cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
358
Views
3
Helpful
4
Replies

VRF Question

N3om
Level 3
Level 3

Hi
We ahve an FTD and subnet 172.16.251.0/24 ingresses via a sub-interface in global routing then egresses via an interface in a user deifned vrf, my question is how do I route the return traffic to 172.16.251.0/24

1. Do I add a static route in the vrf pointing to the global interface for 172.16.251.0/24

2. Do I just add a static route in global pointing to the 172.16.251.0/24 network via the global interface

 

Thanks

1 Accepted Solution

Accepted Solutions

considering the ingress interface is on global routing table, and if you intend to send traffic back, it should be necessary one static route return the traffic on that interface. 

View solution in original post

4 Replies 4

M02@rt37
VIP
VIP

Hello @N3om 

You need route leaking ...

Explore this documentation please: https://www.cisco.com/c/en/us/td/docs/security/firepower/660/fdm/fptd-fdm-config-guide-660/fptd-fdm-virtual-routers.html

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

@N3om 

 This is a trick question. 

 Does it means that the ingress traffic via global routing table and egress traffic via vrf is working currently? 

 Why the return traffic is not using the same interface as ingress traffic?  

If you say "egresses via an interface in a user deifned vrf", then you might already have a routing send egress traffic to interface with vrf. 

Wondering if this is not cause assymetric routing. 

@Flavio Miranda 

 Does it means that the ingress traffic via global routing table and egress traffic via vrf is working currently?  YES

 Why the return traffic is not using the same interface as ingress traffic?  Thats the question we dont have a route to the subnet yet

considering the ingress interface is on global routing table, and if you intend to send traffic back, it should be necessary one static route return the traffic on that interface. 

Review Cisco Networking for a $25 gift card