12-05-2018 03:03 PM
I have a 3850 L3 core switch with VLANs in three different routing domains (global, vrf Inside and vrf DMZ). My DNS servers and other resources are in global VLANs. Hosts in each of the two vrf's need to be able to connect to DNS servers in a global VLAN.
Having difficulty finding a clear example of how leaking of routes can be accomplished with the above scenario.
Here's my basic configuration:
ip vrf DMZ
!
ip vrf Inside
!
interface Vlan6
description Inside VLAN
ip vrf forwarding Inside
ip address 10.6.1.1 255.255.255.0
end
!
interface Vlan7
description DMZ VLAN
ip vrf forwarding DMZ
ip address 10.7.1.1 255.255.255.0
end
!
interface Vlan10
description DNS Server VLAN
ip address 10.10.1.1 255.255.255.0
end
!
DNS server host in VLAN 10: 10.10.1.5
Using static routes, how can I allow all hosts in vrf VLANs 6 & 7 access to a DNS server in VLAN 10 with IP address 10.10.1.5 ?
Thank you!!
Solved! Go to Solution.
12-05-2018 04:25 PM - edited 12-06-2018 07:15 AM
Hello
@2ndcongress wrote:
Using static routes, how can I allow all hosts in vrf VLANs 6 & 7 access to a DNS server in VLAN 10 with IP address 10.10.1.5 ?
You need to tell the rtr/switch how to reach each vrf subnet which reside in their own route vrf route table and tell the vrf subnets how to reach vlan 10 which resides in the global route table.
so try adding:
ip route 10.6.1.0 255,255.255.0 vlan 6
ip route 10.7.1.0 255,255.255.0 vlan 7
ip route vrf inside 10.10.1.0 255.255.255.0 vlan 10 10.1.5 global
ip route vrf DMZ 10.10.1.0 255.255.255.0 vlan 10 10.1.5 global
12-05-2018 04:25 PM - edited 12-06-2018 07:15 AM
Hello
@2ndcongress wrote:
Using static routes, how can I allow all hosts in vrf VLANs 6 & 7 access to a DNS server in VLAN 10 with IP address 10.10.1.5 ?
You need to tell the rtr/switch how to reach each vrf subnet which reside in their own route vrf route table and tell the vrf subnets how to reach vlan 10 which resides in the global route table.
so try adding:
ip route 10.6.1.0 255,255.255.0 vlan 6
ip route 10.7.1.0 255,255.255.0 vlan 7
ip route vrf inside 10.10.1.0 255.255.255.0 vlan 10 10.1.5 global
ip route vrf DMZ 10.10.1.0 255.255.255.0 vlan 10 10.1.5 global
12-06-2018 03:09 PM
That worked beautifully, thank you very much!
12-06-2018 03:33 PM
12-05-2018 10:20 PM
12-06-2018 03:29 PM
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: