03-25-2011 04:12 AM - edited 03-04-2019 11:52 AM
Hi,
I wonder if someone could help me here.
If I have multiple VRFs defined on a switch that extend to respective context on the Firewall. I have following questions regarding this setup
1. How can I access one VRF from another if they have overlapping subnet e.g VRF_A and VRF_B both using 192.168.1.0/24 subnet?
2. If they have diferent subnets then I can use Route target Import/Export?
3. Does Import/Exprot work between VRFs on same switch?
4. Is there is a way to control what services can be accessed between VRF if using RT import/export?
Rgds,
Solved! Go to Solution.
03-25-2011 08:47 AM
Could you not use a spare interface or use subinterfaces to keep the inter-vrf traffic from going to the outside of the contexts ?
Jon
03-25-2011 06:21 AM
Muahmmad
If the firewall is responsible for routing the vrfs which it sounds like it is then i would do all control on the firewalls.
You say you want to limit the services between vrfs, if this is the case then the firewall would be the logical place to do it rather then importing/exporting routes on the switch.
As for the overlapping subnets you can use NAT on your firewall to present the networks as unique to each other.
Jon
03-25-2011 07:04 AM
Thanks Jon.
I suppose that would mean going out one FW context and coming back in to the other Context? My only concern would be inter VRF traffic gets exposed to the public side of the FW context?
Rgds
03-25-2011 08:47 AM
Could you not use a spare interface or use subinterfaces to keep the inter-vrf traffic from going to the outside of the contexts ?
Jon
03-25-2011 09:26 AM
Thanks Jon. Very helpful.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide