ExamOpsPractice free

Cisco Certified Network Associate (CCNA) 200-301 · Free study guide

Objective 3.5 — Explain first-hop redundancy

Hosts usually configure one default-gateway IP address. First-hop redundancy lets multiple routing devices present a shared virtual gateway so the host does not need to learn a new address when one device fails.

Virtual identity

The participating routers share a virtual IP and associated virtual MAC behavior. One router actively forwards for that identity while another is prepared to take over. Hosts resolve and send to the virtual gateway rather than to one router's physical interface address.

The routers still need unique real addresses for management and protocol communication. The virtual address must belong to the host subnet and must not conflict with another endpoint.

Roles and election

First-hop protocols elect forwarding and standby roles using priority and tie- breaking rules. Preemption, when configured and supported, lets a higher-priority router retake the active role after returning. Without it, a healthy current active device may remain active. Tracking can lower priority or change behavior when an upstream path fails, avoiding a gateway that is alive locally but cannot forward onward.

The CCNA objective emphasizes purpose, functions, and concepts rather than one vendor-specific command set. Focus on virtual identity, role selection, hello and failure detection, and failover.

Failure scope

First-hop redundancy protects the gateway role on one LAN. It does not repair a failed access switch, missing VLAN, broken host, absent upstream route, or failed application. Redundant gateway devices should connect through a topology whose Layer 2 and upstream paths are also resilient.

Worked scenario

Hosts use 192.0.2.1 as their gateway. R1 and R2 each have unique subnet addresses and participate in a first-hop group whose virtual IP is .1. R1 is active. When R1 fails, R2 assumes the virtual identity and hosts keep their same configuration. If R2 lacks a return route upstream, gateway failover succeeds locally but applications still fail.

Verification evidence

Inspect group, virtual IP, local role, peer state, priority, preemption, timers, and tracked objects. Confirm hosts resolve the virtual identity. In an authorized lab, test device or tracked-path failure and measure convergence, then verify recovery and role behavior.

Common traps

Readiness checklist

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free