Solved

Cisco VRF

Posted on 2013-06-18
9
516 Views
Last Modified: 2013-07-13
Greetings,

I have a Cisco router (c1921) that travels around the country and plugs into different networks (hotels, convention centers, etc..).  

We of course have issues when the DHCP WAN IP address we receive from the venue conflicts with the LAN networks.

We are thinking of using VRF to fix this issue.

I am looking for a good sample configuration with the WAN interface on the router is getting an IP address via DHCP (mostly private 172.16.x.x, 192.168.x.x and 10.x.x.x networks), and the LAN has multiple subinterfaces for dot1q VLANs.

I do have a Cisco EZVPN that connects to our datacenter, so this would still need to work.

Thank you!

David
0
Comment
Question by:chikagoh
  • 5
  • 3
9 Comments
 
LVL 46

Expert Comment

by:Craig Beck
ID: 39256736
How are you thinking of fixing this with VRF?
0
 
LVL 20

Expert Comment

by:rauenpc
ID: 39257145
http://blog.ine.com/2008/06/15/easy-vpn-combined-with-vrf-lite-2/

The above is a good example of ezvpn with vrf.

The only other piece to the puzzle would be to configure the outside interface with dhcp in the global routing table (with no vrf specified) and to apply the ezvpn vrf to the inside interface.
0
 

Author Comment

by:chikagoh
ID: 39257168
Craigbeck, With vrf you can have duplicate ip networks in different routing instances correct?
0
Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

 
LVL 46

Expert Comment

by:Craig Beck
ID: 39257175
But if you've only got one WAN link, with one IP address, how will VRF help?

Can you expand on what exactly you want to achieve using VRF?
0
 
LVL 46

Expert Comment

by:Craig Beck
ID: 39257184
Yes you can have duplicate IP addresses in different VRFs, BUT if you only have one WAN address, what will VRF do for you?
0
 

Author Comment

by:chikagoh
ID: 39257196
Craigbeck. I just don't want my wan(dhcp) to conflict with any of my LAN sub interfaces
0
 
LVL 46

Expert Comment

by:Craig Beck
ID: 39257198
What I'm getting at is (as an example):

You have a single WAN link with IP 192.168.0.1/24
You have a LAN using IP range 192.168.0.0/16

How will VRF help to overcome this??

Maybe there's something missing from the OP, but are you suggesting that the LAN needs to route to a central office via EZ-VPN (therefore effectively bypassing the WAN routing)?

If so, rauenpc's example is what you need.  If not, VRF won't help.
0
 

Author Comment

by:chikagoh
ID: 39257751
rauenpc: If the WAN interface (global routing table) gets a DHCP address that conflicts with a LAN VRF-lite interface, will there be a conflict?
0
 
LVL 46

Accepted Solution

by:
Craig Beck earned 400 total points
ID: 39257891
If your WAN is NOT configured in a VRF it won't interfere with a LAN interface which is in a VRF.

The problem there is that your LAN interface won't be able to route via the WAN interface.  The VRF membership dictates which interfaces are taking part in that routing instance.

You can configure a VPN and tie that to the VRF, and that can route via the WAN.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

821 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question