miércoles, 12 de agosto de 2009

CCNP3 Module 7: Configuring Campus Switches to Support Voice Parte2

7.2 Accommodating Voice Traffic on Campus Switches


7.2.1 QoS and Voice Traffic in the Campus Module

Regardless of the speed of individual switches or links, speed mismatches, many-to-one switching fabrics, and aggregation can cause congestion and latency. If congestion management features are not in place, some packets will be dropped, causing retransmissions that inevitably increase network load even more. QoS can mitigate latency caused by congestion on campus devices.

QoS classifies and marks traffic at one device. Other devices can then prioritize or queue the traffic according to the marks applied to individual frames or packets.

Figure describes how QoS is applied in the campus network.



7.2.2 LAN-Based Classification and Marking



Classification and marking identifies traffic for proper prioritization as the traffic traverses the network. Traffic is classified by examining information at different layers of the Open Systems Interconnection (OSI) model. The classified traffic receives a mark or QoS value. IP traffic can be classified according to any values configurable in an access control list (ACL) or any of the following criteria :

  • Layer 2 parameters: MAC address, Multiprotocol Label Switching (MPLS), ATM cell loss priority (CLP) bit, Frame Relay discard eligible (DE) bit, or ingress interface

  • Layer 3 parameters: IP precedence, differentiated services code point (DSCP), QoS group, IP address, or ingress interface

  • Layer 4 parameters: TCP or UDP ports, or ingress interface

  • Layer 7 parameters: Application signatures or ingress interface

All traffic classified or grouped according to these criteria will be marked according to that classification. QoS marks establish priority levels or priority classes of service for network traffic as it is processed by each switch. Once traffic is marked with a QoS value, QoS policies on switches and interfaces handle traffic according to the values contained in the individual frames and packets. As a result of classification and marking, traffic is prioritized accordingly at each switch to ensure that delay-sensitive traffic receives priority processing as the switch manages congestion, delay, and bandwidth allocation.

QoS Layer 2 classification examines information in the Ethernet or 802.1Q header, such as the destination MAC address or VLAN ID. QoS Layer 2 marking occurs in the Priority field of the 802.1Q header. LAN Layer 2 headers have no means of carrying a QoS value, so 802.1Q encapsulation is required if Layer 2 QoS marking is to occur. The Priority field is 3 bits long and is also known as the 802.1p User Priority or Class of Service (CoS) value.

This 3-bit field supports CoS values from 1 to 7, with 1 being associated with delay tolerant traffic such as TCP/IP. Voice traffic, which by nature is not delay tolerant, receives higher default CoS values. A CoS value of 5 is given to Voice Bearer traffic, which is the phone conversation itself, so voice quality is impaired if packets are dropped or delayed. Call signaling to create, maintain, and tear down a voice call receives a CoS of 3.

As a result of Layer 2 classification and marking, the following QoS operations can occur:

  • Input queue scheduling: When a frame enters a port, it can be assigned to a port-based queue prior to being scheduled for switching to an egress port. Typically, multiple queues are used where traffic requires different service levels.

  • Policing: Frames are inspected to see if a predefined rate of traffic within a certain timeframe has been exceeded. The timeframe is typically a fixed number internal to the switch. If a frame has exceeded the rate limit, it can either be dropped or the CoS value can be marked down.

  • Output queue scheduling: The switch places the frame into an appropriate outbound (egress) queue for switching. The switch ensures that the buffer does not overflow on the queue.

QoS Layer 3 classification examines header values, such as the destination IP address or protocol. QoS Layer 3 marking occurs in the Type of Service (ToS) byte in the IP header. The first three bits of the ToS byte are occupied by IP Precedence, which correlates to the three CoS bits carried in the Layer 2 header.

The ToS byte can also be used for DSCP marking. DSCP allows prioritization hop by hop as packets are processed on each switch and interface. Figure shows how DSCP uses ToS bits. The first three DSCP bits, correlating to Precedence and CoS, identify the DSCP CoS for the packet.

The next three DSCP bits establish a drop precedence for the packet. Packets with a high DSCP drop precedence value are dropped before those with a low value if a device or queue becomes overloaded. Voice traffic is marked with a low value to minimize voice packet drop.

Each 6-bit DSCP value is also given a DSCP name. DSCP classes 1-4 are Assured Forwarding (AF) classes. If the DSCP class value is 3 and the drop precedence is 1, the DSCP would be AF31.



7.2.3 Describing QoS Trust Boundaries



Trust boundaries establish a border for traffic entering the campus network. As traffic traverses the switches of the campus network, it is handled and prioritized according to the marks received or trusted when the traffic originally entered the network at the trust boundary.

At the trust boundary device, QoS values are trusted if they accurately represent the type of traffic and precedence processing the traffic should receive as it enters the campus network. If untrusted, the traffic is marked with a new QoS value appropriate for the policy in place at the point where the traffic entered the campus network. Ideally, the trust boundary exists at the first switch receiving traffic from a device or IP phone. It is also acceptable to establish the trust boundary where all the traffic from an access switch enters a Building Distribution layer port.

Note:
Best practices suggest classifying and marking traffic as close to the traffic source as possible.


7.2.4 Configuring a Switch for the Attachment of a Cisco Phone



Figure illustrates a typical switch-phone-PC topology. Several commands are used to configure and verify basic features for managing voice traffic on Cisco Catalyst switch ports. Figure provides descriptions for the commands used to manage voice traffic.



7.2.5 Basic Switch Commands to Support Attachment of a Cisco IP Phone



Several commands are used to configure and verify the basic required functions on a switch port connected to an IP phone with a PC connected to that phone. An example configuration is illustrated in Figure .



7.2.6 What is AutoQoS VoIP?



AutoQoS gives customers the ability to deploy QoS features for converged IP telephony and data networks much faster and more efficiently. AutoQoS simplifies and automates the Modular QoS CLI (MQC) definition of traffic classes and the creation and configuration of traffic policies. AutoQoS generates traffic classes and policy map CLI templates. When AutoQoS is configured at the interface, the traffic receives the required QoS treatment automatically. In-depth knowledge of the underlying technologies, service policies, link efficiency mechanisms, and Cisco QoS best practice recommendations for voice requirements is not required to configure AutoQoS.

AutoQoS can be extremely beneficial for the following scenarios:

  • Small- to medium-sized businesses that must deploy IP telephony quickly but lack the experience and staffing to plan and deploy IP QoS services

  • Large customer enterprises that need to deploy Cisco telephony solutions on a large scale, while reducing the costs, complexity, and timeframe for deployment, and ensuring that the appropriate QoS for voice applications is being set in a consistent fashion

  • International enterprises or service providers requiring QoS for VoIP where little expertise exists in different regions of the world and where provisioning QoS remotely and across different time zones is difficult

  • Service providers requiring a template-driven approach to delivering managed services and QoS for voice traffic to large numbers of customer premise devices

Cisco AutoQoS simplifies and shortens the QoS deployment cycle. AutoQoS helps in all five major aspects of successful QoS deployments :

  • Application classification: AutoQoS leverages intelligent classification on routers using Cisco network-based application recognition (NBAR) to provide stateful packet inspection. AutoQoS relies on CDP to ensure that the device attached to the LAN is really a Cisco IP phone. Once an IP phone is identified, the voice traffic is automatically classified and QoS policies are applied.

  • Policy generation: AutoQoS evaluates the network environment and generates an initial policy. It automatically generates interface configurations, policy maps, class maps, and ACLs. AutoQoS VoIP automatically employs Cisco NBAR to classify voice traffic, and mark the traffic with the appropriate DSCP value. It can be instructed to rely on, or trust, the DSCP markings previously applied to the packets.

  • Configuration: With one command, AutoQoS configures the port to prioritize voice traffic without affecting other network traffic, while still offering the flexibility to adjust QoS settings for unique network requirements. It also disables QoS settings when a Cisco IP Phone is relocated or moved to prevent malicious activity.

  • Monitoring and reporting: AutoQoS provides visibility into the classes of service deployed via system logging and Simple Network Management Protocol (SNMP) traps, with notification of abnormal events (that is, VoIP packet drops).

  • Consistency: Deployed QoS configurations are consistent among router and switch platforms, ensuring seamless QoS operation and interoperability within the network.



7.2.7 Configuring AutoQoS VoIP on a Cisco Catalyst Switch



When the AutoQoS feature is enabled on the first interface, QoS is globally enabled (mls qos global configuration command).

When the auto qos voip trust interface configuration command is entered, the ingress classification on the interface is set to trust the CoS QoS label received in the packet, and the egress queues on the interface are reconfigured. QoS labels in ingress packets are trusted.

When the auto qos voip cisco-phone interface configuration command is entered, the trusted boundary feature is enabled. The trusted boundary feature uses CDP to detect the presence or absence of a Cisco IP Phone. When a Cisco IP Phone is detected, the ingress classification on the interface is set to trust the QoS label received in the packet. When a Cisco IP Phone is absent, the ingress classification is set to not trust the QoS label in the packet. The egress queues on the interface are also reconfigured. This command extends the trust boundary if an IP Phone is detected.

To display the initial AutoQoS configuration, use the show auto qos [interface [interface-id]] privileged EXEC command. To display any user changes to that configuration, use the show running-config privileged EXEC command. You can compare the output of the show auto qos and show running-config commands to identify the user-defined QoS settings.

AutoQoS performs the following functions in a LAN :

  • Enforces the trust boundary on Cisco Catalyst switch access ports, and uplinks and downlinks

  • Enables Cisco Catalyst strict priority queuing (also known as expedited queuing) with weighted round robin (WRR) scheduling for voice and data traffic, where appropriate

  • Configures queue admission criteria (maps CoS values in incoming packets to the appropriate queues)

  • Modifies queue sizes and weights where required


7.3 Voice Support Lab Exercises



7.3.1 Lab 7-1 Configuring Switches for IP Telephony Support Lab Activity



Lab Exercise: Lab 7-1 Configuring Switches for IP Telephony Support

  • Configure auto QoS to support IP phones

  • Configure CoS override for data frames

  • Configure the distribution layer to trust access layer QoS measures

  • Manually configure CoS for devices that cannot specify CoS (camera)

  • Configure HSRP for voice and data VLANS to ensure redundancy

  • Configure 802.1Q trunks and EtherChannels for Layer 2 redundancy and load balancing


Summary

When you are implementing a VoIP network, you must address quality of service (QoS), power, and capacity planning considerations. One of the easiest ways to deal with QoS is to implement the AutoQoS features. In addition, using auxiliary VLANs and inline power eases the implementation of the VoIP network. This module highlighted the issues related to implementing a VoIP network, and the initial steps to take to ensure that the VoIP network works correctly.



CCNP3 Module 7: Configuring Campus Switches to Support Voice

Module Overview


When migrating to a Voice over IP (VoIP) network, all network requirements, including power and capacity planning, must be examined. In addition, congestion avoidance techniques should be implemented. This module highlights the basic issues and defines the initial steps to take to ensure a functional VoIP implementation.


7.1 Planning for Implementation of Voice in a Campus


7.1.1 Converged Network Benefits

The benefits of packet telephony versus circuit-switched telephony are as follows:

  • More efficient use of bandwidth and equipment: Traditional telephony networks use a 64-kbps channel for every voice call. Packet telephony shares bandwidth among multiple logical connections and offloads traffic volume from existing voice switches.

  • Lower costs for telephony network transmission: A substantial amount of equipment is needed to combine 64-kbps channels into high-speed links for transport across the network. Packet telephony statistically multiplexes voice traffic alongside data traffic. This consolidation represents substantial savings on capital equipment and operations costs.

  • Consolidated voice and data network expenses: Data networks that function as separate networks to voice networks become major traffic carriers. The underlying voice networks are converted to utilize the packet-switched architecture to create a single integrated communications network with a common switching and transmission system. The benefit is significant cost savings on network equipment and operations.

  • Increased revenues from new services: Packet telephony enables new integrated services, such as broadcast-quality audio, unified messaging, and real-time voice and data collaboration. These services increase employee productivity and profit margins well above those of basic voice services. In addition, these services enable companies and service providers to differentiate themselves and improve their market position.

  • Greater innovation in services: Unified communications use the IP infrastructure to consolidate communication methods that were previously independent; for example, fax, voice mail, e-mail, wireline telephones, cellular telephones, and the Web. The IP infrastructure provides users with a common method to access messages and initiate real-time communications—independent of time, location, or device.

  • Access to new communications devices: Packet technology can reach devices that are largely inaccessible to the time-division multiplexing (TDM) infrastructures of today. Examples of such devices are computers, wireless devices, household appliances, personal digital assistants, and cable set-top boxes. Intelligent access to such devices enables companies and service providers to increase the volume of communications they deliver, the breadth of services they offer, and the number of subscribers they serve. Packet technology, therefore, enables companies to market new devices, including videophones, multimedia terminals, and advanced IP phones.

  • Flexible new pricing structures: Companies and service providers with packet-switched networks can transform their service and pricing models. Because network bandwidth can be dynamically allocated, network usage no longer needs to be measured in minutes or distance. Dynamic allocation gives service providers the flexibility to meet the needs of their customers in ways that bring them the greatest benefits.

7.1.2 VoIP Network Components

The basic components of a VoIP network are:

  • IP phones: Provide IP voice to the desktop.

  • Gatekeeper: Provides connection admission control (CAC), bandwidth control and management, and address translation.

  • Gateway: Provides translation between VoIP and non-VoIP networks, such as the public switched telephone network (PSTN). It also provides physical access for local analog and digital voice devices, such as telephones, fax machines, key sets, and PBXs.

  • Multipoint control unit (MCU): Provides real-time connectivity for participants in multiple locations to attend the same videoconference or meeting.

  • Call agent: Provides call control for IP phones, CAC, bandwidth control and management, and address translation.

  • Application servers: Provide services such as voice mail, unified messaging, and Cisco CallManager Attendant Console.

  • Videoconference station: Provides access for end-user participation in videoconferencing. The videoconference station contains a video capture device for video input and a microphone for audio input. The user can view video streams and hear the audio that originates at a remote user station.

Other components, such as software voice applications, interactive voice response (IVR) systems, and soft phones, provide additional services to meet the needs of enterprise sites.



7.1.3 Traffic Characteristics of Voice and Data



Voice traffic has extremely stringent quality of service (QoS) requirements. Voice traffic usually generates a smooth demand on bandwidth and has minimal impact on other traffic as long as voice traffic is managed.

Although voice packets are typically small (60 to 120 bytes), they cannot tolerate delay or drops. The result of delays and drops is often unacceptable voice quality. Because drops cannot be tolerated, User Datagram Protocol (UDP) is used to package voice packets. TCP retransmit capabilities have no value.

For voice quality, the delay should be no more than 150 ms (one-way requirement) and less than 1 percent packet loss.

A typical voice call requires 17 to 106 kbps of guaranteed priority bandwidth, plus an additional 150 bps per call for voice-control traffic. Multiplying these bandwidth requirements by the maximum number of calls expected during the busiest time period indicates the overall bandwidth required for voice traffic.

The QoS requirements for data traffic vary greatly.

Different applications (for example, a human resources application versus an automated teller machine [ATM] application) may make greatly different demands on the network. Even different versions of the same application may have varying network traffic characteristics.

Data traffic can demonstrate either smooth or bursty characteristics, and it differs from voice and video in terms of delay and drop sensitivity. Almost all data applications can tolerate some delay and generally can tolerate high drop rates.

Because data traffic can tolerate drops, the retransmit capabilities of TCP become important and, as a result, many data applications use TCP.

It is important to be able to identify different types of traffic that move over networks. With TCP/IP, most applications can be identified by their use of TCP or UDP port numbers, and with TCP, a stream of traffic usually occurs.

However, some applications use dynamic port numbers that make classifications more difficult. Cisco IOS software supports network-based application recognition (NBAR), which can be used to recognize dynamic port applications.



7.1.4 VoIP Call Flow

VoIP calls can contend with normal client data for bandwidth. If both the client PC and the VoIP phone are on the same VLAN, each will try to use the available bandwidth without consideration of the other device. To avoid this issue, use two VLANs to allow separation of VoIP and client data. After data is separated, QoS can be applied to prioritize the VoIP traffic as it traverses the network.

A major component of designing a successful IP telephony network is properly provisioning the network bandwidth. You can calculate the required bandwidth by adding the bandwidth requirements for each major application, including voice, video, and data. This sum represents the minimum bandwidth requirement for any given link, and it should not exceed approximately 75 percent of the total available bandwidth for the link.

From a traffic standpoint, an IP telephony call consists of two traffic types, as illustrated in Figure using a Cisco CallManager:

  • Voice carrier stream: Real-Time Transport Protocol (RTP) packets that contain the actual voice samples.

  • Call control signaling: Packets belonging to one of several protocols—those used to set up, maintain, tear down, or redirect a call, depending upon call endpoints. Examples are H.323 or Media Gateway Control Protocol (MGCP).

A VoIP packet consists of the voice payload, RTP header, UDP header, IP header, and Layer 2 encapsulation. The IP header is 20 bytes, the UDP header is 8 bytes, and the RTP header is 12 bytes. The link layer overhead varies in size according to the Layer 2 media used; Ethernet requires 18 bytes of overhead. The voice payload size and the packetization period are device dependent.

Coder-Decoders (codecs) convert the analog voice to a digital signal format. This technology has been used for years to convert a telephone signal into a 64,000 bps digital signal (DS0) for use on TDM-based systems. Today, an IP phone uses a G.711 codec for normal voice digitization. G.711 is the only type supported for the Cisco Conference Connection and Personal Assistant applications. G.729 is another supported codec that provides compression of the voice traffic down to 8 kbps. Cisco VoIP equipment supports G.711 and G.729, along with several other common industry standards.



7.1.5 Auxiliary VLANs

Some Cisco Catalyst switches offer a unique feature called an “auxiliary VLAN” or a “voice VLAN.” Auxiliary VLANs allow you to overlay a voice topology onto a data network. You can segment phones into separate logical networks, even though the data and voice infrastructure are physically the same.

Auxiliary VLANs place the phones into their own VLANs without any end-user intervention. Furthermore, these VLAN assignments can be seamlessly maintained, even if the phone is moved to a new location. The user simply plugs the phone into the switch, and the switch provides the phone with the necessary VLAN information. By placing phones into their own VLANs, network administrators gain the advantages of network segmentation and control. Furthermore, network administrators can preserve their existing IP topology for the data end stations. IP phones can be easily assigned to different IP subnets using standards-based DHCP operation.

With the phones in their own IP subnets and VLANs, network administrators can more easily identify and troubleshoot network problems. Additionally, network administrators can create and enforce QoS or security policies. Auxiliary VLANs enable Cisco network administrators to gain all the advantages of physical infrastructure convergence while maintaining separate logical topologies for voice and data terminals. This creates the most effective way to manage a multiservice network.



7.1.6 QoS



Almost any network can take advantage of QoS for optimum efficiency, whether it is a small corporate network, an Internet service provider (ISP), or an enterprise network. QoS utilizes features and functionality to meet the networking requirements of applications sensitive to loss, delay, and delay variation (jitter). QoS allows preference to be given to critical application flows for the available bandwidth.

The Cisco IOS implementation of QoS software provides these benefits:

  • Priority access to resources: Administrators can control which traffic is allowed to access specific network resources, such as bandwidth, equipment, and WAN links. Critical traffic can take possession of a resource because the QoS implementation drops low-priority frames.

  • Efficient management of network resources: If network management and accounting tools indicate that specific traffic is experiencing latency, jitter, or packet loss, you can use QoS tools to adjust how that traffic is handled.

  • Tailored services: ISPs can offer carefully tailored grades of service to their customers. For example, an ISP can offer one service level agreement (SLA) to a customer website that receives 3,000 to 4,000 hits per day and another to a site that receives only 200 to 300 hits per day.

  • Coexistence of mission-critical applications: Mission-critical business applications receive priority access to network resources while providing adequate processing for applications that are not delay sensitive. Multimedia and voice applications tolerate little latency and require priority access to resources. Other delay-tolerant traffic traversing the same link, such as Simple Mail Transfer Protocol (SMTP) over TCP, can still be adequately serviced.



7.1.7 Importance of High Availability for VoIP



The traditional telephony network strives to provide 99.999 percent uptime to the user. This corresponds to 5.25 minutes per year of downtime. Many data networks cannot make the same claim. To provide telephony users the same, or close to the same, level of service as they experience with traditional telephony, the reliability and availability of the data network takes on new importance.


Reliability is a measure of how resilient a network can be. Efforts to ensure reliability include choosing hardware and software with a low mean time between failure, or installing redundant hardware and links. Availability is a measure of how accessible the network is to the users. When a user wants to make a call, for example, the network should be accessible to that user. Efforts to ensure availability include installing proactive network management to predict failures before they happen, and taking steps to correct problems in the design of the network as it grows.

When the data network goes down, it may not come back up for minutes or even hours. This delay is unacceptable for telephony users. Local users with network equipment, such as voice-enabled routers, gateways, or switches for IP phones, now find that their connectivity is terminated. Administrators must provide an uninterruptible power supply (UPS) to these devices in addition to providing network availability. Previously, users received their power directly from the telephone company central office or through a UPS that was connected to a keyswitch or PBX in the event of a power outage. Today, the network devices must continue to function, provide service to the end devices, and possibly (as with Power over Ethernet [PoE]) supply power to end devices.

Note:
Cisco has the option of using DC power with many of its routers, which allows power to be distributed from a “battery bank” that is continuously being charged. When a power outage occurs, the batteries supply DC to the equipment. Battery banks are very common in the telephone industry.

Network reliability comes from incorporating redundancy into the network design. In traditional telephony, switches have multiple redundant connections to other switches. If either a link or a switch becomes unavailable, the telephone company can easily re-route calls. This is why telephone companies can claim a high availability rate.

High availability encompasses many areas of the network. In a fully redundant network, the following components need to be duplicated:

  • Servers and call managers

  • Access layer devices, such as LAN switches

  • Distribution layer devices, such as routers or multilayer switches

  • Core layer devices, such as multilayer switches

  • Interconnections, such as WAN links and PSTN gateways, even through different providers

  • Power supplies and UPSs

In some data networks, a high level of availability and reliability is not critical enough to warrant financing the hardware and links required to provide complete redundancy. But if voice is layered onto the network, these requirements need to be revisited.

With Cisco Architecture for Voice, Video and Integrated Data (AVVID) technology, Cisco CallManager clusters provide a way to design redundant hardware. When using gatekeepers, you can configure backup devices as secondary gatekeepers in case the primary gatekeeper fails. Redundant devices and Cisco IOS services, like Hot Standby Router Protocol (HSRP), also provide high availability. For proactive network monitoring and trouble reporting, a network management platform such as CiscoWorks2000 provides a high degree of responsiveness to network issues.

7.1.8 Power Requirements in Support of VoIP



Accurate calculations of power requirements are critical for an effective IP telephony solution. IP phones are best implemented with PoE. Power can be supplied to the IP phones directly from Cisco Catalyst switches with inline power capabilities or by inserting a Cisco Catalyst Inline Power Patch Panel. In addition to IP phones, failover power and total load must be considered for all devices in the IP telephony availability definition, including Building Distribution and Campus Backbone submodules, gateways, Cisco CallManager, and other servers and devices. Power calculations must be network-based rather than device-based. Also, as with wireless access points, VoIP phones are best implemented with Power over Ethernet (PoE).

To provide highly available power protection, you need either a UPS with a minimum battery life of 1 hour for power system failures, or a generator. This solution must include UPS or generator backup for all devices associated with the IP telephony network. In addition, consider UPS systems that have auto-restart capability and a service contract for 4-hour support response.

Recommendations for IP telephony high-availability power and environment include the following:

  • UPS and generator backup

  • UPS systems with auto-restart capability

  • UPS system monitoring

  • 4-hour service response contract for UPS system problems

  • Recommended equipment operating temperatures maintained at all times

martes, 11 de agosto de 2009

Module 5: Implementing High Availability in a Campus Environment Parte3

5.3 Configuring Layer 3 Redundancy with VRRP and GLBP


5.3.1 Describing Virtual Router Redundancy

Like HSRP, Virtual Router Redundancy Protocol (VRRP) allows a group of routers to form a single virtual router. In an HSRP or VRRP group, one router is elected to handle all requests sent to the virtual IP address. With HSRP, this is the active router. An HSRP group has one active router, at least one standby router, and perhaps many listening routers. A VRRP group has one master router and one or more backup routers. The LAN workstations are then configured with the address of the virtual router as their default gateway.

VRRP differs from HSRP in the following ways:

  • VRRP is an IEEE standard (RFC 2338) for router redundancy; HSRP is a Cisco-proprietary protocol.

  • The virtual router represents a group of routers, known as a VRRP group or virtual router group.

  • The active router is referred to as the master virtual router.

  • The master virtual router may have the same IP address as the virtual router group.

  • Multiple routers can function as backup routers.

  • VRRP is supported on Ethernet, Fast Ethernet, and Gigabit Ethernet interfaces, and with Multiprotocol Label Switching (MPLS), virtual private networks (VPNs), and VLANs.

In Figure , routers A, B, and C are members of a VRRP group. The IP address of the virtual router is the same as that of the LAN interface of router A (10.0.0.1). Router A is responsible for forwarding packets sent to this IP address.

The clients have a gateway address of 10.0.0.1. Routers B and C are backup routers. If the master router fails, the backup router with the highest priority becomes the master router. When router A recovers, it resumes the role of master router.

VRRP provides redundancy for the real IP address of a router or for a virtual IP address shared among the VRRP group members. If a real IP address is used, the router with that address becomes the master. If a virtual IP address is used, the master is the router with the highest priority. The master router uses VRRP messages to inform group members that it is the master.



5.3.2 Identifying the VRRP Operations Process


Figure shows a LAN topology in which VRRP is configured so that routers A and B share the load of being the default gateway for clients 1 through 4. Routers A and B act as backup virtual routers to one another should either one fail.

In this example, two virtual router groups are configured. For virtual router 1, router A is the owner of IP address 10.0.0.1, and therefore the master virtual router for clients configured with that default gateway address. Router B is the backup virtual router to router A.

For virtual router 2, router B is the owner of IP address 10.0.0.2 and is the master virtual router for clients configured with the default gateway IP address of 10.0.0.2. Router A is the backup virtual router to router B.

Given that the IP address of the VRRP group is that of a physical interface on one of the group members, the router owning that address is the master in the group. Its priority is set to 255. Backup router priority values can range from 1 to 254; the default is 100. A priority value of 0 indicates that the current master has stopped participating in VRRP. This setting is used to trigger backup routers to transition quickly to the master without having to wait for the current master to time out.

With VRRP, only the master sends advertisements (the equivalent of HSRP hellos). Advertisements are sent on multicast 224.0.0.18 protocol number 112 at a default interval of 1 second.

When the master becomes unavailable, the dynamic failover uses three timers: the advertisement interval, the master down interval, and the skew time.

  • The advertisement interval is the time between advertisements in seconds. The default is 1 second.

  • The master down interval is the number of seconds for the backup to declare the master down. The default is 3 x advertisement interval + skew time.

  • The skew time, (256 - priority) / 256 ms, ensures that the backup router with the highest priority becomes the new master.

Figure lists the steps involved in the VRRP transition.

Note:
If the VRRP master has an orderly shutdown, it sends an advertisement with a priority of 0. This priority setting then triggers the backup router to take over quicker by waiting only the skew time instead of the master down interval.


5.3.3 Configuring VRRP

VRRP is supported on select Cisco Catalyst platforms and can be configured using the commands in Figure .

Figure describes the VRRP command parameters.

Figure describes how to configure VRRP.

Example: Implementing VRRP

SwitchA(config)#interface vlan10
SwitchA(config-if)#ip address 10.1.10.5 255.255.255.0
SwitchA(config-if)#vrrp 10 ip 10.1.10.1
SwitchA(config-if)#vrrp 10 priority 150
SwitchA(config-if)#vrrp 10 timer advertise 4
SwitchB(config)#interface vlan10
SwitchB(config-if)#ip address 10.1.10.6 255.255.255.0
SwitchB(config-if)#vrrp 10 ip 10.1.10.1
SwitchB(config-if)#vrrp 10 priority 100
SwitchB(config-if)#vrrp 10 timer advertise 4

5.3.4 Describing GLBP


While HSRP and VRRP provide gateway resiliency, the upstream bandwidth is not used for the standby members of the redundancy group while the device is in standby mode. Only the active router for HSRP and VRRP groups forwards traffic for the virtual MAC. Resources associated with the standby router are not fully utilized. Some load balancing can occur by creating multiple groups and assigning multiple default gateways, but this configuration creates an administrative burden.

Cisco designed the Gateway Load Balancing Protocol (GLBP) to allow automatic selection, simultaneous use of multiple gateways, and automatic failover between those gateways. Multiple routers share the load of frames that, from a client perspective, are sent to a single default gateway address.

With GLBP, resources can be fully utilized without the administrative burden of configuring multiple groups and managing multiple default gateway configurations as is required with HSRP and VRRP.

GLBP has the following functions:

  • Active virtual gateway (AVG): Members of a GLBP group elect one gateway to be the AVG for that group. Other group members provide backup for the AVG if the AVG becomes unavailable. The AVG assigns a virtual MAC address to each member of the group.

  • Active virtual forwarder (AVF): Each gateway assumes responsibility for forwarding packets sent to the virtual MAC address assigned to it by the AVG. These gateways are known as AVFs for their virtual MAC address.

  • Communication: GLBP members communicate with each other using hello messages sent every 3 seconds to the multicast address 224.0.0.102, User Datagram Protocol (UDP) port 3222.

GLBP has the following features:

  • Load sharing: Traffic from LAN clients can be shared by multiple routers.

  • Multiple virtual routers: Up to 1,024 virtual routers (GLBP groups) can be on each physical interface of a router, and there can be up to four virtual forwarders per group.

  • Preemption: You can preempt an AVG with a higher priority backup virtual gateway. Forwarder preemption works in a similar way, except that it uses weighting instead of priority and is enabled by default.

  • Efficient resource utilization: Any router in a group can serve as a backup, which eliminates the need for a dedicated backup router because all available routers can support network traffic.

GLBP provides upstream load sharing by utilizing the redundant uplinks simultaneously. It uses link capacity efficiently, thus providing peak-load traffic coverage. By making use of multiple available paths upstream from the routers or Layer 3 switches running GLBP, output queues may also be reduced.

HSRP and VRRP use only a single path; other paths are idle, unless multiple groups and gateways are configured. The single path may encounter higher output queue rates during peak times, which leads to lower performance from higher jitter rates. The impact of jitter is lessened and overall performance is improved with GLBP, because more upstream bandwidth is available and additional upstream paths are used.



5.3.5 Identifying the GLBP Operations Process


GLBP allows automatic selection and simultaneous use of all available gateways in the group. The members of a GLBP group elect one gateway to be the AVG for that group. Other members of the group provide backup for the AVG if it becomes unavailable. The AVG assigns a virtual MAC address to each member of the GLBP group. All routers become AVFs for frames addressed to that virtual MAC address. As clients send Address Resolution Protocol (ARP) requests for the address of the default gateway, the AVG sends these virtual MAC addresses in the ARP replies. A GLBP group can have up to four group members.

GLBP supports the following operational modes for load balancing traffic across multiple default routers servicing the same default gateway IP address:

  • Weighted load-balancing algorithm: The amount of load directed to a router is dependent upon the weighting value advertised by that router.

  • Host-dependent load-balancing algorithm: A host is guaranteed to use the same virtual MAC address as long as that virtual MAC address is participating in the GLBP group.

  • Round-robin load-balancing algorithm: As clients send ARP requests to resolve the MAC address of the default gateway, the reply to each client contains the MAC address of the next possible router in round-robin fashion. All routers’ MAC addresses take turns being included in address resolution replies for the default gateway IP address.

GLBP automatically manages the virtual MAC address assignment, determines who handles the forwarding, and ensures that each station has a forwarding path for failures to gateways or tracked interfaces. If failures occur, the load-balancing ratio is adjusted among the remaining AVFs so that resources are used in the most efficient way.

As shown in Figure , GLBP attempts to balance traffic on a per-host basis using the round-robin algorithm.

Figure describes how GLBP balances traffic using the round-robin algorithm.

In Figure , clients A and B have each resolved a different MAC address for the default gateway, so they send their routed traffic to separate routers, although they both have the same default gateway address configured. Each GLBP router is an AVF for the virtual MAC address to which it has been assigned.

Like HSRP, GLBP can be configured to track interfaces. In Figure , the WAN link from router R1 is lost, and GLBP detects the failure.

Because interface tracking was configured on R1, the job of forwarding packets for virtual MAC address 0000.0000.0001 is taken over by the secondary virtual forwarder for the MAC, which is router R2. Therefore, the client sees no disruption of service nor does it need to resolve a new MAC address for the default gateway.

GLBP is supported on select Cisco Catalyst platforms. Figure illustrates the GLBP interface commands. Figure describes the command parameters. Figure describes the steps needed to configure GLBP.

The following example configures GLBP on two multilayer switches:

SwitchA(config)#interface vlan7
SwitchA(config-if)#ip address 10.1.7.5 255.255.255.0
SwitchA(config-if)#glbp 7 ip 10.1.7.1
SwitchA(config-if)#glbp 7 priority 150
SwitchA(config-if)#glbp 7 timers msec 250 msec 750
SwitchB(config)#interface vlan7
SwitchB(config-if)#ip address 10.1.7.6 255.255.255.0
SwitchB(config-if)#glbp 7 ip 10.1.7.1
SwitchB(config-if)#glbp 7 priority 100
SwitchB(config-if)#glbp 7 timers msec 250 msec 750
SwitchA#show glbp 7
Vlan7 - Group 7
State is Active
2 state changes, last state change 23:50:33
Virtual IP address is 10.1.7.1
Hello time 250 msec, hold time 750 msec
Next hello sent in 40 msecs
Redirect time 600 sec, forwarder time-out 7200 sec
Authentication text "stringabc"
Preemption enabled, min delay 60 sec
Active is local
Standby is unknown
Priority 254 (configured)
Weighting 105 (configured 110), thresholds: lower 95, upper 105
Track object 2 state Down decrement 5
Load balancing: host-dependent
There is 1 forwarder (1 active)
Forwarder 1
State is Active
1 state change, last state change 23:50:15
MAC address is 0007.b400.0101 (default)
Owner ID is 0005.0050.6c08
Redirection enabled
Preemption enabled, min delay 60 sec

5.4 High Availability Lab Exercise

5.4.1 Lab 5-1 Hot Standby Router Protocol


Lab Activity

Lab Exercise: Lab 5-1 Hot Standby Router Protocol

Configure inter-VLAN routing with HSRP to provide redundant, fault tolerant routing to the internal network.

Summary


Device, link, or hardware component redundancy at strategic points in the network leads to high availability. Hot Standby Router Protocol (HSRP) provides router redundancy to network hosts and can be optimized in several ways. Virtual Router Redundancy Protocol (VRRP) and Gateway Load Balancing Protocol (GLBP) were derived from HSRP and provide additional redundancy features.

Module 5: Implementing High Availability in a Camp...Parte2

5.2 Optimizing HSRP


5.2.1 Describing HSRP Optimization Options

The options illustrated in Figures and make it possible to optimize HSRP operation in the campus network.


Each standby group has its own active and standby routers. The network administrator can assign a priority value to each router in a standby group, allowing the administrator to influence the active and standby router selection.

To set the priority value of a router (default is 100), enter this command in interface configuration mode:

Switch(config-if)#standby group-number priority priority-value

Figure describes the variables for the standby command.

During the election process, the router with the highest priority in an HSRP group becomes the active router. In the case of a tie, the router with the highest configured IP address is chosen.

To reinstate the default standby priority value, use the no standby priority command.

The following example states that interface VLAN10 has a priority value of 150 in HSRP group 1. If this priority value is the highest number in that HSRP group, the routing device on which this interface resides is the active router for that group.

Switch#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.32 255.255.255.0
no ip redirects
standby 1 priority 150
standby 1 ip 172.16.10.110

The standby router automatically assumes the active router role when the active router fails or is removed from service. This new active router remains the forwarding router, even if a former active router with a higher priority regains service in the network.

A former active router can be configured to resume the forwarding router role from a router with a lower priority by using the following command in interface configuration mode:

Switch(config-if)#standby [group-number] preempt [{delay} [minimum delay] [sync delay]]

When the standby preempt command is issued, the interface changes to the appropriate state.

Note:
If the routers do not have preempt configured, a router that boots up significantly faster than the others in the standby group becomes the active router, regardless of the configured priority.

To remove the interface from preemptive status, use the no standby group preempt command.

The following example states that interface VLAN10 is configured to resume its role as the active router in HSRP group 1, assuming that interface VLAN10 on this router has the highest priority in that standby group.

Switch#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.82 255.255.255.0
no ip redirects
standby 1 priority 150
standby 1 preempt
standby 1 ip 172.16.10.110

HSRP hello messages are transmitted constantly by the active and standby HSRP routers and during elections by all HSRP-enabled routers. The hello message contains the priority of the router, along with the hello time and hold time values. The hello time is the interval between the hello messages that the router sends. The hold time is the amount of time that the current hello message is considered valid. The default hello and hold times are 3 and 10 seconds, respectively, which means failover time could be as much as 10 seconds for clients to start communicating with the new default gateway. In some cases, this interval may be excessive for application support.

You can change the default values of the timers to milliseconds to accommodate subsecond failovers. Lowering the hello timer results in increased traffic for hello messages and should be used cautiously. The hold time should be at least three times the value of the hello time.

To change the timers, enter this command in interface configuration mode:

Switch(config-if)#standby group-number timers [msec] hellotime holdtime
Note:
Hello and dead timers intervals must be identical for all devices within an HSRP group.

Figure describes the command options.

To reinstate the default values, use the no standby group timers command.

In some situations, the status of an interface directly affects which router needs to become the active router. This is particularly true when each of the routers in an HSRP group has a different path to resources within the campus network.

In Figure , routers A and B reside in one building, and they each support a Gigabit Ethernet link to the other building. Router A has the higher priority and is the active forwarding router for standby group 1. Router B is the standby router for that group. Routers A and B are exchanging hello messages through their E0 interfaces.


The Gigabit Ethernet link between the active forwarding router for the standby group and the other building experiences a failure.
If HSRP is not enabled, router A would detect the failed link and send an ICMP redirect to router B. However, when HSRP is enabled, ICMP redirects are disabled. Therefore, neither router A nor the virtual router sends an ICMP redirect. In addition, although the G1 interface on router A is no longer functional, router A still communicates hello messages out interface E0, indicating that router A is still the active router. Packets sent to the virtual router for forwarding to headquarters may not be routed.

It is possible that a dynamic routing protocol (if in use) would detect the link failure and then update the routing tables of the routers. However, traffic would then be sent by hosts to the active HSRP router and forwarded back across the Ethernet segment to the standby HSRP router where the functional Gigabit link would be used.


Interface tracking enables the priority of a standby group router to be automatically adjusted based on the availability of that router’s interfaces. When a tracked interface becomes unavailable, the HSRP priority of the router is decreased. When properly configured, the HSRP tracking feature ensures that a router with an unavailable key interface relinquishes the active router role.

In this example, the E0 interface on router A tracks the G1 interface. If the link between the G1 interface and the other building fails, the router automatically decrements the priority on the E0 interface and stops transmitting hello messages out that interface. Router B assumes the active router role when no hello messages are detected for the hold time period. The hello packet has a field that indicates the current priority of the HSRP-enabled interface. Router A changes this field to indicate its priority for subsequent hellos.

To configure HSRP tracking, enter the command in Figure in interface configuration mode.

To disable interface tracking, use the no standby group track command.

The command to configure HSRP tracking on a multilayer switch is the same as on the external router, except that the interface type can be identified as a switch virtual interface or as a physical interface.

Multiple tracking statements may be applied to an interface, which is useful if the intent is for the currently active HSRP interface to relinquish its status only when two (or more) tracked interfaces fail।


5.2.2 Tuning HSRP Operations

You can adjust HSRP timers to tune the performance of HSRP on distribution devices, thereby increasing their resilience and reliability in routing packets off the local VLAN.

You can set the HSRP hello and hold times to millisecond values so that HSRP failover occurs in less than 1 second. For example:

Switch(config-if)#standby 1 timers msec 200 msec 750

Remember that the lower the hello timer is, the greater the hello traffic.

Preemption is an important feature of HSRP, because it allows the primary router to resume the active role when the router comes back online after a failure or maintenance event. Preemption forces a predictable routing path for the VLAN during normal operations and ensures that the Layer 3 forwarding path for a VLAN parallels the Layer 2 Spanning Tree Protocol (STP) forwarding path whenever possible.

You should always use preemption when tracking interfaces. In the previous example, when the Gigabit link came back up, router A’s priority would increase, but without preemption, it would not become the HSRP active router until router B had a state change.

When a preempting distribution switch is rebooted, HSRP preempt communication should not begin until the distribution switch has established full connectivity to the rest of the network. This allows routing protocol convergence to occur more quickly once the preferred router is in an active state. To accomplish this, measure the system boot time and set the HSRP preempt delay to a value 50 percent greater than the boot time. This ensures that the primary distribution switch establishes full connectivity to the network before HSRP communication occurs.

For example, if the boot time for the distribution device is 120 seconds, the preempt configuration would be as follows:

standby 1 preempt
standby 1 preempt delay minimum 180


5.2.3 Describing Load Sharing

With a single HSRP group on a subnet, the active router is forwarding all the packets off that subnet while the standby router is not forwarding any packets. To facilitate load sharing, a single router may be a member of multiple HSRP groups on the same segment. Multiple standby groups further enable redundancy and load sharing. While a router is actively forwarding traffic for one HSRP group, the router can be in standby or listen state for another group. Each standby group emulates a single virtual router. There can be up to 255 standby groups on any LAN, but the maximum number of standby groups need be no more than the number of routers on a segment. In most cases, two standby groups are sufficient.

CAUTION:

Increasing the number of groups in which a router participates increases the load on the router, which can impact the router’s performance.

In Figure , both router A and B are members of groups 1 and 2. Router A is the active forwarding router for group 1 and the standby router for group 2. Router B is the active forwarding router for group 2 and the standby router for group 1.

The following example shows how multiple HSRP groups can be configured on the same segment to facilitate load sharing. To be useful, half the hosts on the segment need to use 172.16.10.110 as a default gateway, while the other half need to use 172.16.10.120.

RouterA#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.32 255.255.255.0
no ip redirects
standby 1 priority 150
standby 1 ip 172.16.10.110
standby 2 priority 50
standby 2 ip 172.16.10.120
RouterB#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.33 255.255.255.0
no ip redirects
standby 1 priority 50
standby 1 ip 172.16.10.110
standby 2 priority 150
standby 2 ip 172.16.10.120
RouterA#show standby brief
P indicates configured to preempt.
|
Interface Grp Prio P State Active Standby Virtual IP
Vl10 1 150 Active local 172.16.10.33 172.16.10.110
Vl10 2 50 Standby 172.16.10.33 local 172.16.10.120

Routers can simultaneously provide redundant backup and perform load sharing across different IP subnets.

In Figure , two HSRP-enabled routers participate in two separate VLANs, using ISL or 802.1Q. Running HSRP over trunks allows users to configure redundancy among multiple routers that are configured as front ends for VLAN IP subnets. By configuring HSRP over trunks, users can eliminate situations in which a single point of failure causes traffic interruptions. This feature provides some improvement in overall networking resilience by providing load balancing and redundancy capabilities between subnets and VLANs.

For a VLAN, configure the same device to be both the spanning tree root and the HSRP active router. This approach ensures that the Layer 2 forwarding path leads directly to the Layer 3 active router, thereby achieving maximum load balancing efficiency on the routers and trunks.

A standby group, an IP address, and a single well-known MAC address with a unique group identifier should be allocated to the group for each VLAN. Although up to 255 standby groups can be configured, the number of group identifiers used should be kept to a minimum. If you are configuring two distribution layer switches, you typically need only two standby group identifiers.

The following example shows how multiple HSRP groups can be configured on two HSRP-enabled routers participating in two separate VLANs

RouterB#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.32 255.255.255.0
no ip redirects
standby 1 priority 150
standby 1 ip 172.16.10.110
interface Vlan20
ip address 172.16.20.32 255.55.255.0
no ip redirects
standby 2 priority 50
standby 2 ip 172.16.20.120

RouterB#show running-config
Building configuration...

Current configuration:
!

interface Vlan10
ip address 172.16.10.33 255.255.255.0
no ip redirects
standby 1 priority 50
standby 1 ip 172.16.10.110
interface Vlan20
ip address 172.16.20.33 255.255.255.0
no ip redirects
standby 2 priority 150
standby 2 ip 172.16.20.120


5.2.4 HSRP Debug Commands

The commands in Figure are used to debug HSRP operations.

Figure describes the debug commands.


5.2.5 Debugging HSRP Operations

The Cisco IOS implementation of HSRP supports the debug command, which displays HSRP state changes and information regarding the transmission and receipt of HSRP packets. To enable HSRP debugging, enter the following command in privileged EXEC mode:

Switch#debug standby

Figure provides a description of debug standby fields.

CAUTION:

Because debugging output is assigned high priority in the CPU process, this command can render the system unusable.

Example: Debugging with Two Active Routers

The example in Figure displays output on distribution router 1DSW1. Router 1DSW1 is also receiving an HSRP hello from 172.16.1.112 for the same VLAN and same virtual IP address but with a different standby group number. Hence, both routers are active for the same virtual IP address.

The debug standby command is being used to troubleshoot the problem. The standby group number is not consistent, so the two routers have not formed a standby group.

Example: Debugging Active Router Negotiation

This example displays the debug standby command output as the 1DSW1 router with IP address 172.16.1.111 initializes and negotiates for the role of active router.

*Mar 8 20:34:10.221: SB11: Vl11 Init: a/HSRP enabled
*Mar 8 20:34:10.221: SB11: Vl11 Init -> Listen
*Mar 8 20:34:20.221: SB11: Vl11 Listen: c/Active timer expired (unknown)
*Mar 8 20:34:20.221: SB11: Vl11 Listen -> Speak
*Mar 8 20:34:20.221: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:23.101: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:25.961: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:28.905: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:30.221: SB11: Vl11 Speak: d/Standby timer expired (unknown)
*Mar 8 20:34:30.221: SB11: Vl11 Standby router is local
*Mar 8 20:34:30.221: SB11: Vl11 Speak -> Standby
*Mar 8 20:34:30.221: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 8 20:34:30.221: SB11: Vl11 Standby: c/Active timer expired (unknown)
*Mar 8 20:34:30.221: SB11: Vl11 Active router is local
*Mar 8 20:34:30.221: SB11: Vl11 Standby router is unknown, was local
*Mar 8 20:34:30.221: SB11: Vl11 Standby -> Active
*Mar 8 20:34:30.221: %STANDBY-6-STATECHANGE: Vlan11 Group 11 state Standby -> Active
*Mar 8 20:34:30.221: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115

To disable the debugging feature, use either the no debug standby or the no debug all command.

Example: Debugging First and Only Router on Subnet

Because 1DSW1 (172.16.11.111) is the only router on the subnet, and it is not configured for preempt, it goes through five HSRP states before becoming the active router. Notice that at Mar 8 20:34:10.221 the interface comes up, and 1DSW1 enters the listen state. The router stays in listen state for a hold time of 10 seconds. 1DSW1 then goes into speak state at Mar 8 20:34:20.221 for 10 seconds. When the router is speaking, it sends its state out every 3 seconds, according to its hello interval. After 10 seconds in speak state, the router has determined that there is no standby router and enters the standby state at Mar 8 20:34:30.221. The router has also determined that there is not an active router; therefore, it immediately enters active state at Mar 8 20:34:30.221. From that point on, the active router sends its active state hello message every 3 seconds. Because there are no other routers on this broadcast domain, no hellos are being received.

1DSW1(config)#interface vlan 11
1DSW1(config-if)#no shut

*Mar 8 20:34:08.925: %SYS-5-CONFIG_I: Configured from console by console
*Mar 8 20:34:10.213: %LINK-3-UPDOWN: Interface Vlan11, changed state to up
*Mar 8 20:34:10.221: SB: Vl11 Interface up
*Mar 8 20:34:10.221: SB11: Vl11 Init: a/HSRP enabled
*Mar 8 20:34:10.221: SB11: Vl11 Init -> Listen
*Mar 8 20:34:11.213: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan11, changed state to up
*Mar 8 20:34:20.221: SB11: Vl11 Listen: c/Active timer expired (unknown)
*Mar 8 20:34:20.221: SB11: Vl11 Listen -> Speak
*Mar 8 20:34:20.221: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:23.101: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:25.961: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:28.905: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 8 20:34:30.221: SB11: Vl11 Speak: d/Standby timer expired (unknown)
*Mar 8 20:34:30.221: SB11: Vl11 Standby router is local
*Mar 8 20:34:30.221: SB11: Vl11 Speak -> Standby
*Mar 8 20:34:30.221: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 8 20:34:30.221: SB11: Vl11 Standby: c/Active timer expired (unknown)
*Mar 8 20:34:30.221: SB11: Vl11 Active router is local
*Mar 8 20:34:30.221: SB11: Vl11 Standby router is unknown, was local
*Mar 8 20:34:30.221: SB11: Vl11 Standby -> Active
*Mar 8 20:34:30.221: %STANDBY-6-STATECHANGE: Vlan11 Group 11 state Standby -> Active
*Mar 8 20:34:30.221: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 8 20:34:33.085: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 8 20:34:36.025: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 8 20:34:38.925: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115

Example: Router Without Preempt Coming Up

Router 1DSW1 (172.16.11.111) is configured with a priority of 100, which is higher than the priority of 50 of the current active router, 1DSW2 (172.16.11.112). Router 1DSW1 is not configured with preempt, so even though it has a higher priority, it does not immediately become the active router. After router 1DSW1 goes through the HSRP initialization states, it will come up as the standby router.

1DSW1(config)#interface vlan 11
1DSW1(config-if)#no shut

*Mar 1 00:12:16.871: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:16.871: SB11: Vl11 Active router is 172.16.11.112
*Mar 1 00:12:16.891: %SYS-5-CONFIG_I: Configured from console by console
*Mar 1 00:12:18.619: %LINK-3-UPDOWN: Interface Vlan11, changed state to up
*Mar 1 00:12:18.623: SB: Vl11 Interface up
*Mar 1 00:12:18.623: SB11: Vl11 Init: a/HSRP enabled
*Mar 1 00:12:18.623: SB11: Vl11 Init -> Listen
*Mar 1 00:12:19.619: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan11, changed state to up
*Mar 1 00:12:19.819: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:19.819: SB11: Vl11 Listen: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:22.815: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:22.815: SB11: Vl11 Listen: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:25.683: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:25.683: SB11: Vl11 Listen: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:28.623: SB11: Vl11 Listen: d/Standby timer expired (unknown)
*Mar 1 00:12:28.623: SB11: Vl11 Listen -> Speak
*Mar 1 00:12:28.623: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 1 00:12:28.659: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:28.659: SB11: Vl11 Speak: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:31.539: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:31.539: SB11: Vl11 Speak: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:31.575: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 1 00:12:34.491: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:34.491: SB11: Vl11 Speak: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:34.547: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 1 00:12:37.363: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:37.363: SB11: Vl11 Speak: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:37.495: SB11: Vl11 Hello out 172.16.11.111 Speak pri 100 ip 172.16.11.115
*Mar 1 00:12:38.623: SB11: Vl11 Speak: d/Standby timer expired (unknown)
*Mar 1 00:12:38.623: SB11: Vl11 Standby router is local
*Mar 1 00:12:38.623: SB11: Vl11 Speak -> Standby
*Mar 1 00:12:38.623: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 1 00:12:40.279: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:40.279: SB11: Vl11 Standby: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:41.551: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 1 00:12:43.191: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:43.191: SB11: Vl11 Standby: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:44.539: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 1 00:12:46.167: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:46.167: SB11: Vl11 Standby: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:47.415: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115
*Mar 1 00:12:49.119: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:12:49.119: SB11: Vl11 Standby: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:12:50.267: SB11: Vl11 Hello out 172.16.11.111 Standby pri 100 ip 172.16.11.115

Example: Router with Preempt Coming Up

Router 1DSW1 (172.16.11.11) is configured with a priority of 100, which is higher than the priority of the active router, 1DSW2 (172.16.11.112). 1DSW1 is also configured with preempt. At Mar 1 00:16:43.099, VLAN11 on 1DSW1 comes up and transitions into the listen state. At Mar 1 00:16:43.295, 1DSW1 receives a hello message from the active router (1DSW2). 1DSW1 determines that the active router has a lower priority. At Mar 1 00:16:43.295, 1DSW1 immediately sends out a coup message indicating that 1DSW1 is transitioning to the active router. 1DSW2 enters the speak state and eventually becomes the standby router.

1DSW1(config)#interface vlan 11
1DSW1(config-if)#no shut

*Mar 1 00:16:41.295: %SYS-5-CONFIG_I: Configured from console by console
*Mar 1 00:16:43.095: %LINK-3-UPDOWN: Interface Vlan11, changed state to up
*Mar 1 00:16:43.099: SB: Vl11 Interface up
*Mar 1 00:16:43.099: SB11: Vl11 Init: a/HSRP enabled
*Mar 1 00:16:43.099: SB11: Vl11 Init -> Listen
*Mar 1 00:16:43.295: SB11: Vl11 Hello in 172.16.11.112 Active pri 50 ip 172.16.11.115
*Mar 1 00:16:43.295: SB11: Vl11 Active router is 172.16.11.112
*Mar 1 00:16:43.295: SB11: Vl11 Listen: h/Hello rcvd from lower pri Active router (50/172.16.11.112)
*Mar 1 00:16:43.295: SB11: Vl11 Active router is local, was 172.16.11.112
*Mar 1 00:16:43.295: SB11: Vl11 Coup out 172.16.11.111 Listen pri 100 ip 172.16.11.115
Mar 1 00:16:43.295
*Mar 1 00:16:43.299: %STANDBY-6-STATECHANGE: Vlan11 Group 11 state Listen -> Active
*Mar 1 00:16:43.299: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:43.303: SB11: Vl11 Hello in 172.16.11.112 Speak pri 50 ip 172.16.11.115
*Mar 1 00:16:44.095: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan11, changed state to up
*Mar 1 00:16:46.187: SB11: Vl11 Hello in 172.16.11.112 Speak pri 50 ip 172.16.11.115
*Mar 1 00:16:46.207: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:49.095: SB11: Vl11 Hello in 172.16.11.112 Speak pri 50 ip 172.16.11.115
*Mar 1 00:16:49.195: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:52.079: SB11: Vl11 Hello in 172.16.11.112 Speak pri 50 ip 172.16.11.115
*Mar 1 00:16:52.147: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:53.303: SB11: Vl11 Hello in 172.16.11.112 Standby pri 50 ip 172.16.11.115
*Mar 1 00:16:53.303: SB11: Vl11 Standby router is 172.16.11.112
*Mar 1 00:16:55.083: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:56.231: SB11: Vl11 Hello in 172.16.11.112 Standby pri 50 ip 172.16.11.115
*Mar 1 00:16:58.023: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:16:59.223: SB11: Vl11 Hello in 172.16.11.112 Standby pri 50 ip 172.16.11.115
*Mar 1 00:17:00.983: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115
*Mar 1 00:17:02.211: SB11: Vl11 Hello in 172.16.11.112 Standby pri 50 ip 172.16.11.115
*Mar 1 00:17:03.847: SB11: Vl11 Hello out 172.16.11.111 Active pri 100 ip 172.16.11.115