Allied Telesis C613-16164-00 REV E manual Vlan

Page 27

Simple VRF-lite configuration examples

VRFs accessing a shared network. An example of static inter-VRF routing

The partial configuration example below shows the key components required to support static inter-VRF routing.

Two companies (VRF red and VRF green) are able to access shared vlan100. Shared vlan100 exists in the Global default VRF. Static inter-VRF routing is used in this example to facilitate inter-VRF communication. There are no overlapping IP addresses. As there is no external router in vlan100 and there is no Internet access via vlan100, ACLs are not required.

1. vlan 12

 

 

 

 

 

 

 

 

 

10.

 

 

 

 

 

100

 

 

 

1.

 

 

 

 

 

.0/24

 

 

0/24

 

Global

vlan

.100

 

 

 

 

 

 

 

 

.100

 

 

 

 

 

100

 

 

 

 

VRF

 

VRF

 

default

 

 

 

 

red

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

domain

 

 

 

 

 

 

VRF

green

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

1. vlan

 

 

 

 

 

 

 

 

20.

 

14

 

 

 

 

 

 

 

1.

 

 

 

 

 

 

 

 

0/24

- Inter VRF (IVR) communications

 

 

 

 

 

 

 

 

via static IVR routes

 

 

 

 

 

 

 

 

 

...

!

ip vrf red

!

ip vrf green

!

interface vlan12

ip vrf forwarding red ip address 1.10.1.1/24

!

interface vlan14

ip vrf forwarding green ip address 1.20.1.1/24

!

interface vlan100

ip address 100.100.100.100/24

!

ip route vrf red 0.0.0.0/0 vlan100 ip route vrf green 0.0.0.0/0 vlan100 ip route 1.10.1.0/24 vlan12

ip route 1.20.1.0/24 vlan14

!

...

Configure VRF-lite Page 27

Image 27
Contents What is VRF-lite? How To Configure VRF-lite IntroductionWhich products and software version does it apply to? Software feature licensesCommand summary Who should read this document?Contents VRF GlossaryUnderstanding VRF-lite Vlan5 VRF-lite security domainsRoute table and interface management with VRF-lite Interface management with VRFAdding a VRF-aware static ARP Route management with VRFInter-VRF communication Static and dynamic inter-VRF routing For example VRF-lite features in AW+ Ping VRF aware services includeRoute limiting per VRF instance VRF-aware utilities within AW+ Telnet client  SSH client TCP dump Awplusconfig# access-list standard Configuring VRF-liteAwplusconfig-if#switchportaccess vlanx Family Awplusconfig-route-map#match ip Ip route 192.168.50.0/24 Ip route vrf green 192.168.1.0/24 Static inter-VRF routingForwarding Information Base FIB and routing protocols Dynamic inter-VRF communication explainedBGP Inter-VRF communication via BGP Can be replaced with Using the route-target commandRoute-target import ASNVRFinstance For example Route-target both ASNVRFinstance For exampleVia BGP IVR, VRF shared will end up with the routes Also, if VRF shared configuration includesIf VRF red initially includes If VRF shared initially includesThen via BGP IVR, VRF red will end up with the routes If VRF shared configuration includes Viewing source VRF and attribute information for a prefix How VRF-lite security is maintainedMultiple VRFs without inter-VRF communication Simple VRF-lite configuration examples26 Configure VRF-lite Vlan 28 Configure VRF-lite Configure VRF-lite 30 Configure VRF-lite Configure VRF-lite 32 Configure VRF-lite Inter-VRF configuration examples with Internet access Configuration Configure VRF-lite Example B Configuration 38 Configure VRF-lite Configure VRF-lite Example C Configuration 42 Configure VRF-lite Configure VRF-lite Configuring a complex inter-VRF solution Network description Each VLANs is associated with a VRF instance VRF communication plan Configuration breakdown Configure VRF-lite Configure Vrfs Configure the hardware ACLs This example, three access groups are attached to port Within the same IP subnet that the switch port is a member192.168.43.0/24 via the shared VRF Configure Vlan Database Configure IP Addresses Configure VRF-lite Configure Dynamic Routing Configure VRF-lite 56 Configure VRF-lite Configure Static Routing Complete show run output from VRF device is below Configure VRF-lite 60 Configure VRF-lite Configure VRF-lite IP route table from VRF device is below VRF blue Hostname Internetrouter Hostname sharedrouter N1 Ospf Nssa Hostname redospfpeerHostname greeniBGPpeer Hostname bluerippeer Hostname orangerouter Hostname orangeospfpeer Grey Other features used in this configurationVCStack and VRF-lite Stack provisioningVirtual Chassis ID X610 VCStack configurationX900 configuration 74 Configure VRF-lite Port Sharing VRF routing and double tagging on the same portCommunication plan GreenConfigurations X610 aX610 B Configure VRF-lite Additional notes BGP configuration tips 80 Configure VRF-lite VRF device Red router vlan database Red router Route Limits Configuring static route limitsConfiguring Dynamic route limits Allowed number of fib routes excluding Connect and Static100 Syntax No max-fib-routesVRF-lite usage guidelines Useful VRF-related diagnostics command list GeneralRouting general Routing protocols IP prefix network, e.g TCPdump HW platform table commands