TP-Link T3700G-28TQ T3700G-28TQ V1 UG - Page 211

Authentication Methods, Master Election

Page 211 highlights

new master router will be elected among them to take the role of the master router if master router fails. 2. Master Election Initially-created routers work in Backup state and learn other members' priorities in the virtual router via VRRP packets. The one with the highest priority is elected as master router. If the priority values are the same, the router with the highest interface IP address is selected as the master.  In preemptible mode, when backup router receives VRRP packet, it will compare its priority with that of the advertisement packet. If of higher priority, the backup router will become the master router; otherwise, it will maintain Backup state.  In non-preemptible mode, physical routers in the backup group will maintain Master or Backup state as long as the master router functions normally. Even if backup router is given higher priority, it cannot become a master router in non-preempt mode. The VRRP priority ranges from 0 to 255 (the bigger the number is, the higher the priority is). Configurable range is 1-254. The priority value 0 is reserved for the current master when it gives up its role as master router. For example, when master router receives shutdown message, it would send VRRP packet with priority 0 to the backup group which the interface belongs to. The priority of the IP address owner must be 255. Therefore, if there exists an IP address owner in the backup group and it works normally, it must be the master router. 3. State Transition VRRP defines three state modes: Initialize, Master and Backup. Only in Master state can master router provide service for forwarding request via virtual IP address and forward VRRP packet. When the system just starts, it comes to Initialize state. If the virtual router is not given a virtual IP address, the system would maintain Initialize state. If the virtual IP address is configured properly, when the system receives startup message from interface, it would transition to the Backup state (in which case its priority is not 255) or Master state (in which case its priority is 255). Routers in master or backup state can change to Initialize state only when they receive shutdown message from interface. In Initialize state, router cannot deal with VRRP packet. If the master router functions properly, it will periodically send VRRP packets informing backup routers in the backup group that it functions properly. VRRP timer can be manually configured to customize the intervals that master router sends VRRP packet. If the backup router waits for a period longer than three times the advertisement timer and fails to receive VRRP packets from the master router, they will assume that the master router is dead and initiate an election process by transitioning to the Master state and forwarding VRRP packets. To avoid frequent Master-Backup state transition among routers in the backup group and provide enough time for backup routers to collect necessary information, backup router would not preempt to be master as soon as it receives packets with lower priority value. It would wait for a certain time, which is called preempt-mode delay time, and then send packets to take place of the former master. Users can customize the preempt-mode delay time. 4. Authentication Methods VRRP provides three authentication methods:  No authentication: the eligibility of VRRP packets is not verified and no security insurance is provided. In a safe network, no authentication can be set as authentication method.  Simple text password: in a network where security is possible to be threatened, simple text password is recommended. The router which forwards the VRRP packets fills the 200

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396

new master router will be elected among them to take the role of the master router if master
router fails.
2. Master Election
Initially-created routers work in Backup state and learn other members' priorities in the virtual
router via VRRP packets. The one with the highest priority is elected as master router. If the
priority values are the same, the router with the highest interface IP address is selected as the
master.
In preemptible mode, when backup router receives VRRP packet, it will compare its priority
with that of the advertisement packet. If of higher priority, the backup router will become
the master router; otherwise, it will maintain Backup state.
In non-preemptible mode, physical routers in the backup group will maintain Master or
Backup state as long as the master router functions normally. Even if backup router is
given higher priority, it cannot become a master router in non-preempt mode.
The VRRP priority ranges from 0 to 255 (the bigger the number is, the higher the priority is).
Configurable range is 1-254. The priority value 0 is reserved for the current master when it
gives up its role as master router. For example, when master router receives shutdown
message, it would send VRRP packet with priority 0 to the backup group which the interface
belongs to. The priority of the IP address owner must be 255. Therefore, if there exists an IP
address owner in the backup group and it works normally, it must be the master router.
3. State Transition
VRRP defines three state modes: Initialize, Master and Backup. Only in Master state can
master router provide service for forwarding request via virtual IP address and forward VRRP
packet.
When the system just starts, it comes to Initialize state. If the virtual router is not given a virtual
IP address, the system would maintain Initialize state. If the virtual IP address is configured
properly, when the system receives startup message from interface, it would transition to the
Backup state (in which case its priority is not 255) or Master state (in which case its priority is
255). Routers in master or backup state can change to Initialize state only when they receive
shutdown message from interface. In Initialize state, router cannot deal with VRRP packet.
If the master router functions properly, it will periodically send VRRP packets informing backup
routers in the backup group that it functions properly. VRRP timer can be manually
configured to customize the intervals that master router sends VRRP packet. If the backup
router waits for a period longer than three times the advertisement timer and fails to receive
VRRP packets from the master router, they will assume that the master router is dead and
initiate an election process by transitioning to the Master state and forwarding VRRP packets.
To avoid frequent Master-Backup state transition among routers in the backup group and
provide enough time for backup routers to collect necessary information, backup router would
not preempt to be master as soon as it receives packets with lower priority value. It would wait
for a certain time, which is called preempt-mode delay time, and then send packets to take
place of the former master. Users can customize the preempt-mode delay time.
4. Authentication Methods
VRRP provides three authentication methods:
No authentication: the eligibility of VRRP packets is not verified and no security insurance
is provided. In a safe network, no authentication can be set as authentication method.
Simple text password: in a network where security is possible to be threatened, simple text
password is recommended. The router which forwards the VRRP packets fills the
200