09-22-2017 06:20 AM - edited 03-05-2019 09:10 AM
Does anyone know if VRF is transitive?
vrf Internet
import/export Guests
import/export Creditcards
vrf Guests
import/export Internet
vrf Creditcards
import/export Internet
Would Guests & Creditcards be able to talk to each other, through the Internet vrf?
If so, is ACL or firewall the only way to stop them from talking to each other?
TIA
09-22-2017 07:35 AM
Hi,
I have not applied that before but it could works, other way to allow the communication between VRF is with the following configuration:
vrf Guests
import/export route-target (Guest)
import route-target (Creditcards)
vrf Creditcards
import/export route-target (Creditcards)
import route-target (Guest)
Hope it is useful
:-)
09-22-2017 07:43 AM
Thank you for the quick reply, but we actually don't want Guests & Creditcards to talk to each other for security reasons.
If Guests & Creditcards don't import/export each other's RT, they should not be able to talk to each other, correct? (which is what we want)
09-22-2017 07:46 AM
That is correct, actually if they don't import the each other VRFs.
Now if you want to allow Internet access for them separately, you can keep the Internet default route on the global table.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide