{"id":5196,"date":"2024-09-09T06:38:14","date_gmt":"2024-09-09T11:38:14","guid":{"rendered":"http:\/\/109.199.106.156\/~indeni\/wp\/?p=1568"},"modified":"2024-09-09T06:38:14","modified_gmt":"2024-09-09T11:38:14","slug":"how-to-configure-hsrp-vip-problems-using-next-hop-redundancy-protocol-alert","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/09\/09\/how-to-configure-hsrp-vip-problems-using-next-hop-redundancy-protocol-alert\/","title":{"rendered":"How to Configure HSRP VIP Problems Using Next Hop Redundancy Protocol Alert"},"content":{"rendered":"<p>For those of you who don\u2019t know what HSRP is, here is a quick explanation (for those who do, just skip to the 2<sup>nd<\/sup> paragraph). HSRP is \u2018<a target=\"_blank\" href=\"http:\/\/www.cisco.com\/en\/US\/tech\/tk648\/tk362\/tk321\/tsd_technology_support_sub-protocol_home.html\" rel=\"noopener\">Hot Standby Router Protocol<\/a>\u2019. It is a <strong>Cisco-proprietary redundancy protocol<\/strong> for establishing a fault-tolerant default gateway\u2013basically, redundancy for routers.<\/p>\n<p>It is crucial for all devices communicating with routers in an HSRP setup to use the HSRP\u2019s Virtual IP (or VIP) and to make sure there is no access enabled to the physical IP of those routers\/interfaces.<\/p>\n<p>The problem is that when the router goes down, the physical IP goes down with it and all those devices that are configured to use this physical IP (and not the VIP) will not be able to switch over to other routers in the HSRP setup. In most cases, this happens because before you enabled HSRP, all your network devices used the physical IP of this router\u2019s NIC. Since we\u2019re all human, we may forget to change some of those devices to use the Virtual IP.<\/p>\n<p>I wrote a signature (indeni\u2019s Dynamic Knowledge checks: See all checks <a href=\"https:\/\/indeni.com\/indeni-insight\/\" target=\"_blank\" rel=\"noopener\">here<\/a>) to check for this specific setup. indeni will automatically verify that all indeni-monitored devices are using Virtual IP. In order to do this, I used the following commands:<\/p>\n<ul>\n<li>\u201cshow standby\u201d \u2013 to get the Virtual IP<\/li>\n<li>\u201cshow ip interface brief\u201d \u2013 to get the IP of the NIC<\/li>\n<\/ul>\n<p>Once we have collected all the relevant information, we go over all the devices and check whether they are using a physical IP instead of a Virtual IP. If indeni finds any physical IPs, then indeni alerts that \u201c<b>HSRP Virtual IP Is Not Used as Next Hop on Some Devices\u201d<\/b>, with detailed information of our findings, for example:<\/p>\n<p>indeni found that 10.0.0.1 has a route \u201c10.50.1.0\/24 nexthop 192.168.1.2\u201d; however, you have HSRP configured with the Virtual IP address 192.168.1.1.<\/p>\n<p><a href=\"https:\/\/bluecatnetworks.com\/all-alerts\/virtual-ips-and-hsrp\/\">BlueCat Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>For those of you who don\u2019t know what HSRP is,<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[2623,1764,2624,2625,2626],"tags":[2627,1769,2628,2629,2630],"class_list":["post-5196","post","type-post","status-publish","format-standard","hentry","category-alerts","category-cisco","category-hsrp","category-hsrp-configuration","category-vip","tag-alerts","tag-cisco","tag-hsrp","tag-hsrp-configuration","tag-vip"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Blue Cat","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/bluecat\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/alerts\/\" rel=\"category tag\">Alerts<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cisco\/\" rel=\"category tag\">Cisco<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/hsrp\/\" rel=\"category tag\">HSRP<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/hsrp-configuration\/\" rel=\"category tag\">hsrp configuration<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/vip\/\" rel=\"category tag\">VIP<\/a>","tag_info":"VIP","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5196","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5196"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5196\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5196"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5196"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5196"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}