covered separately in RFC 4541.
What address do IGMP queries use?
General queries go to 224.0.0.1, the all hosts group on the local segment. IGMPv3 membership reports go to 224.0.0.22.
Should I enable IGMP snooping?
Yes, wherever multicast is present and something on that VLAN is sending queries. On a VLAN with neither, snooping adds a dependency without solving a problem.
Does IGMP work over a VPN or between sites?
Only where multicast routing has been configured for that path. Most site to site tunnels carry unicast traffic only, which is why multicast applications so often stop at the site boundary.
Why is multicast flooding every port on my switch?
Because a Layer 2 switch floods frames it has no forwarding entry for, and without IGMP snooping it has no entry for a multicast group. Snooping, with a querier present, is what creates the entries.
Is IGMP a security concern?
It has no authentication, so any device on the network segment can join any multicast group it likes and can influence snooping state. On a network where that matters, the control is segmentation with VLANs rather than anything inside the protocol.
What are the IGMP timers?
The main IGMP timers in version 2 are the query interval, 125 seconds by default, and the maximum response time, 10 seconds. With a robustness value of 2 they give a group membership interval of 260 seconds. A switch doing IGMP snooping needs timers that agree with the querier, or streams drop periodically.
Keep readingRelated concepts
Read next · Switching Spanning Tree Protocol The other switch behavior that only becomes visible when it goes wrong, and the other one people disable for the wrong reason. Open this next11 min- Switching · 14 min What Is a VLAN? The boundary multicast floods inside, and the segmentation that decides how far a flooded group actually reaches.
- Diagnostics · 11 min Packet Loss vs Latency, and Why They Feel the Same to Users How to tell a stream that is being dropped from a stream that has stopped being forwarded, which look identical from the desk.
- Routing · 9 min Protocol Independent Multicast, and How PIM Builds the Tree How a host signals the multicast group that PIM then routes to it.