Summary
- RFC 9568 uses address-owner configuration, priority, advertisements and derived expiry timers to select the Active Router for one virtual-router instance; that result is a narrow control-plane fact, not an authenticated claim of rightful control or a data-plane health certificate.
- A defensible failover receipt must join the election to virtual-MAC movement, ARP or Neighbor Discovery convergence, forwarding and adjacency state, upstream reachability, the independent IPv4 and IPv6 instances, and observed traffic recovery.
At 09:00:00, a backup stopped hearing advertisements. Roughly three advertisement intervals plus its priority-dependent skew later, it became Active. Its logs were clean. The former backup began transmitting VRRP advertisements with the expected VRID, priority and protected addresses. A dashboard turned green.
At 09:00:07, the customer circuit was still dark.
Nothing in that sequence contradicts RFC 9568. The standard solved the problem it was written to solve: choosing which participant should assume a virtual-router role on a LAN when the prior Active participant is no longer heard. It did not promise that every switch learned the virtual MAC, every host replaced a stale neighbor entry, every forwarding adjacency survived, every upstream route remained usable, or every stateful service followed the address. “Active” is a decision in a protocol state machine. Availability is a joined claim across several systems.
What the advertisement actually says
A VRRPv3 advertisement names one virtual-router instance. It carries a VRID, a priority, a maximum advertisement interval and the IPv4 or IPv6 addresses protected by that instance. IPv4 advertisements use link-local multicast 224.0.0.18; IPv6 advertisements use ff02::12. Both use protocol number 112, and both require a TTL or Hop Limit of 255. The checksum detects accidental corruption. These fields are precise because interoperable elections need precise inputs.
They are also bounded. The packet does not contain a forwarding-information-base digest, the status of an uplink, a neighbor-table receipt, a BFD result, an ACL decision, a NAT state count, a service-health verdict or an application measurement. The protocol knows which advertisements arrived. It does not observe the whole path that the newly Active router is expected to serve.
Priority expresses election preference, not measured capacity. The configured owner of the protected address uses 255. Backups use 1 through 254, with 100 as the default. Zero is a relinquishment signal. A higher number wins, and the IPvX source address breaks an equal-priority tie. None of those values is an external proof that the configuration is correct. RFC 9568 itself makes the security boundary sharper: version 3 includes no authentication. The 255-hop check constrains remote injection, but a hostile or misconfigured participant on the local link can still behave as Active.
A timer can identify silence without diagnosing it
The backup derives Skew_Time from its priority and the Active router’s advertised interval. It declares the Active router down after three advertised intervals plus that skew. The arithmetic makes takeover deterministic and gives a preferred backup a shorter wait. It does not say why the advertisements stopped.
The prior router may have lost power. The multicast may have been filtered. A switch may have partitioned the control packets while leaving some data traffic intact. The receiving process may have stalled while the forwarding ASIC continued working. The local interface may be alive while the upstream path failed. Conversely, the backup may hear advertisements from an Active router whose data plane is already unusable. Silence and continued speech are both observations of the VRRP channel, not diagnoses of every dependency behind it.
This is why a faster timer is not the same as a shorter outage. Sub-second advertisements can reduce the interval before role change. They cannot force a switch to relearn immediately, make hosts accept an unsolicited Neighbor Advertisement, repair a missing route or reconstruct state that lives outside the virtual-router instance. RFC 9568 even warns that a slow high-priority Active router can interact badly with faster backups, creating a temporary competing Active state. The timer is an instrument; its setting changes both convergence and instability risk.
The virtual MAC is a handover, not a completed journey
On transition, the new Active router uses the virtual MAC and announces the protected address. IPv4 relies on ARP behaviour; IPv6 relies on Neighbor Discovery and unsolicited Neighbor Advertisements. This is the point at which a control-role decision must become a link-layer reality.
That join can fail partially. A switch may retain the old port for the virtual MAC. One host may accept the announcement while another keeps a stale cache. Security controls may filter unsolicited updates. RFC 9131 notes that extra configuration can be necessary before unsolicited Neighbor Advertisements update caches. A packet capture showing that the new Active router emitted the correct announcement proves emission, not universal uptake.
The apparent health check can mislead in both directions. Accept_Mode defaults to false, so a non-owner Active router need not accept ordinary packets addressed to the protected address as its own, even though it can forward transit traffic using that address as the first hop. A failed ping can coexist with working forwarding. A successful ping can establish local control-plane reachability while the uplink, policy path or destination remains broken. The probe must match the claim.
IPv4 and IPv6 do not inherit each other’s answer
RFC 9568 treats the IPv4 and IPv6 virtual routers as independent instances. They may share a chassis, an operator and a name, but they do not share an election by implication. An IPv4 Active transition does not prove an IPv6 transition happened, and a working IPv6 neighbor cache says nothing about an IPv4 ARP cache.
The separation matters when dashboards flatten “gateway redundancy” into one icon. A dual-stack service can recover in one family and remain unreachable in the other. Router Advertisements add another boundary: options advertising special services should not move to a backup unless that backup can assume the service fully with synchronized state. A role that can advertise a prefix is not necessarily a role ready to deliver every service previously attached to it.
The minimum operating receipt
An operator should be able to reconstruct the failover as a chain, not as a single green state:
- identify the exact VRID, address family and protected addresses;
- record configured ownership, priority, interval, preemption and accept mode;
- show the last valid advertisement and the calculated expiry that triggered the transition;
- show which router became Active and why it won any tie;
- verify the virtual MAC and ARP or Neighbor Discovery state at relevant switches and hosts;
- verify interface, adjacency, forwarding, policy and any stateful-service prerequisites on the new router;
- test the relevant upstream and downstream path independently of the protected address itself; and
- measure packet loss, convergence time and application recovery for IPv4 and IPv6 separately.
BFD can contribute a stronger liveness signal where it is deliberately integrated, but it is not retroactively embedded in the word Active. Management telemetry can expose state and counters, but a modelled state is still one receipt surface. The decisive evidence joins protocol state to running traffic.
RFC 9568 is valuable precisely because its claim is narrow. It creates a disciplined local election that end hosts need not participate in. Operational error begins when the label produced by that election is promoted into a verdict about systems the election never measured.
Sources
- https://www.rfc-editor.org/rfc/rfc9568.html
- https://www.rfc-editor.org/info/rfc9568
- https://datatracker.ietf.org/doc/rfc9568/
- https://datatracker.ietf.org/doc/rfc9568/history/
- https://www.rfc-editor.org/errata/rfc9568
- https://www.rfc-editor.org/rfc/rfc5798.html
- https://www.rfc-editor.org/rfc/rfc8347.html
- https://www.rfc-editor.org/rfc/rfc5082.html
- https://www.rfc-editor.org/rfc/rfc4861.html
- https://www.rfc-editor.org/rfc/rfc9131.html
- https://www.rfc-editor.org/rfc/rfc9099.html
- https://www.rfc-editor.org/rfc/rfc5880.html
- https://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml
- https://www.iana.org/assignments/multicast-addresses/multicast-addresses.xhtml
- https://www.iana.org/assignments/ethernet-numbers/ethernet-numbers.xhtml
- https://heng.lu/on-reality-layers-symbolic-power-and-why-clarity-feels-so-hostile/
- https://heng.lu/running-code-primary-the-patch-needed-to-preserve-the-internet-original-design/
- https://heng.lu/on-why-btw-media-exists-and-why-reality-not-advocacy-is-the-product/
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

