Networking · Concept · 9 min read

What IGMP Is, and Why Multicast Floods Without It

Most people meet IGMP because multicast is flooding every port, or because a stream worked for four minutes and died. Both symptoms are the same mechanism seen from opposite sides.

Written by Marko Ristic, Editor Updated Sep 17, 2026
260 sGroup membership interval, and the length of the mystery outage
125 sHow often the querier asks whether anybody still wants the group
2The IP protocol number IGMP rides in, with no transport layer
9776The RFC that replaced 3376 as the IGMPv3 specification in 2025
Short answer

IGMP is the Internet Group Management Protocol, and it is how a host tells the network that it wants a particular multicast stream. The host sends a join, the router starts forwarding that group onto the segment, and every 125 seconds the router asks again whether anybody still wants it.

Membership is a lease rather than a setting: if nothing on the segment sends those periodic queries, the lease expires 260 seconds later and the traffic stops.

  • Lets a host join and leave a multicast group
  • Runs directly in IP, protocol number 2, with no transport layer
  • Membership expires after 260 seconds unless it is renewed
  • IGMP snooping is a Layer 2 switch listening in so it can stop flooding
  • Snooping with nothing sending queries is the classic four minute failure
On this page

The protocolWhat IGMP actually does

Multicast sends one copy of the data to many receivers, which is why it exists for video, market data, imaging and discovery. The hard part is not sending the traffic. The hard part is knowing which devices want it, and IGMP is the answer to that question and nothing else.

Three IGMP messages carry the whole protocol. A membership report is a host saying it wants a multicast group. A query is a router asking which hosts still want anything. A leave message is a host saying it is finished, which IGMPv2 added so a router does not have to wait for a timeout to find out.

The direction matters. Hosts do not register with anything centrally and routers do not push a list downward. The router asks the network segment periodically, the hosts answer, and the group state exists only as long as those IGMP messages keep arriving. That is the design decision everything else follows from.

VersionRFCWhat it added
IGMPv1RFC 1112, 1989Join and query, no explicit leave
IGMPv2RFC 2236, 1997Leave messages and a querier election
IGMPv3RFC 9776, 2025Source specific filtering, include and exclude lists

IGMPv3 was specified in RFC 3376 for twenty years, which is what almost every article still cites. RFC 9776 obsoletes it and is the current standard, with clarifications and errata fixes rather than a new protocol, so nothing in a working network changes. It is worth citing the current one anyway.

SnoopingIGMP snooping, and why the switch is where the trouble is

A Layer 2 switch is not supposed to care about IP at all. A multicast frame has a multicast destination address, and the default behavior for a frame a switch has no entry for is to flood the traffic out every port in the VLAN.

On a quiet network nobody notices. On a network carrying a video stream, every device gets the data whether or not it asked.

IGMP snooping is a Layer 2 switch reading the IGMP messages that pass through it anyway, building a table of which ports asked for which multicast group, and forwarding the traffic accordingly.

It is not part of IGMP. It is a switch feature that eavesdrops on IGMP, and RFC 4541 exists to describe how a switch should behave while doing it, because the protocol itself never anticipated being overheard.

Two consequences follow, and both surprise people.

The first is that IGMP snooping depends on hearing queries. No queries on a network segment means no reports in response to them, which means no entries, which means the switch either falls back to flooding the multicast or drops it entirely.

So enabling snooping on a VLAN with no multicast router in it does not improve anything; it introduces a dependency that was not there before.

The second is that vendors legitimately differ on what to do with a group nobody has asked for. RFC 4541 requires a switch to forward an unregistered packet to any port with an IGMP router attached, and says a switch may default to forwarding unregistered packets on all ports.

May, not must. This is why the same configuration produces flooding on one brand and silence on another, and why the answer to what happens to unregistered multicast is genuinely the vendor documentation rather than the standard.

The classic faultThe four minute failure

This is the fault worth being able to recognize on sight, because it is specific and it is common.

The symptom: a stream, a camera feed, a screen or an imaging job works, and then between four and five minutes later the multicast data stops. Restarting the client device fixes it, for another four minutes.

The arithmetic behind it, all from IGMPv2 defaults.

TimerDefaultWhat it governs
Query interval125 secondsHow often the querier asks
Query response interval10 secondsHow long a host may wait to answer
Robustness variable2How many losses the design tolerates
Group membership interval260 secondsRobustness times interval, plus one response

When no IGMP membership report arrives inside the group membership interval, the router concludes the multicast group has no local members and stops forwarding that traffic onto the network. Two times 125 plus 10 is 260 seconds, which is four minutes and twenty seconds, and that is the number the symptom is describing.

The cause is almost always that no device is sending queries. There is no multicast router on that VLAN, or there is one and IGMP is not enabled on the interface, or a Layer 2 switch was expected to act as querier and was never configured to.

The fix is to give the segment a querier, and RFC 4541 notes that a snooping switch sending proxy queries should use an all zeros source address when it is not itself the elected querier.

In the fieldWhere an IT team actually meets IGMP

SituationWhat uses multicastThe usual symptom
Digital signage and IPTVThe video stream itselfFlooding, or the four minute stop
Imaging and deploymentMulticast image deliverySlow or failed imaging over one VLAN
Building systemsCameras, access control, audioTraffic on ports that should be quiet
Consumer devices at workDiscovery protocolsWireless slowdowns from flooded frames
Market data and tradingThe feedLoss under load, which is the intended use

The fourth row deserves a note, because it is the one that reaches a help desk without ever being called multicast. Discovery on an office wireless network floods the messages to every associated device, and on a busy access point that is real airtime spent on traffic almost nobody wants.

The fix is usually a filtering feature on the wireless controller rather than IGMP, but the diagnosis starts in the same place: something is flooding, and nothing is limiting who receives it.

PitfallsWhere people go wrong

Enabling IGMP snooping without a querier. The single most common IGMP mistake, and the cause of the four minute failure. Snooping needs a conversation to listen to.

Treating group membership as configuration. It is a lease with a 260 second expiry. Anything that stops the periodic exchange of IGMP messages stops the traffic, on a delay long enough that nobody connects the two events.

Assuming unregistered multicast behaves the same everywhere. RFC 4541 says a switch may flood it. Two switches from two vendors are both compliant and behave differently.

Blaming the application. A stream that dies at a consistent four to five minutes is not an application bug. The interval is a network timer, and its value is printed above.

Confusing IGMP with multicast routing. IGMP works between hosts and their local router on one network segment. Getting multicast data from one segment to another is PIM, which is a separate protocol and a separate configuration.

Turning snooping off to fix flooding. That is backwards. Snooping off is the flooding, and the fix is snooping on with something sending queries.

THE FOUR MINUTE FAILURE, ON A CLOCKEvery mark is an IGMPv2 default from RFC 2236.With a querieron the segmenttraffic flowsqueryqueryqueryNo queriernothing asks againtraffic stopsjoin260 s0 s125 s250 s300 stime since the join260 s is the group membership interval: robustness 2, times 125 s, plus one 10 s response.Four minutes twenty. Which is the number the help desk ticket is already describing.
The two tracks differ by one thing: whether anybody is asking. Everything else on the clock follows from the defaults.

ComparisonUnicast, broadcast and multicast, side by side

CriterionUnicastBroadcastMulticast
RecipientsOneEveryone on the segmentWhoever joined
Copies sent by the sourceOne per receiverOneOne
Crosses a routerYesNoYes, if routing is configured
Who controls deliveryThe senderNobodyThe receivers, through IGMP
Scales to many receiversNoPoorly, it reaches everyoneYes, this is the point
Default switch behaviorForward to one portFloodFlood, unless snooping is on

The fourth row is the one that explains the protocol. In multicast the receiving devices decide, which is unusual, and IGMP is the entire mechanism by which they do it.

FAQFrequently asked questions

What is IGMP?

The Internet Group Management Protocol. It is how a host tells the router on its network that it wants to receive a particular multicast group, and how the router periodically checks whether anybody still does.

What does IGMP stand for?

Internet Group Management Protocol. The group in the name is a multicast group, and managing membership of those groups is the whole of what it does.

Is IGMP a routing protocol?

No. It works between hosts and the router on their own segment. Moving multicast between segments is done by a multicast routing protocol such as PIM.

What is IGMP snooping?

A Layer 2 switch feature that reads the IGMP messages passing through it and builds a table of which ports asked for which multicast group, so the traffic goes only to those ports instead of being flooded to the whole VLAN.

What is an IGMP querier?

Whatever sends the periodic general queries on a segment, normally the multicast router. Without one, no reports are triggered, membership expires and snooping has nothing to work with.

Why does my multicast stream stop after about four minutes?

Because the group membership interval is 260 seconds by default, and when no report arrives within it the router stops forwarding the group. Something is not sending queries.

How often does IGMP send queries?

Every 125 seconds by default, with hosts allowed up to 10 seconds to respond. Those two numbers, with a robustness value of 2, produce the 260 second expiry.

What is the difference between IGMPv2 and IGMPv3?

IGMPv2 added explicit leave messages and querier election. IGMPv3 added source specific filtering, so a host can ask for a group only from named sources, and it is now specified in RFC 9776.

Which RFC defines IGMP?

RFC 1112 for version 1, RFC 2236 for version 2, and RFC 9776 for version 3, which obsoleted RFC 3376 in 2025. Snooping behavior is covered separately in RFC 4541.

What address do IGMP queries use?

General queries go to 224.0.0.1, the all hosts group on the local segment. IGMPv3 membership reports go to 224.0.0.22.

Should I enable IGMP snooping?

Yes, wherever multicast is present and something on that VLAN is sending queries. On a VLAN with neither, snooping adds a dependency without solving a problem.

Does IGMP work over a VPN or between sites?

Only where multicast routing has been configured for that path. Most site to site tunnels carry unicast traffic only, which is why multicast applications so often stop at the site boundary.

Why is multicast flooding every port on my switch?

Because a Layer 2 switch floods frames it has no forwarding entry for, and without IGMP snooping it has no entry for a multicast group. Snooping, with a querier present, is what creates the entries.

Is IGMP a security concern?

It has no authentication, so any device on the network segment can join any multicast group it likes and can influence snooping state. On a network where that matters, the control is segmentation with VLANs rather than anything inside the protocol.

What are the IGMP timers?

The main IGMP timers in version 2 are the query interval, 125 seconds by default, and the maximum response time, 10 seconds. With a robustness value of 2 they give a group membership interval of 260 seconds. A switch doing IGMP snooping needs timers that agree with the querier, or streams drop periodically.

Read next · Switching Spanning Tree Protocol The other switch behavior that only becomes visible when it goes wrong, and the other one people disable for the wrong reason. Open this next11 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.