Industrial networking-Design Review: VRRP + PRP Hybrid Architecture

Hi Experts,

I'm validating a hybrid design combining L3 gateway redundancy (VRRP router-on-a-stick) with IEC 62439-3 PRP. Would appreciate your critique on standards alignment and latent failure modes.

### Proposed Architecture
* **Core Gateway:** Dual routers running router-on-a-stick with per-vlan VRRP (unique Virtual IP/VMAC per substation VLAN).
* **PRP Integration:** R909 RedBoxes interfacing core routers into parallel LAN-A / LAN-B infrastructure.
* **Topology Path:** Core Routers ↔ RedBoxes ↔ Aggregation Switches (A & B) ↔ 10 Substation Downstreams.
* **VLAN Strategy:**
* Field/Client VLANs: Unique per substation (VLAN 1–10).
* Management VLAN: Common `VLAN 555` stretched across all 10 substations.
* Trunk Policy: All trunks unpruned end-to-end.

### Key Questions for Review
1. Does terminating VRRP gateway virtual IPs on a router-on-a-stick fed via RedBox interlinks comply cleanly with standard PRP integration patterns?
2. Do you see stability or security risks with unpruned trunks across all downstream aggregation links?
3. Are there regulatory/security (IEC 62443) or operational red flags with stretching a common management `VLAN 555` across 10 discrete substations?]

Zoo365_0-1789651194746.png
 
Top