Configuring a complex inter-VRF solution
!
ip vrf shared 5 rd 100:5
route-target import 100:1 route-target import 100:2 route-target import 100:3 route-target import 100:4 route-target export 100:5
!
ip vrf overlap 6
!
no ip multicast-routing
!
spanning-tree mode rstp
!
access-list hardware access43 permit ip any 192.168.43.0/24 access-list hardware access44 permit ip any 192.168.44.0/24 access-list hardware access45 permit ip any 192.168.45.0/24
access-list hardware allow100_deny_private permit ip any 192.168.100.0/24
deny ip any 192.168.0.0/16 access-list hardware allow_to_self_10 permit ip any 192.168.10.0/24 access-list hardware allow_to_self_20 permit ip any 192.168.20.0/24 access-list hardware allow_to_self_30 permit ip any 192.168.30.0/24 access-list hardware allow_to_self_40 permit ip any 192.168.40.0/24
!
switch 1 provision x900-24
!
vlan database
vlan 2-7 state enable
!
interface port1.0.1 switchport switchport mode access
access-group allow_to_self_10 access-group access43 access-group allow100_deny_private
!
interface port1.0.2 switchport switchport mode access switchport access vlan 2 access-group allow_to_self_20 access-group access44 access-group allow100_deny_private
!
interface port1.0.3 switchport switchport mode access switchport access vlan 3 access-group allow_to_self_30 access-group access45 access-group allow100_deny_private
!
interface port1.0.4-1.0.5 switchport
switchport mode access
Configure VRF-lite Page 59