Understanding VRF-lite

Inter-VRF communication

Whilst the prime purpose of VRF-lite is to keep routing domains separate from each other, there are cases where you do want some communication between VRFs.

An example to consider is multiple 'clients' requiring shared Internet access. In this case a VRF instance can be created for each, providing secure and separate routing. Whilst overlapping IP addresses could be used with this scenario, only one instance of each overlapping address range will be able to access the Internet for the simple reason that when return traffic comes back from the Internet to an address in one of the overlapped subnets, the VRF aware device must have only one choice for which instance of that subnet to send that return traffic to.

A distinct shared VRF is utilised to allow sharing of the Internet connection. The shared VRF is actually just another VRF instance; it has no special VRF properties.

In the example below, each of the red and green VRFs need inter-VRF communication with the shared VRF. This is achieved by selectively leaking routes between the shared VRF and the other two VRFs, and vice-versa. The selective leaking can use statically configured routes or dynamic route import/export via the BGP protocol.

 

 

 

 

 

Internet

 

 

VRF

 

VRF

 

 

 

red

 

 

 

 

(Wi-

 

shared

 

 

Fi)

 

 

 

 

 

 

Wi

-Fi

access

 

VRF

green

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

(company)

Internal Company

 

 

 

 

 

Network

 

 

 

For example, a company may wish to segregate their network and provide Wi-Fi access to the Internet for visitors to the company, whilst preventing the visitors from accessing the internal company network. The users in internal company network and visitors in the Wi-Fi network are able to share a single common Internet connection.

Internal company and Wi-Fi networks are isolated in Layer 3 on the same device by using different VRFs, but they want to access the Internet by using the same network interface on VRF shared. To make it work with dynamic route import/export, VRF green (company VRF) needs to import routes from VRF shared to access the Internet and some selected routes from VRF green need to be exported to VRF shared. Similar configuration is needed for VRF red (Wi-Fi VRF) for importing/exporting routes between VRF red and VRF shared.

As a result traffic flows between VRF green and VRF shared and between VRF red and VRF shared but not between VRF green and VRF red.

Page 8 Configure VRF-lite

Page 8
Image 8
Allied Telesis C613-16164-00 REV E manual Inter-VRF communication

C613-16164-00 REV E specifications

The Allied Telesis C613-16164-00 REV E is a robust networking device designed to enhance connectivity and communication within enterprise environments. Renowned for its reliability and efficiency, this device serves as an ideal choice for organizations seeking to improve their network infrastructure.

At its core, the C613-16164-00 REV E is a part of Allied Telesis' suite of products that adhere to high-performance standards. One of the main features is its support for both Layer 2 and Layer 3 networking, making it versatile enough to handle a variety of network configurations. This capability allows for seamless integration into different network architectures, whether for simple local area networks (LANs) or more advanced setups with routing capabilities.

Another significant characteristic of the C613-16164-00 REV E is its high-speed data transfer capabilities. With support for Gigabit Ethernet, the device ensures that data can be transmitted quickly and efficiently across the network. This is particularly important for businesses that rely on heavy data usage and need to maintain performance standards even during peak hours.

Additionally, the C613-16164-00 REV E features advanced security measures, including VLAN support and port security configurations, which help protect sensitive information and prevent unauthorized access. This is essential for businesses that handle confidential data and must comply with industry regulations.

In terms of manageability, the device supports SNMP (Simple Network Management Protocol), allowing for easy monitoring and management of network resources. Network administrators can efficiently manage the device and optimize performance with minimal effort, improving overall productivity.

The design of the C613-16164-00 REV E is also noteworthy; it is built for durability, often featuring a compact form factor that makes installation straightforward without compromising on performance. Its compatibility with various Allied Telesis products ensures that organizations can build a cohesive network ecosystem.

In conclusion, the Allied Telesis C613-16164-00 REV E stands out as an excellent networking solution characterized by its support for multiple networking layers, high-speed data transfer, and robust security features. Ideal for both small to medium enterprises and larger organizations, it helps ensure that businesses can maintain efficient and secure operations in a constantly evolving digital landscape.