![](/images/new-backgrounds/1206105/20610511x1.webp)
Understanding
VRF-lite security domains
|
|
| vlan1 | 1. |
|
|
|
|
|
|
|
|
| |
|
| vlan2 |
|
| 1. |
|
|
|
|
|
|
|
| |
|
|
|
|
| 1. |
|
| SW |
|
|
| |||
|
| 10. |
|
|
| 1/24 |
|
|
|
|
| |||
|
|
| 1. |
|
|
|
|
|
|
|
|
|
| |
PC1 |
|
|
| 1. |
|
| .1/24 |
|
|
|
|
| ||
|
|
|
| 1/8 |
|
|
|
|
|
|
| |||
|
|
|
|
|
|
|
| .1 |
|
|
|
|
|
|
|
|
|
|
|
|
| .1 |
| .1/16 |
|
|
|
| |
|
|
|
|
|
|
| 1 |
|
|
|
|
| ||
|
|
|
|
|
|
|
| .1 |
|
|
|
|
| |
|
|
|
|
|
| vlan3 | .1 |
| vlan5 |
|
|
| ||
|
|
|
|
|
| 10 |
| 1. |
|
| ||||
|
|
|
|
|
|
| vlan4 |
|
|
|
| |||
| PC2 |
|
|
|
|
|
|
|
| vlan6 |
| 1. |
| |
Company A |
|
|
|
|
|
|
|
|
|
| 1. | |||
|
|
|
|
|
|
|
|
| 10. |
|
| 1/24 | ||
|
|
|
|
|
|
|
|
|
|
| 1. |
|
| |
|
|
|
|
|
|
|
|
|
|
|
| 1. |
|
|
| PC3 |
|
|
|
|
|
|
|
|
|
| 1/24 | ||
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
| Company B | PC4 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| PC5 |
|
|
|
|
|
|
|
| |
VRF red |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
VRF green |
| Company C |
|
|
| PC6 |
|
|
|
| ||||
VRF blue |
|
|
|
|
|
|
|
|
| |||||
|
|
|
|
|
|
|
|
|
|
|
|
|
|
For example, on a device three VRF instances (VRF red, VRF green and VRF blue) are configured for three different companies. Devices PC1 and PC2 from Company A can communicate normally within the confines of VRF red, but none of PC1’s and PC2’s traffic can be seen by other devices in VRF green and VRF blue.
Route table and interface management with VRF-lite
A key feature that
By default, before any VRF is configured, a router will have one route table, and routes via all IP interfaces of the router will be stored in this one table. As VRF instances are configured on the router, the original route table remains. This default route table, and its associated IP interfaces, are then referred to as the default global VRF domain.
Interface management with VRF
Each network interface can belong to only one VRF. As mentioned above, initially every interface is in the default global VRF domain. As Layer 3 interfaces are moved to the created VRF instances, they are removed from the global VRF domain, so the global VRF domain manages a decreasing set of Layer 3 interfaces.
Page 6 Configure