# Troubleshooting VRRP

**URL:** https://forum.networklessons.com/t/troubleshooting-vrrp/1197
**Category:** Lessons Discussion
**Created:** [December 27, 2016, 11:58pm UTC](https://forum.networklessons.com/t/troubleshooting-vrrp/1197 "2016-12-27T23:58:54Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![ReneMolenaar](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/renemolenaar/32/488_2.png) [@ReneMolenaar](https://forum.networklessons.com/u/ReneMolenaar)
#### Post date: [December 27, 2016, 11:58pm UTC](https://forum.networklessons.com/t/troubleshooting-vrrp/1197/1 "2016-12-27T23:58:54Z")

</div>

This topic is to discuss the following lesson:

> **[Troubleshooting VRRP](https://networklessons.com/ip-services/troubleshooting-vrrp)**
>
> This lesson explains Virtual Router Redundancy Protocol (VRRP) troubleshooting on Cisco IOS routers. VRRP lets you create a virtual gateway.

---

<div class="post-metadata">

### Author: ![javeedz](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/j/90ced4/32.png) [@javeedz](https://forum.networklessons.com/u/javeedz)
#### Post date: [February 22, 2016, 4:48pm UTC](https://forum.networklessons.com/t/troubleshooting-vrrp/1197/2 "2016-02-22T16:48:55Z")

</div>

Hello Rene,

One quick Question if there is any mismatch in the authentication .. in first place it should not forward packets at all ? we could see some packets are being forwarded .. could you please explain.

Thanks  
Shayan

---

<div class="post-metadata">

### Author: ![andrew](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/andrew/32/645_2.png) [@andrew](https://forum.networklessons.com/u/andrew)
#### Post date: [February 22, 2016, 9:32pm UTC](https://forum.networklessons.com/t/troubleshooting-vrrp/1197/3 "2016-02-22T21:32:40Z")

</div>

Hi Shayan,  
Believe it or not, what you are seeing is expected behavior from VRRP! If the authentication is not correct from a VRRP neighbor, then its packets get ignored. Each side will claim the other has incorrect authentication, so each VRRP router believes itself to be the master, and each will claim to own the IP address! The only upside to this is that assuming each side is using the same VRRP instance number, the MAC address will agree between them, so other computers on the network would have no idea this is going on. Additionally, should one of the VRRP mismatch routers fail, the VRRP IP will remain up–so you will achieve fault-tolerance by accident.

By the way, besides an authentication mismatch, the same thing will happen should the VRRP timers not match as well.

This goes to show you how useless authentication is with VRRP. The whole point of authentication is to stop a rogue device from claiming to be the virtual IP, but clearly it doesn’t matter.

Below is a sample VRRP output from two routers in this situation, notice how they disagree on the IP of the Master Router

```auto
R1#sh vrrp
FastEthernet0/0 - Group 1
  State is Master
  Virtual IP address is 10.0.0.254
  Virtual MAC address is 0000.5e00.0101
  Advertisement interval is 1.000 sec
  Preemption enabled
  Priority is 100
  Authentication MD5, key-string
  Master Router is 10.0.0.252 (local), priority is 100
  Master Advertisement interval is 1.000 sec
  Master Down interval is 3.609 sec

```

```auto
R2#sh vrrp
FastEthernet0/0 - Group 1
  State is Master
  Virtual IP address is 10.0.0.254
  Virtual MAC address is 0000.5e00.0101
  Advertisement interval is 1.000 sec
  Preemption enabled
  Priority is 100
  Master Router is 10.0.0.253 (local), priority is 100
  Master Advertisement interval is 1.000 sec
  Master Down interval is 3.609 sec

```

–Andrew

---

<div class="post-metadata">

### Author: ![javeedz](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/j/90ced4/32.png) [@javeedz](https://forum.networklessons.com/u/javeedz)
#### Post date: [March 1, 2016, 7:33am UTC](https://forum.networklessons.com/t/troubleshooting-vrrp/1197/4 "2016-03-01T07:33:59Z")

</div>

Hello Andrew,

Thanks a lot for your detailed explanation on the vrrp authentication.

Regards!  
Shayan

---

<div class="post-metadata">

### Author: ![Networkteam](https://cdn-forum.networklessons.com/letter_avatar_proxy/v4/letter/n/e47774/32.png) [@Networkteam](https://forum.networklessons.com/u/Networkteam)
#### Post date: [January 27, 2021, 5:32pm UTC](https://forum.networklessons.com/t/troubleshooting-vrrp/1197/5 "2021-01-27T17:32:23Z")

</div>

Let us assume authentication is proper & timers also. Suppose the VRRP keepalive messages are not able to reach each other due to any random reason, in that case both should be active & active.  
So will they forward packets or not?

---

<div class="post-metadata">

### Author: ![lagapidis](https://cdn-forum.networklessons.com/user_avatar/forum.networklessons.com/lagapidis/32/4949_2.png) [@lagapidis](https://forum.networklessons.com/u/lagapidis)
#### Post date: [January 30, 2021, 9:30am UTC](https://forum.networklessons.com/t/troubleshooting-vrrp/1197/6 "2021-01-30T09:30:03Z")

</div>

Hello Tejas

Yes, if that is the case, both devices will become active, and any packets arriving at a device will be forwarded. But, if for whatever reason the redundant gateways can’t reach each other, that means that hosts will also have trouble reaching one of the gateways for the same reason. Remember that redundant gateways and hosts are all on the same subnet. If communication between gateways somehow fails, then communication will also fail between hosts and one or more of the redundant gateways.

So in most cases, even if both gateways become active, the same network fault that caused the failure will also cause hosts not to reach one of the two or more gateways.

I hope this has been helpful!

Laz
