@techreport{cassen-vrrp-auth-hmac-01, number = {draft-cassen-vrrp-auth-hmac-01}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-cassen-vrrp-auth-hmac/01/}, author = {Alexandre Cassen and Quentin Armitage}, title = {{An HMAC Authentication Extension for the Virtual Router Redundancy Protocol (VRRP)}}, pagetotal = 18, year = 2026, month = jul, day = 27, abstract = {VRRP relies on a hop limit of 255 to prove that an advertisement came from the local link. That guard cannot apply when advertisements travel as multi-hop unicast across a routed or overlay network, as is common in cloud deployments, leaving the protocol open to off-segment injection and replay. The legacy VRRPv2 authentication types do not close this gap and were removed from later VRRP specifications. This document defines an authentication extension that appends an HMAC- SHA256 trailer and a time-based sequence number to VRRPv3 advertisements, authenticating the sender as a holder of the group key, protecting message integrity and bounding replay, for both IP address families. The extension is the primary defense where the hop-limit check cannot apply, and defense in depth for multicast and single-hop unicast, where that check remains in force.}, }