Summary

  • RGMP replaced multicast flooding toward router ports with explicit, refreshed per-group demand, but required exactly one enabled router directly attached to each enabled switch port.
  • Two routers on one port could black-hole traffic after one sent Leave. RFC 3488 preferred that visible low-traffic failure to flooding that looked healthy while erasing capacity protection.

IGMP snooping could answer a host question: which switch ports had listeners for a multicast group? It could not answer the router question. A router did not advertise through IGMP every flow it might need to route, so a switch usually flooded multicast toward router-facing ports. In a backbone full of routers, the switch delivered unwanted traffic and each router spent resources discarding it.

RFC 3488 documented Cisco's Router-port Group Management Protocol as a narrow remedy. Only routers originated RGMP messages; switches consumed them; routers ignored messages they received. A Hello changed the status of a port. A Join established interest in one group. Periodic Joins refreshed that interest. Leave removed it. Bye or expiry of five Hello intervals restored the port's previous forwarding behavior.

The state machine was simple because it relied on a physical invariant: one RGMP router, directly connected to one RGMP switch port. That statement was not installation advice around the protocol. It was part of the protocol's truth model. A switch could optionally remember the IPv4 sources of Hello and Bye messages and alert when more than one appeared, but it could not make two routers' independent intentions safe merely by accepting their packets.

Suppose two routers shared one physical port. Both wanted group G. One later sent Leave while the other still needed G. The switch stored state per port, not per router behind the port, so it could stop forwarding G to both. Users behind the remaining router observed intermittent black holing.

The RFC's reaction is striking. The black hole was easy for actual users to notice, and the failure produced less traffic rather than more. A switch could offer an operator button that disabled RGMP and returned the port to multicast flooding, but the document called that option potentially dangerous. Flooding would make everything appear to work while quietly discarding the traffic-constraining benefit.

That false recovery changed time as well as volume. The invalid topology occurred at installation or reconfiguration. Flooding could postpone visible harm until the port or routers became congested. When overload finally arrived, it might be separated from the original cause by days, traffic growth and other changes. Reachability during the interval was not proof that the configuration was sound.

The rest of the protocol shows why a single “joined” field is insufficient evidence. Some link-local and Cisco discovery groups always had to be forwarded. A router could emit a data-triggered Leave after receiving an unwanted group, but should rate-limit it. If a wanted and unwanted IPv4 group mapped to the same Ethernet destination MAC, the router might suppress that Leave and the switch might be unable to filter selectively.

Other Layer-2 mechanisms also complicated removal. If RGMP and IGMP snooping or another filter both operated, forwarding had to remain whenever either one required it. State could disappear only when none did. A captured Leave therefore did not prove that hardware stopped packets, and a continued packet stream did not by itself prove that RGMP ignored the Leave.

Inter-switch links were another boundary. RGMP deliberately did not define full restriction across them. Switches did not forward RGMP messages, so PIM Hello discovery or manual configuration could keep those links flooded. Routers without RGMP received all groups. An enabled edge port and a constrained whole LAN were different claims.

The simplicity also excluded routing cases. PIM Dense Mode and DVMRP required traffic that an explicit-Join model could withhold. A Bidir-PIM designated forwarder could not safely enable RGMP on that network. In PIM-SM, a designated router with directly attached sources needed unconditional reception to trigger registration; PIM-SSM behaved differently. Configuration had to follow protocol role, not merely feature availability.

Security inherited the one-system port assumption. Physical isolation was expected to prevent another system from forging state. A forged Hello could turn a non-RGMP router port into a restricting port. A forged Leave could black-hole selected groups. A forged Bye or Join could restore unwanted traffic and overload capacity provisioned on the assumption that suppression worked. Attacks could therefore drive the state machine toward too little traffic or too much.

The evidence chain begins before the control packet. Record the exact physical port and every system behind it. Preserve Hello and Bye source addresses, the five-interval timer, group address, Join refreshes and Leave sequence. Then join destination-MAC mapping, parallel filter state and actual switch forwarding entries. Only after packet counters, router discard load, port utilization and downstream receipt can an operator distinguish intentional suppression, accidental black holing and concealed flooding.

Heng Lu's reality-layer discipline explains why the RFC's harsh default had value. A visible failure forced the configured topology to confront the protocol's invariant. Flooding would have protected appearances while transferring the cost into bandwidth, router work and delayed diagnosis. RFC 3488 chose neither universal availability nor elegant abstraction. It chose a failure whose location could still be found.

Sources