Domain 2.0 | Network Implementation — 20% of exam
Learning Objectives
By the end of this lesson, you will be able to:
- Explain the purpose of a First Hop Redundancy Protocol (FHRP) and why default gateway redundancy matters
- Describe how a virtual IP (VIP) and virtual MAC address let multiple physical routers act as one default gateway
- Compare the core characteristics of HSRP, VRRP, and GLBP
- Distinguish active/standby operation from GLBP’s active/active load-balancing approach
- Explain priority, preemption, and object tracking in FHRP failover behavior
Key Terms
| Term | Definition |
|---|---|
| FHRP (First Hop Redundancy Protocol) | A protocol that lets multiple physical routers share a single virtual IP address, so hosts always have a reachable default gateway even if one router fails |
| Virtual IP (VIP) | The shared IP address configured as the default gateway on end hosts, mapped to whichever physical router is currently active |
| HSRP (Hot Standby Router Protocol) | Cisco’s proprietary FHRP, using active/standby roles |
| VRRP (Virtual Router Redundancy Protocol) | The open-standard FHRP equivalent to HSRP, using master/backup roles |
| GLBP (Gateway Load Balancing Protocol) | Cisco’s FHRP that allows multiple routers to actively forward traffic simultaneously, rather than sitting idle in standby |
| Preemption | The behavior where a higher-priority router reclaims the active role once it comes back online, rather than leaving a lower-priority router in charge |
Explanation
Why a Default Gateway Is a Single Point of Failure
Every host on a subnet is configured with exactly one default gateway address — the router it sends traffic to whenever the destination isn’t on the local network. That’s a problem: if that one router goes down, every host on the subnet loses its path out, even if a second, perfectly healthy router sits right next to it on the same segment. Manually reconfiguring hundreds of hosts with a new gateway address during an outage isn’t realistic, and hosts don’t dynamically discover a replacement gateway on their own.
This is exactly the kind of redundancy gap that the traditional topologies lesson touched on conceptually — having two routers physically present on a segment does nothing for reliability if hosts only know how to talk to one of them.
What an FHRP Actually Does: Virtual IP and Virtual MAC
A First Hop Redundancy Protocol (FHRP) solves this by having two or more physical routers share one virtual IP address (VIP). Hosts on the subnet are configured with the virtual IP as their default gateway — never a real router’s actual address. Behind the scenes, the FHRP also assigns a shared virtual MAC address, so that at Layer 2, ARP requests for the gateway’s IP always resolve to the same virtual MAC no matter which physical router is currently doing the forwarding.

How Multiple Physical Routers Share One Virtual IP And Virtual MAC As A Single Default Gateway
At any given moment, one physical router is actually forwarding traffic sent to the virtual IP. If that router fails, another router in the group takes over the virtual IP and virtual MAC almost immediately — and because the hosts never had to change anything (they were always pointed at the virtual address), the failover is completely transparent to every device on the subnet.
HSRP: Cisco’s Original Standard
HSRP (Hot Standby Router Protocol) is Cisco’s original, proprietary FHRP, and it’s still extremely common in Cisco-only environments. HSRP uses an active/standby model: exactly one router in the group is active and forwarding traffic at any time, while the other routers sit in standby, ready to take over.
Key HSRP characteristics:
- Priority determines which router becomes active — higher priority wins (default priority is 100).
- Virtual MAC address follows the pattern
0000.0c07.acXX, where XX is the HSRP group number in hexadecimal. - Hello and hold timers control how often routers announce themselves and how long a standby router waits before assuming the active router has failed.
- Only one router is ever actively forwarding traffic per group — the rest are idle from a forwarding perspective, even though they’re healthy.
VRRP: The Open Standard Equivalent
VRRP (Virtual Router Redundancy Protocol) does essentially the same job as HSRP but as an open, vendor-neutral standard, making it common in multi-vendor environments where not every device is Cisco.
Key differences from HSRP, mostly in terminology:
- VRRP calls its active router the master and the others backup, instead of active/standby.
- VRRP’s virtual MAC address pattern is
0000.5e00.01XX. - One functional difference worth remembering: VRRP can use a router’s own real interface IP as the virtual IP, whereas HSRP always requires a distinct virtual IP.
Functionally, though, VRRP behaves almost identically to HSRP — same single-active-router model, same idea of priority determining who’s in charge.
GLBP: Adding Load Balancing
GLBP (Gateway Load Balancing Protocol), also Cisco-proprietary, takes a different approach. Instead of leaving all but one router idle, GLBP lets multiple routers actively forward traffic at the same time — true active/active operation.
GLBP does this with two roles:
- The Active Virtual Gateway (AVG) is elected to handle ARP requests for the virtual IP, but instead of always replying with the same virtual MAC, it hands out different virtual MAC addresses to different hosts, spreading them across multiple Active Virtual Forwarders (AVFs).
- Each AVF is a physical router actually forwarding traffic for the subset of hosts it was assigned, meaning the traffic load gets distributed across all group members instead of concentrating on a single active router.

How HSRP, VRRP, and GLBP Differ In Roles, Virtual MAC Format, And Active Router Count
| HSRP | VRRP | GLBP | |
|---|---|---|---|
| Vendor | Cisco proprietary | Open standard | Cisco proprietary |
| Roles | Active / Standby | Master / Backup | AVG / AVF (multiple) |
| Forwarding model | Active/standby (one forwards) | Active/standby (one forwards) | Active/active (multiple forward) |
| Virtual MAC pattern | 0000.0c07.acXX | 0000.5e00.01XX | Multiple virtual MACs per group |
| Can use a real interface IP as the VIP? | No | Yes | No |
Priority, Preemption, and Object Tracking
Which router becomes active isn’t left to chance — it’s determined by a configurable priority value, and the router with the highest priority in the group wins the active/master role during a normal election.
Preemption controls what happens when a higher-priority router that was previously down comes back online. With preemption enabled, that router immediately reclaims the active role from whatever lower-priority router had taken over in its absence. Without preemption enabled, the current active router — even if it has a lower priority — simply stays active until it fails again, which can leave a network quietly running on its “backup” path indefinitely without anyone noticing.

How Priority And Preemption Determine Which Router Becomes And Stays Active
Many real deployments also use object tracking, where a router’s priority is automatically lowered if a tracked interface (often the uplink toward the internet or the rest of the network) goes down — even if the router’s connection to the local subnet is still perfectly healthy. This prevents a scenario where a router keeps winning the active election on its local segment while having no usable path to anywhere else.
Where FHRP Fits in the Bigger Picture
FHRP virtual IPs are almost always the address configured as the default gateway on end-user subnets, sitting in front of whatever routing and address translation work is happening further out. A pair of distribution-layer routers might run HSRP or VRRP between themselves, present a single virtual IP to hosts on the subnet, and each independently run dynamic routing protocols and NAT/PAT translation toward the rest of the network and the internet. FHRP solves exactly one problem — gateway reachability — and it’s designed to sit cleanly alongside everything else these routers are doing.
Recognition-Level Verification Concepts
A few patterns are worth recognizing on sight:
- A gateway MAC address beginning with
0000.0c07.acpoints to HSRP; one beginning with0000.5e00.01points to VRRP. - Only one router responding to ARP for the gateway IP with a single, unchanging virtual MAC — while other group members stay idle — describes active/standby operation (HSRP or VRRP).
- Multiple routers simultaneously forwarding traffic for the same virtual IP, using different virtual MACs handed out to different hosts, is the signature of GLBP’s active/active model.
- A router with a healthy local subnet connection but a failed uplink, whose priority has automatically dropped, points to object tracking in action.
Common Exam Traps
- HSRP and VRRP are functionally similar but not identical. VRRP can use a real interface address as the virtual IP; HSRP cannot. Don’t assume the two are perfectly interchangeable.
- GLBP is the only one of the three that’s genuinely active/active. HSRP and VRRP both concentrate all forwarding on a single active/master router — don’t describe either of them as load-balancing traffic.
- Priority determines the election, but preemption determines what happens afterward. A high-priority router that comes back online will not automatically reclaim the active role unless preemption is explicitly enabled.
- FHRP is not a routing protocol and has no administrative distance. It solves the “what’s my gateway” problem at the edge of a subnet, not the “how do I reach a distant network” problem that OSPF, EIGRP, and BGP solve.
- The virtual MAC address patterns are frequently tested exhibit material — recognize
0000.0c07.acas HSRP and0000.5e00.01as VRRP on sight.
Lesson 2.1.4 Practice Quiz — FHRP and Virtual IPs for Gateway Redundancy
17 questions covering HSRP, VRRP, GLBP, virtual IPs and MACs, priority, preemption, and object tracking.
N10-009 · Domain 2.1Summary
An FHRP lets multiple physical routers share a single virtual IP (and virtual MAC), giving hosts an always-reachable default gateway even if one router fails.
HSRP (Cisco proprietary) uses active/standby roles; only one router forwards traffic at a time.
VRRP (open standard) is functionally similar to HSRP but uses master/backup terminology and can use a real interface IP as the virtual IP.
GLBP (Cisco proprietary) is the only true active/active FHRP, using an Active Virtual Gateway to distribute traffic across multiple Active Virtual Forwarders.
Priority determines which router wins the active role; preemption determines whether a returning higher-priority router reclaims that role automatically.
Object tracking can automatically lower a router's priority if a critical uplink fails, preventing a router with no real path forward from staying active on its local segment.



