HSRP vs VRRP vs GLBP: FHRP Configuration Compared - 夜莺博客

HSRP vs VRRP vs GLBP: FHRP Configuration Compared

First-hop redundancy protocols hide a single default gateway behind a shared virtual IP and virtual MAC, so hosts never notice a router failure. HSRP, VRRP and GLBP all solve that problem, but they differ in ownership, election defaults and load-balancing capability – and those differences are exactly what breaks failover during a maintenance window. This article puts the three side by side, shows working configurations, and lists the behaviours that surprise engineers in production.

The basics that all three share

Two or more routers agree on a virtual IP; one is active and answers ARP for it, with a stable virtual MAC so hosts never re-ARP during failover. Failover time is governed by hello and hold timers, and both HSRP and VRRP converge on the rule "highest priority wins, highest IP breaks the tie". Everything else is detail.

Side-by-side comparison

Property HSRP VRRP GLBP
Origin Cisco proprietary (RFC 2281 informational) IETF standard (RFC 5798) Cisco proprietary
Roles Active / Standby Master / Backup AVG + up to 4 AVFs
Virtual MAC 0000.0c07.acXX (v1), 0000.0c9f.fXXX (v2) 0000.5e00.01XX 0007.b400.XXYY
Default priority 100 100 (IP owner 255) 100
Default timers hello 3 s / hold 10 s advertise 1 s / master-down ~3 s hello 3 s / hold 10 s
Preempt default Disabled Enabled AVG disabled, AVF forwarder preempt separate
Load balancing Only via multiple groups Only via multiple groups Native, per-client virtual MACs
Auth Plaintext default "cisco", optional MD5 None / plaintext / AH, MD5 key Plaintext default "cisco"

Configuration examples

HSRP on two routers with interface tracking

track 1 interface GigabitEthernet0/1 line-protocol

interface GigabitEthernet0/0
 ip address 192.168.10.2 255.255.255.0
 standby 1 ip 192.168.10.254
 standby 1 priority 110
 standby 1 preempt
 standby 1 timers 1 3
 standby 1 track 1 decrement 20

Without preempt the router that boots last never takes back its role, even with a higher priority – the most common cause of "failover worked, failback did not".

VRRP (multivendor)

interface GigabitEthernet0/0
 ip address 192.168.10.3 255.255.255.0
 vrrp 1 ip 192.168.10.254
 vrrp 1 priority 110
 vrrp 1 preempt
 vrrp 1 authentication md5 key-string S3cret
 vrrp 1 track 1 decrement 20

VRRP preempts by default, which is convenient across vendors but can cause a flapping interface to steal mastership repeatedly. Raising the preempt delay is usually the right fix.

GLBP for real load balancing

interface GigabitEthernet0/0
 ip address 192.168.10.4 255.255.255.0
 glbp 1 ip 192.168.10.254
 glbp 1 priority 110
 glbp 1 preempt
 glbp 1 load-balancing round-robin
 glbp 1 weighting 110 lower 60 upper 90
 glbp 1 weighting track 1 decrement 30

GLBP gives one virtual IP with several virtual MACs, distributing the load round-robin or weighted. The AVG hands out MACs; the AVFs actually forward.

Verification

show standby brief
show standby vlan 10
show vrrp brief
show glbp brief
show track

show standby brief is the daily driver: it shows group, priority, the preempt flag, state and virtual IP in one line. A router parked in Listen or Speak rather than Standby usually means a duplicate virtual IP on the segment or mismatched group numbers.

Pitfalls worth planning for

  • Firewall/ACL blocking hellos – HSRP uses UDP 1985 to 224.0.0.2, VRRP uses IP protocol 112 to 224.0.0.18; an uplink ACL that drops multicast kills redundancy silently.
  • Group number mismatch – a group configured on one side but not the other gives two routers both claiming the virtual IP.
  • Tracking too coarse – tracking only the physical interface misses upstream failures; track an IP SLA object for end-to-end reachability.
  • Split groups for load balancing – if you scale HSRP across subnets, remember each group consumes a virtual MAC in the ARP/cam tables of every attached switch.

Related: Cisco IOS IP SLA and track objects, ArubaOS-CX VRRP and active gateway, and Huawei VRRP master/backup.

原文链接:https://community.cisco.com/t5/networking-knowledge-base/gateway-redundancy-protocol/ta-p/3114538