[c-nsp] VRF, then fall through to main / global route table ?
Mark Zipp
mark.r.zipp at gmail.com
Tue Apr 11 20:43:19 EDT 2006
Hi,
I'm hoping somebody could save me some time and tell me if the
following scenario is possible using Cisco's VRF functionality. I'm
familiar with the idea of having a per-interface route table, however
in the brief review of Cisco's VRF functionality I haven't found a
quick answer. I'm keen to learn more about Cisco's VRF, although I
think it might take me a lot longer than it would to have somebody
answer it here :-)
Is it possible to have a Cisco router look at a interface specific
VRF, and then if there isn't a matching route, fall through to looking
at the main or global route table on the router ? I think it would be
useful to have a generic, customer facing VRF that null / sink routes
the various martian addresses (RFC1918 etc.), and then falls through
to the main route table for further route lookup.
We could achieve similar by putting sink routes for the martian routes
in the main table, the problem is that we are using addresses such as
RFC1918 internally, and therefore that would mean that for all traffic
entering or leaving the router those destinations would be
unreachable, rather than just for traffic that is entering customer
facing interfaces.
Customer facing ACLs would of course be an alternative, however I
think sink routes in a VRF would be a bit simpler and easier to
maintain, and would probably be slightly faster for the router to
process.
Thanks,
Mark.
More information about the cisco-nsp
mailing list