cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4576
Views
0
Helpful
4
Replies

Routing between VRFs with Overlapping subnets.

Muhammad Khan
Level 1
Level 1

Hi,

I wonder if someone could help me here.

If I have multiple VRFs defined on a switch that extend to respective context on the Firewall. I have following questions regarding this setup

1. How can I access one VRF from another if they have overlapping subnet e.g VRF_A and VRF_B both using 192.168.1.0/24 subnet?

2. If they have diferent subnets then I can use Route target Import/Export?

3. Does Import/Exprot work between VRFs on same switch?

4. Is there is a way to control what services can be accessed between VRF if using RT import/export?

Rgds,

1 Accepted Solution

Accepted Solutions

Could you not use a spare interface or use subinterfaces to keep the inter-vrf traffic from going to the outside of the contexts ?

Jon

View solution in original post

4 Replies 4

Jon Marshall
Hall of Fame
Hall of Fame

Muahmmad

If the firewall is responsible for routing the vrfs which it sounds like it is then i would do all control on the firewalls.

You say you want to limit the services between vrfs, if this is the case then the firewall would be the logical place to do it rather then importing/exporting routes on the switch.

As for the overlapping subnets you can use NAT on your firewall to present the networks as unique to each other.

Jon

Thanks Jon.

I suppose that would mean going out one FW context and coming back in to the other Context? My only concern would be inter VRF traffic gets exposed to the public side of the FW context?

Rgds

Could you not use a spare interface or use subinterfaces to keep the inter-vrf traffic from going to the outside of the contexts ?

Jon

Thanks Jon. Very helpful.

Review Cisco Networking for a $25 gift card