Back to Blogs

RIP for CCNP ENARSI: The Technical Guide

Routing Information Protocol (RIP) is an interior gateway protocol designed for small-to-medium networks. While modern enterprise cores rely on OSPF, EIGRP, or BGP, RIP remains an essential component of the CCNP ENARSI (300-410) certification curriculum.

RIP CCNP ENARSI Routing
RIP for CCNP ENARSI: The Technical cheat sheet: use this quick map before reading the detailed sections.
Lesson overview

In This Lesson

Review RIP at CCNP depth, from distance-vector behavior and versions to authentication, route control, convergence, and troubleshooting. Commands are tied to the evidence they produce.

  1. Part 1: Core Architecture & Operation
  2. Part 2: Protocol Versions: RIPv1 vs. RIPv2
  3. Part 3: Configuration & Advanced Control
  4. Part 4: Cryptographic Authentication
  5. Part 5: Convergence Mechanics & Loop Prevention
  6. Part 6: Route Control, Redistribution & Lab Practice
  7. Part 7: CCNP ENARSI Troubleshooting Commands
From concept to practice

Quick Learning Map

Keep this three-step view in mind as you work through the detailed lesson.

1

Exchange distance vectors

Understand hop count, updates, timers, split horizon, and loop prevention.

2

Control advertisements

Configure RIPv2, authentication, passive interfaces, summaries, and redistribution.

3

Troubleshoot convergence

Inspect neighbors, updates, routes, timers, and the actual forwarding result.

Fast orientation

RIP for CCNP ENARSI: The Technical Guide at a Glance

Use this summary before moving into the detailed explanations, examples, commands, and checks.

Core focus

Review RIP at CCNP depth, from distance-vector behavior and versions to authentication, route control, convergence, and troubleshooting.

Key connection

Exchange distance vectors → Control advertisements → Troubleshoot convergence

Practical outcome

Commands are tied to the evidence they produce.

Part 1: Core Architecture & Operation

RIP is a pure distance-vector routing protocol. Unlike link-state protocols that maintain a complete topology graph, RIP routers exchange their routing tables only with directly connected neighbors. This model is often called routing by rumor.

+-------------------------------------------------------+
|                   RIP Encapsulation                   |
|  +-------------+-----------+-----------------------+  |
|  | IP Header   | UDP Frame | RIP Header & Payloads |  |
|  | (224.0.0.9) | (Port 520)| (Up to 25 Routes)     |  |
|  +-------------+-----------+-----------------------+  |
+-------------------------------------------------------+
TransportUDP 520 / 521
MetricHop Count
Maximum Valid Hop15
Infinity16
  • Transport Encapsulation: RIP uses UDP Port 520 for IPv4 and UDP Port 521 for RIPng/IPv6. It does not establish formal neighbor adjacencies or acknowledge packets.
  • Metric Calculation: RIP uses one metric: hop count. Each Layer 3 router crossed adds one hop.
  • Network Diameter: The maximum valid hop count is 15. A hop count of 16 is infinite and unreachable.
  • Periodic Updates: Routers send their full routing tables every 30 seconds.
  • Payload Capacity: A standard RIP packet can carry 25 route entries, or 24 when cryptographic authentication is attached.

Part 2: Protocol Versions: RIPv1 vs. RIPv2

The move from RIPv1 to RIPv2 fixed important addressing, security, and troubleshooting limitations.

Feature / Behavior RIPv1 (RFC 1058) RIPv2 (RFC 2453)
Routing ClassClassful, no subnet masks transmittedClassless, transmits subnet masks
VLSM & CIDRNot supportedFully supported
Update DestinationBroadcast 255.255.255.255Multicast 224.0.0.9
AuthenticationNonePlaintext and MD5 cryptographic
Route TaggingNot supportedSupported for redistribution
Next-Hop FieldNot supportedSupported for optimized paths

Part 3: Configuration & Advanced Control

When configuring RIPv2, disable classful summarization to prevent overlapping subnet issues across discontiguous networks.

Basic Classless Implementation

Router(config)# router rip
Router(config-router)# version 2
Router(config-router)# no auto-summary
Router(config-router)# network 10.0.0.0
Router(config-router)# network 192.168.1.0
Note: RIP network statements use the major classful network boundary, such as 10.0.0.0, even when the interface itself uses a CIDR mask like /24 or /30.

Passive Interfaces

Sending RIP updates toward end-user switches wastes bandwidth and exposes routing information. Silence user-facing links and selectively enable routing links.

! Best Practice: Silence all interfaces by default, then selectively enable routing links
Router(config-router)# passive-interface default
Router(config-router)# no passive-interface GigabitEthernet0/0

Default Route Propagation

Router(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.1
Router(config)# router rip
Router(config-router)# default-information originate

Part 4: Cryptographic Authentication

To prevent unauthorized routing updates and man-in-the-middle attacks, RIPv2 supports MD5 authentication. Authentication is configured per interface using a global key-chain.

! Step 1: Define the Key Chain and cryptographic string
Router(config)# key chain RIP_AUTH_CHAIN
Router(config-keychain)# key 1
Router(config-keychain-key)# key-string CcNP_SeCuRe_K3Y

! Step 2: Apply the authentication mode and key-chain to the routing interface
Router(config)# interface GigabitEthernet0/1
Router(config-if)# ip rip authentication mode md5
Router(config-if)# ip rip authentication key-chain RIP_AUTH_CHAIN

Part 5: Convergence Mechanics & Loop Prevention

Distance-vector protocols lack a global topology map, so RIP uses timers and loop-prevention behavior to avoid count-to-infinity failures.

The Four Core Timers

  • Update (30s): How often the router sends its routing table.
  • Invalid (180s): If no update arrives in this window, the route is marked unreachable with metric 16 and placed into holddown.
  • Holddown (180s): The router ignores unstable updates for the route to prevent flapping paths from being reinstalled.
  • Flush (240s): The dead route is physically removed from the routing table. Because the flush timer runs concurrently with the invalid timer, the route is usually removed 60 seconds after entering holddown.

Loop Prevention Techniques

  • Split Horizon: A router never advertises a route out of the same interface it learned the route from.
  • Split Horizon with Poison Reverse: The router advertises the route back to the source with metric 16.
  • Route Poisoning: When a connected network fails, the router immediately advertises the subnet as unreachable.
  • Triggered Updates: RIP sends topology changes immediately instead of waiting for the normal 30-second update timer.

Part 6: Route Control, Redistribution & Lab Practice

In real networks, RIP is often found at the edge of older environments, small branch designs, or certification labs where redistribution behavior must be understood clearly. Because RIP has a low maximum diameter and a simple hop-count metric, route control is important. Advertise only the networks that should participate, use passive interfaces toward end hosts, and filter routes when redistributing between RIP and a more capable protocol such as OSPF, EIGRP, or BGP.

Redistribution also requires careful metric planning. A route redistributed into RIP needs a valid hop-count metric from 1 to 15. If the metric is missing or becomes 16, the receiving routers treat it as unreachable. In mixed-protocol labs, always verify both the protocol database and the final routing table because a route can exist in RIP but lose installation to a route with a better administrative distance.

Router(config)# router rip
Router(config-router)# version 2
Router(config-router)# redistribute ospf 10 metric 2
Router(config-router)# passive-interface default
Router(config-router)# no passive-interface GigabitEthernet0/0
  • Use passive interfaces: Advertise connected networks without sending updates toward user devices.
  • Filter at boundaries: Prevent accidental route leaks between old RIP segments and modern routing domains.
  • Document metrics: Hop count is simple, but redistribution can still create confusing reachability if metrics are inconsistent.
  • Confirm timers: Lab problems often come from waiting for invalid and flush timers instead of triggering a clean update.

Part 7: CCNP ENARSI Troubleshooting Commands

When diagnosing RIP issues on Cisco IOS, verify protocol parameters, interface states, and database entries in a consistent order.

Protocol Stateshow ip protocols
Installed Routesshow ip route rip
RIP Databaseshow ip rip database
Live Packetsdebug ip rip
  • show ip protocols: Displays active protocols, timers, automatic summarization, authentication key-chains, and interfaces sending or receiving updates.
  • show ip route rip: Displays only RIP-learned routes, marked with the R legend code.
  • show ip rip database: Shows internal RIP entries, summarized routes, and poisoned routes still in holddown.
  • debug ip rip: Shows inbound and outbound RIP update packets, source IPs, advertised subnets, and hop counts.
  • debug ip rip events: Shows high-level events such as triggered updates, database pruning, and authentication errors.