cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1863
Views
0
Helpful
1
Replies

VRF Lite with vFW using ASA

john.dejesus
Level 1
Level 1

I would like to know if ASA is an VRF aware firewall. I have this scenario wherein I have multiple clients at the edge on two different sites and I want them to be separated in RT with advanced security features. So I opted to use vrf lite and vFW in ASA. See attached topology.

Problem: Two sites can see each other's routes in the RT and BGP table. But ping failed. Need help on this. See attached configs.

1 Reply 1

Vinit Jain
Cisco Employee
Cisco Employee

Hello John

As far as i recall, Cisco ASA doesn't support vrf concept. They do have multi-context features for virtualization purposes but not vrf. You can have ipsec aware vrf on the routers to solve this problem.

Thanks
--Vinit