[c-nsp] VRF & Hairpin Routing?
Bruce Pinsky
bep at whack.org
Thu Apr 6 15:09:11 EDT 2006
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Sean Watkins wrote:
> Hi,
>
> Is there anyway one can use a VRF to hairpin route some traffic in and out
> of a router on fast ethernet interfaces?
>
> I have got what I believe a good config, but IOS doesn't like to see a
> packet from itself going to itself?
>
> Here is important snippits of my config
>
>
> ip vrf Customers
> rd 1:1
> !
> ip cef
>
> interface FastEthernet0/0.11
> encapsulation dot1Q 11
> ip vrf forwarding Customers
> ip address 10.10.1.2 255.255.255.0
> no snmp trap link-status
> !
>
> interface FastEthernet0/1.10
> encapsulation dot1Q 10
> ip address 10.10.1.1 255.255.255.0
> no snmp trap link-status
> !
> interface FastEthernet0/1.12
> encapsulation dot1Q 12
> ip vrf forwarding Customers
> ip address 10.12.1.1 255.255.255.0
> no snmp trap link-status
> !
>
> ip route vrf Customers 0.0.0.0 0.0.0.0 10.10.1.1
>
>
>
> Vlans 10 & 11 are connected together in an upstream switch via a crossover
> cable.
>
>
> I get these error messages on debug arp;
>
>
> 1d00h: IP ARP: sent req src 10.10.1.1 0003.fdcb.ec06,
> dst 10.10.1.2 0000.0000.0000 FastEthernet0/1.10
>
> 1d00h: IP ARP req filtered src 10.10.1.1 0003.fdcb.ec06, dst 10.10.1.2
> 0000.0000.0000 it's our address
>
>
>
> Any ideas?
>
Why are you trying to do this? What's the objective?
- --
=========
bep
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFENWdXE1XcgMgrtyYRAgoXAKDvuSSlMrzlN22tkMgM87fUfzHSQwCdFKJ2
f1H67SLimXsosFIxljMHWLc=
=phgB
-----END PGP SIGNATURE-----
More information about the cisco-nsp
mailing list