Solved

Cisco VRF

Posted on 2013-06-18
9
528 Views
Last Modified: 2013-07-13
Greetings,

I have a Cisco router (c1921) that travels around the country and plugs into different networks (hotels, convention centers, etc..).  

We of course have issues when the DHCP WAN IP address we receive from the venue conflicts with the LAN networks.

We are thinking of using VRF to fix this issue.

I am looking for a good sample configuration with the WAN interface on the router is getting an IP address via DHCP (mostly private 172.16.x.x, 192.168.x.x and 10.x.x.x networks), and the LAN has multiple subinterfaces for dot1q VLANs.

I do have a Cisco EZVPN that connects to our datacenter, so this would still need to work.

Thank you!

David
0
Comment
Question by:chikagoh
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
9 Comments
 
LVL 46

Expert Comment

by:Craig Beck
ID: 39256736
How are you thinking of fixing this with VRF?
0
 
LVL 20

Expert Comment

by:rauenpc
ID: 39257145
http://blog.ine.com/2008/06/15/easy-vpn-combined-with-vrf-lite-2/

The above is a good example of ezvpn with vrf.

The only other piece to the puzzle would be to configure the outside interface with dhcp in the global routing table (with no vrf specified) and to apply the ezvpn vrf to the inside interface.
0
 

Author Comment

by:chikagoh
ID: 39257168
Craigbeck, With vrf you can have duplicate ip networks in different routing instances correct?
0
Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

 
LVL 46

Expert Comment

by:Craig Beck
ID: 39257175
But if you've only got one WAN link, with one IP address, how will VRF help?

Can you expand on what exactly you want to achieve using VRF?
0
 
LVL 46

Expert Comment

by:Craig Beck
ID: 39257184
Yes you can have duplicate IP addresses in different VRFs, BUT if you only have one WAN address, what will VRF do for you?
0
 

Author Comment

by:chikagoh
ID: 39257196
Craigbeck. I just don't want my wan(dhcp) to conflict with any of my LAN sub interfaces
0
 
LVL 46

Expert Comment

by:Craig Beck
ID: 39257198
What I'm getting at is (as an example):

You have a single WAN link with IP 192.168.0.1/24
You have a LAN using IP range 192.168.0.0/16

How will VRF help to overcome this??

Maybe there's something missing from the OP, but are you suggesting that the LAN needs to route to a central office via EZ-VPN (therefore effectively bypassing the WAN routing)?

If so, rauenpc's example is what you need.  If not, VRF won't help.
0
 

Author Comment

by:chikagoh
ID: 39257751
rauenpc: If the WAN interface (global routing table) gets a DHCP address that conflicts with a LAN VRF-lite interface, will there be a conflict?
0
 
LVL 46

Accepted Solution

by:
Craig Beck earned 400 total points
ID: 39257891
If your WAN is NOT configured in a VRF it won't interfere with a LAN interface which is in a VRF.

The problem there is that your LAN interface won't be able to route via the WAN interface.  The VRF membership dictates which interfaces are taking part in that routing instance.

You can configure a VPN and tie that to the VRF, and that can route via the WAN.
0

Featured Post

VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses
Course of the Month9 days, 11 hours left to enroll

623 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question