Chapter 9. Is HSRP Resilient?

Hot Standby Router Protocol1 (HSRP) commonly provides high availability in an access network where hosts rely only on a default static route. This chapter explains HSRP’s vulnerabilities. Also, this chapter describes mitigation techniques to make HSRP a real high-availability solution instead of a denial of service (DoS) target.

HSRP Mechanics

HSRP’s role is to make a group of Layer 2 adjacent routers appear as a single virtual router. One physical router, known as the active router, actually works and forwards IP packets.

The other physical routers, known as standby routers, basically do nothing but keep the HSRP states. When the active router fails, a standby router automatically takes over the active role; that ...

Get LAN Switch Security: What Hackers Know About Your Switches now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.