Lesson 2.1.4 — FHRP and Virtual IPs for Gateway Redundancy

Avatar Of Asad IjazAsad Ijaz ·Sep 17, 2026 ·7 min read
Illustration Of A Roadway Supported By Two Identical Pillars Beneath One Continuous Road Surface

Domain 2.0 | Network Implementation — 20% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain the purpose of a First Hop Redundancy Protocol (FHRP) and why default gateway redundancy matters
  • Describe how a virtual IP (VIP) and virtual MAC address let multiple physical routers act as one default gateway
  • Compare the core characteristics of HSRP, VRRP, and GLBP
  • Distinguish active/standby operation from GLBP’s active/active load-balancing approach
  • Explain priority, preemption, and object tracking in FHRP failover behavior

Key Terms

TermDefinition
FHRP (First Hop Redundancy Protocol)A protocol that lets multiple physical routers share a single virtual IP address, so hosts always have a reachable default gateway even if one router fails
Virtual IP (VIP)The shared IP address configured as the default gateway on end hosts, mapped to whichever physical router is currently active
HSRP (Hot Standby Router Protocol)Cisco’s proprietary FHRP, using active/standby roles
VRRP (Virtual Router Redundancy Protocol)The open-standard FHRP equivalent to HSRP, using master/backup roles
GLBP (Gateway Load Balancing Protocol)Cisco’s FHRP that allows multiple routers to actively forward traffic simultaneously, rather than sitting idle in standby
PreemptionThe behavior where a higher-priority router reclaims the active role once it comes back online, rather than leaving a lower-priority router in charge

Explanation

Why a Default Gateway Is a Single Point of Failure

Every host on a subnet is configured with exactly one default gateway address — the router it sends traffic to whenever the destination isn’t on the local network. That’s a problem: if that one router goes down, every host on the subnet loses its path out, even if a second, perfectly healthy router sits right next to it on the same segment. Manually reconfiguring hundreds of hosts with a new gateway address during an outage isn’t realistic, and hosts don’t dynamically discover a replacement gateway on their own.

This is exactly the kind of redundancy gap that the traditional topologies lesson touched on conceptually — having two routers physically present on a segment does nothing for reliability if hosts only know how to talk to one of them.

What an FHRP Actually Does: Virtual IP and Virtual MAC

A First Hop Redundancy Protocol (FHRP) solves this by having two or more physical routers share one virtual IP address (VIP). Hosts on the subnet are configured with the virtual IP as their default gateway — never a real router’s actual address. Behind the scenes, the FHRP also assigns a shared virtual MAC address, so that at Layer 2, ARP requests for the gateway’s IP always resolve to the same virtual MAC no matter which physical router is currently doing the forwarding.

Diagram Showing Two Physical Routers Sharing One Virtual Ip And Virtual Mac As A Single Default Gateway For Hosts
How Multiple Physical Routers Share One Virtual Ip And Virtual Mac As A Single Default Gateway

How Multiple Physical Routers Share One Virtual IP And Virtual MAC As A Single Default Gateway

At any given moment, one physical router is actually forwarding traffic sent to the virtual IP. If that router fails, another router in the group takes over the virtual IP and virtual MAC almost immediately — and because the hosts never had to change anything (they were always pointed at the virtual address), the failover is completely transparent to every device on the subnet.

HSRP: Cisco’s Original Standard

HSRP (Hot Standby Router Protocol) is Cisco’s original, proprietary FHRP, and it’s still extremely common in Cisco-only environments. HSRP uses an active/standby model: exactly one router in the group is active and forwarding traffic at any time, while the other routers sit in standby, ready to take over.

Key HSRP characteristics:

  • Priority determines which router becomes active — higher priority wins (default priority is 100).
  • Virtual MAC address follows the pattern 0000.0c07.acXX, where XX is the HSRP group number in hexadecimal.
  • Hello and hold timers control how often routers announce themselves and how long a standby router waits before assuming the active router has failed.
  • Only one router is ever actively forwarding traffic per group — the rest are idle from a forwarding perspective, even though they’re healthy.

VRRP: The Open Standard Equivalent

VRRP (Virtual Router Redundancy Protocol) does essentially the same job as HSRP but as an open, vendor-neutral standard, making it common in multi-vendor environments where not every device is Cisco.

Key differences from HSRP, mostly in terminology:

  • VRRP calls its active router the master and the others backup, instead of active/standby.
  • VRRP’s virtual MAC address pattern is 0000.5e00.01XX.
  • One functional difference worth remembering: VRRP can use a router’s own real interface IP as the virtual IP, whereas HSRP always requires a distinct virtual IP.

Functionally, though, VRRP behaves almost identically to HSRP — same single-active-router model, same idea of priority determining who’s in charge.

GLBP: Adding Load Balancing

GLBP (Gateway Load Balancing Protocol), also Cisco-proprietary, takes a different approach. Instead of leaving all but one router idle, GLBP lets multiple routers actively forward traffic at the same time — true active/active operation.

GLBP does this with two roles:

  • The Active Virtual Gateway (AVG) is elected to handle ARP requests for the virtual IP, but instead of always replying with the same virtual MAC, it hands out different virtual MAC addresses to different hosts, spreading them across multiple Active Virtual Forwarders (AVFs).
  • Each AVF is a physical router actually forwarding traffic for the subset of hosts it was assigned, meaning the traffic load gets distributed across all group members instead of concentrating on a single active router.
Diagram Comparing Hsrp, Vrrp, And Glbp Roles, Virtual Mac Formats, And Active Router Counts
How Hsrp, Vrrp, And Glbp Differ In Roles, Virtual Mac Format, And Active Router Count

How HSRP, VRRP, and GLBP Differ In Roles, Virtual MAC Format, And Active Router Count

HSRPVRRPGLBP
VendorCisco proprietaryOpen standardCisco proprietary
RolesActive / StandbyMaster / BackupAVG / AVF (multiple)
Forwarding modelActive/standby (one forwards)Active/standby (one forwards)Active/active (multiple forward)
Virtual MAC pattern0000.0c07.acXX0000.5e00.01XXMultiple virtual MACs per group
Can use a real interface IP as the VIP?NoYesNo

Priority, Preemption, and Object Tracking

Which router becomes active isn’t left to chance — it’s determined by a configurable priority value, and the router with the highest priority in the group wins the active/master role during a normal election.

Preemption controls what happens when a higher-priority router that was previously down comes back online. With preemption enabled, that router immediately reclaims the active role from whatever lower-priority router had taken over in its absence. Without preemption enabled, the current active router — even if it has a lower priority — simply stays active until it fails again, which can leave a network quietly running on its “backup” path indefinitely without anyone noticing.

Diagram Showing How Priority Determines The Active Router And How Preemption Affects Failback
How Priority And Preemption Determine Which Router Becomes And Stays Active

How Priority And Preemption Determine Which Router Becomes And Stays Active

Many real deployments also use object tracking, where a router’s priority is automatically lowered if a tracked interface (often the uplink toward the internet or the rest of the network) goes down — even if the router’s connection to the local subnet is still perfectly healthy. This prevents a scenario where a router keeps winning the active election on its local segment while having no usable path to anywhere else.

Where FHRP Fits in the Bigger Picture

FHRP virtual IPs are almost always the address configured as the default gateway on end-user subnets, sitting in front of whatever routing and address translation work is happening further out. A pair of distribution-layer routers might run HSRP or VRRP between themselves, present a single virtual IP to hosts on the subnet, and each independently run dynamic routing protocols and NAT/PAT translation toward the rest of the network and the internet. FHRP solves exactly one problem — gateway reachability — and it’s designed to sit cleanly alongside everything else these routers are doing.

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • A gateway MAC address beginning with 0000.0c07.ac points to HSRP; one beginning with 0000.5e00.01 points to VRRP.
  • Only one router responding to ARP for the gateway IP with a single, unchanging virtual MAC — while other group members stay idle — describes active/standby operation (HSRP or VRRP).
  • Multiple routers simultaneously forwarding traffic for the same virtual IP, using different virtual MACs handed out to different hosts, is the signature of GLBP’s active/active model.
  • A router with a healthy local subnet connection but a failed uplink, whose priority has automatically dropped, points to object tracking in action.

Common Exam Traps

  • HSRP and VRRP are functionally similar but not identical. VRRP can use a real interface address as the virtual IP; HSRP cannot. Don’t assume the two are perfectly interchangeable.
  • GLBP is the only one of the three that’s genuinely active/active. HSRP and VRRP both concentrate all forwarding on a single active/master router — don’t describe either of them as load-balancing traffic.
  • Priority determines the election, but preemption determines what happens afterward. A high-priority router that comes back online will not automatically reclaim the active role unless preemption is explicitly enabled.
  • FHRP is not a routing protocol and has no administrative distance. It solves the “what’s my gateway” problem at the edge of a subnet, not the “how do I reach a distant network” problem that OSPF, EIGRP, and BGP solve.
  • The virtual MAC address patterns are frequently tested exhibit material — recognize 0000.0c07.ac as HSRP and 0000.5e00.01 as VRRP on sight.

Lesson 2.1.4 Practice Quiz — FHRP and Virtual IPs for Gateway Redundancy

17 questions covering HSRP, VRRP, GLBP, virtual IPs and MACs, priority, preemption, and object tracking.

N10-009 · Domain 2.1
Question 1Plain
What problem does a First Hop Redundancy Protocol (FHRP) solve?
FHRP lets multiple physical routers share a virtual IP as the default gateway, so a single router failure doesn't cut hosts off from their gateway.
Question 2Plain
Which virtual MAC address pattern is associated with HSRP?
HSRP's virtual MAC pattern is 0000.0c07.acXX, where XX is the group number in hex. 0000.5e00.01XX is VRRP's pattern.
Question 3Plain
What does preemption control in an FHRP group?
Preemption determines whether a router that comes back online with a higher priority than the current active router will take over the active role again.
Question 4Choose Two
Which two statements about GLBP are correct? (Choose two.)
GLBP is Cisco-proprietary (not open standard) and uniquely supports active/active forwarding, using an AVG to assign hosts across multiple AVFs rather than leaving all but one router idle.
Question 5Choose Two
Which two statements about VRRP are correct? (Choose two.)
VRRP is the open-standard FHRP and is unique among the three in being able to use a router's real interface address as the virtual IP. Active Virtual Forwarders are a GLBP concept, and VRRP is not Cisco-proprietary.
Question 6Choose Two
Which two statements correctly describe how FHRP elections and role changes work? (Choose two.)
Priority decides the election outcome, and preemption decides whether a later-arriving higher-priority router takes back control. Administrative distance and metric are routing concepts, not FHRP concepts.
Question 7Scenario
A company has a mixed-vendor network with routers from two different manufacturers and needs a gateway redundancy protocol both vendors support. Which protocol fits best?
VRRP is the open, vendor-neutral standard, making it the right choice when routers from multiple manufacturers need to participate in the same gateway redundancy group.
Question 8Scenario
A network administrator wants both routers in a redundancy pair to actively forward traffic simultaneously, rather than leaving one idle as a pure backup. Which protocol should be used?
GLBP is the only one of the three FHRPs that supports genuine active/active forwarding, distributing hosts across multiple Active Virtual Forwarders.
Question 9Scenario
Router A (priority 150) fails and Router B (priority 100) takes over as active. Router A later comes back online, but Router B remains active. What is the most likely explanation?
Without preemption enabled, a returning higher-priority router will not automatically reclaim the active role — the current active router keeps it until it fails again.
Question 10Scenario
A router's connection to its local subnet is healthy, but its uplink toward the rest of the network fails. Its FHRP priority automatically drops as a result, causing another router to take over as active. What feature caused this?
Object tracking automatically lowers a router's priority when a tracked interface (like an uplink) fails, preventing it from staying active despite having no usable path forward.
Question 11Scenario
During a router failover in an HSRP group, end-user hosts on the subnet experience no interruption and require no reconfiguration. Why?
Because hosts are configured with the virtual IP as their gateway, failover is transparent — the standby router simply takes over that same virtual IP and virtual MAC, and hosts never notice anything changed.
Question 12Exhibit
Based on this ARP entry for the default gateway, which FHRP is in use?
Host# arp -a Internet Address Physical Address Type 192.168.1.1 0000.0c07.ac0a dynamic
The MAC address 0000.0c07.ac0a matches HSRP's virtual MAC pattern (0000.0c07.acXX).
Question 13Exhibit
Based on this ARP entry, which FHRP is in use?
Host# arp -a Internet Address Physical Address Type 10.10.10.1 0000.5e00.0105 dynamic
The MAC address 0000.5e00.0105 matches VRRP's virtual MAC pattern (0000.5e00.01XX).
Question 14Exhibit
Based on this output, which router is currently forwarding traffic for this HSRP group?
R1# show standby brief Interface Grp Pri P State Active Standby Virtual IP Gi0/0 1 150 P Active local 10.0.0.2 192.168.1.1
The State column shows "Active" and the Active column shows "local," confirming R1 itself currently holds the active role and is forwarding traffic for virtual IP 192.168.1.1.
Question 15Exhibit
Based on this GLBP output showing two forwarders with different virtual MACs actively assigned to hosts, what does this confirm about the group's behavior?
R1# show glbp brief Interface Grp Fwd Pri State Address Active router Standby router Gi0/0 1 1 100 Active 0007.b400.0101 local 10.0.0.2 Gi0/0 1 2 100 Active 0007.b400.0102 10.0.0.2 local
Two forwarder entries, each "Active" with a distinct virtual MAC and each router acting as the other's standby for a different forwarder, is exactly GLBP's active/active load-balancing behavior.
Question 16Exhibit
What does this configuration line enable?
R1(config-if)# standby 1 preempt
The "preempt" keyword enables preemption for HSRP group 1 on this interface, allowing the router to reclaim the active role once it's back online with a higher priority.
Question 17Exhibit
Based on this configuration, what will happen to R1's HSRP priority if interface Gi0/1 goes down?
R1(config-if)# standby 1 priority 150 R1(config-if)# standby 1 track GigabitEthernet0/1 30
This is object tracking: the "track" command lowers priority by the specified decrement (30) if the tracked interface goes down, dropping R1 from 150 to 120 — potentially below another router's priority, triggering failover.
📝

Summary

An FHRP lets multiple physical routers share a single virtual IP (and virtual MAC), giving hosts an always-reachable default gateway even if one router fails.

HSRP (Cisco proprietary) uses active/standby roles; only one router forwards traffic at a time.

VRRP (open standard) is functionally similar to HSRP but uses master/backup terminology and can use a real interface IP as the virtual IP.

GLBP (Cisco proprietary) is the only true active/active FHRP, using an Active Virtual Gateway to distribute traffic across multiple Active Virtual Forwarders.

Priority determines which router wins the active role; preemption determines whether a returning higher-priority router reclaims that role automatically.

Object tracking can automatically lower a router's priority if a critical uplink fails, preventing a router with no real path forward from staying active on its local segment.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.