Hello @arcanain ,
I would expect egress VRF ID = 0 to mean global routing table
I would expect a non zero value to be seen if the incoming interface belongs to a VRF and that number to be related to the VRF in some way.
We configure VRF by using a name, it is also possible to assign a VPN id or it is assigned automatically this should be the value used to fill the netflow fields we are talking aboutl.
>> And what's the value if some flowspecks tells router to drop the packet or blackhole it somehow? Will it have some "invalid" value set in vfr id?
I do not follow you on this if the packets of the flow are silenty discarded the exit interface is null0 and so yo should see the SNMP ifindex of null0 in the field exit interface.
VRF ID should still stay at zero .
Hope to help
Giuseppe