No video

How VRFs Work (VRF Lite) | VRFs Part 1

How VRFs Work (VRF Lite) | VRFs Part 1
VRFs, or Virtual Routing and Forwarding, are virtual routing tables. They enable separation of one part of the network from another.
There could be many reasons to do this. It could be for security, to separate the inside network from the DMZ. Or, it could be to separate BU's, or separate customers from each other.
This video explains VRF basics, what they are used for, when they are used, and how they work.
This includes two labs you can follow along with.
The first lab starts at the beginning and shows basic VRF configuration to separate two customers.
The second lab shows how you can use VRFs to force traffic through a firewall for security purposes.
You can download the labs, and practice on your own if you want (Patreon).
networkdirecti...
Part 1: VRF Lite - The Fundamentals of how VRF's work. This covers route separation, why you need it, and how it's configured
• How VRFs Work (VRF Lit...
Part 2: Dynamic Routing - Taking it a step further, we see how to add OSPF, EIGRP, and BGP routing, all while keeping it VRF-aware
• Dynamic Routing with V...
Part 3: Route Targets - VRF's are local to each router. But, we can use route-targets and MP-BGP to share routes between VRF's on different routers. The ed result? VRF's are spanned across your network!
• Route Target Import an...
Part 4: Route Leaking - VRF's keep routes separate, but what if you have some important services to share? How do you share the routes then? With Route Leaking!
• Leak Routes Between VRF's
For more information, have a look at networkdirecti...
/ networkdirection
/ netwrkdirection
/ networkdirection

Пікірлер: 123

  • @patriceboccara
    @patriceboccara2 жыл бұрын

    the first video where vrf is cleary explained... thanx

  • @NetworkDirection

    @NetworkDirection

    2 жыл бұрын

    Thankyou! I also found it hard to find a clear explanation (which is why I tried to make one)

  • @functiongarage
    @functiongarage4 жыл бұрын

    This is really solid bud. Been doing this stuff for 10+ years. Showed this to some entry level guys on my team and they picked it up instantly. Great work!

  • @NetworkDirection

    @NetworkDirection

    4 жыл бұрын

    Thanks Rougewolf! I am really glad you have been able to find the videos beneficial! Have a great day.

  • @MrGuitarSmoker

    @MrGuitarSmoker

    4 жыл бұрын

    Hello ! I can only confirm since i'm a entry level network engineer who never heard about VRFs and your video explained it very well ! I got it now ;) Thanks buddy !

  • @TheQadri92
    @TheQadri923 жыл бұрын

    Beautifully explained

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    Thanks

  • @clanIRG
    @clanIRG2 ай бұрын

    very easy explanation from the beginning to the end. New subscriber!

  • @zeeesh9806
    @zeeesh98062 жыл бұрын

    I love the way how you keep it simple and short! Thank you very much for the great content :)

  • @NetworkDirection

    @NetworkDirection

    2 жыл бұрын

    Thanks for the feedback

  • @LuisReyes-mw3jo
    @LuisReyes-mw3jo3 жыл бұрын

    Thank you for sharing. Simple explanation of a complex subject. Great work.

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    Glad you like it, thanks for the feedback

  • @narinderpalsingh4769
    @narinderpalsingh47695 жыл бұрын

    Thanks for this video, now i feel more confident on VRF's.

  • @techno_ocean1938
    @techno_ocean19386 жыл бұрын

    You are great bro, first time I found great explanation to this topic, we need more videos series for other network topics

  • @NetworkDirection

    @NetworkDirection

    6 жыл бұрын

    Thanks Techno Ocean. Working through a GRE series right now. Considering a DMVPN series in the near future.

  • @hussainsyed2161

    @hussainsyed2161

    5 жыл бұрын

    Never understood this before hitting here God bless you sir

  • @AxRic
    @AxRic3 жыл бұрын

    I'm amazed how easy looks the concept after your explanation. Kudos for this great content.

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    Thanks!

  • @mikgruff
    @mikgruff3 жыл бұрын

    excellent!! Just what I was looking for. Thanks for your time.

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    Glad to help!

  • @rlopez3188
    @rlopez31883 жыл бұрын

    You’re the best!!!!! Thanks for the knowledge dump!

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    You're welcome!

  • @GoodGameOKC1
    @GoodGameOKC15 жыл бұрын

    Nice video, glad to have found this channel. Thanks for sharing.

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    Glad to help

  • @nachogon9302
    @nachogon93024 жыл бұрын

    Great explanation!

  • @NetworkDirection

    @NetworkDirection

    4 жыл бұрын

    Thanks!

  • @James-op5hb
    @James-op5hb3 жыл бұрын

    The Videos are great for refreshing one's knowledge, top.

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    Glad you like it

  • @fredd164
    @fredd1644 жыл бұрын

    great video. lots of work put into this to make it easily digestible

  • @dustcore
    @dustcore Жыл бұрын

    Great explanation. Thank you

  • @VandersonT_
    @VandersonT_5 жыл бұрын

    Amazing job! You guys rock!!

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    Thanks mate!

  • @xdarkryujinx
    @xdarkryujinx3 жыл бұрын

    I'm literally configuring this right now except with Cisco 3850s and clustered as sRX345 that need to route back for nat. Thank you for this! It's wonky for sure but a work around I had to do due to vendor compliance.

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    Glad this is helping! I also use SRX345's. They use the term 'routing-instance'. The 'virtual router' type is most similar to Cisco's VRF-Lite, as discussed in this video networkdirection.net/articles/routingandswitching/juniper-routers-and-switches/juniper-routing-instances/

  • @zorlac72
    @zorlac725 жыл бұрын

    Amazing! Simple and clear explanation. Thank you!

  • @Jota_VA
    @Jota_VA4 жыл бұрын

    Great videos, thank you very much!

  • @NetworkDirection

    @NetworkDirection

    4 жыл бұрын

    You're welcome!

  • @shahadatanwar4109
    @shahadatanwar41092 жыл бұрын

    great explanation thanks

  • @NetworkDirection

    @NetworkDirection

    2 жыл бұрын

    Glad you liked it

  • @tonyhoy4688
    @tonyhoy46882 жыл бұрын

    Nice one. Keep up the good work.

  • @NetworkDirection

    @NetworkDirection

    2 жыл бұрын

    Thanks!

  • @DarkbaseTTV
    @DarkbaseTTV6 жыл бұрын

    Awesome video, once again! I also really enjoy how you run into errors on purpose, because that's likely what someone configuring VRFs for the first time would run into. But a little sad that it's only available on an enterprise service license level in IOS, if you run another license level on your L3 device, you won't be able to use VRFs. :(

  • @NetworkDirection

    @NetworkDirection

    6 жыл бұрын

    Thanks again 😀 Some platforms (like the N5k I think) allow VRF lite on a lower license, and full VRF on a higher license

  • @DarkbaseTTV

    @DarkbaseTTV

    6 жыл бұрын

    Roman Matys This is not a lab issue, but a real life enterprise issue for me :P

  • @relaxationinnature4608
    @relaxationinnature46083 жыл бұрын

    ** GREAT WORK ------ THANKS FOR SHARING ------- CHEERS PEOPLE ! **

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    Glad you like it!

  • @shehabeldinalabyad787
    @shehabeldinalabyad7873 жыл бұрын

    Very Helpful. Thank you

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    Glad it was helpful!

  • @chaotikpie1881
    @chaotikpie18814 жыл бұрын

    Fantastic mate

  • @HimanshuSharma1981
    @HimanshuSharma19813 жыл бұрын

    Awesome explanation!

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    Thanks!

  • @Mandolorian84
    @Mandolorian84 Жыл бұрын

    thank you! amazing video!

  • @siminwen4580
    @siminwen45805 жыл бұрын

    help a lot, Thanks for sharing

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    Happy to help! Glad you're getting some value from the videos!

  • @dupajasiu920
    @dupajasiu9205 жыл бұрын

    absolutely fantastic Teacher !

  • @sportsboy5935
    @sportsboy59356 жыл бұрын

    how u make it so easy to understand :) well done

  • @NetworkDirection

    @NetworkDirection

    6 жыл бұрын

    Hours of writing and rewriting the script :) Thanks for watching

  • @luigui.a7907
    @luigui.a79075 жыл бұрын

    Superuseful video !

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    That's good to hear, thanks!

  • @alenbilic
    @alenbilic4 жыл бұрын

    Great work on these vids. would be awesome to see some more vids in relation to routing and switching

  • @NetworkDirection

    @NetworkDirection

    4 жыл бұрын

    Hi Alenbilic, thanks for the suggestion. Is there anything specific that you are after?

  • @alenbilic

    @alenbilic

    4 жыл бұрын

    @@NetworkDirection im the middle of studying for my CCNP route switch. so detailed info on the layer 2 and 3 technologies and also some vids in regards to the TSHOOT exam. e.g troubleshooting scenarios, would be awesome

  • @paulzapodeanu9407
    @paulzapodeanu94074 жыл бұрын

    Vrf commands can be cumbersome to work with, so on some platforms there is a command that can help out a lot: #routing-context vrf CustA and then you can use the regular commands. Much easier!

  • @NetworkDirection

    @NetworkDirection

    4 жыл бұрын

    I didn't know about that shortcut, thanks!

  • @tusharnaik4710
    @tusharnaik47106 жыл бұрын

    Nice Video.....appreciated

  • @philipbadhams5139
    @philipbadhams5139 Жыл бұрын

    Do you not need to configure a route distinguisher when you create the VRF?

  • @Blueadi1
    @Blueadi15 жыл бұрын

    Very nice video...helps a lot...keep it coming :)

  • @Bilal.Al-Sardar
    @Bilal.Al-Sardar Жыл бұрын

    Great video and right to the point!. i have a scenario where i want to use 1 VRF and leak 1 route to the global table, is it possible?.

  • @TheJerseyJohn
    @TheJerseyJohn5 жыл бұрын

    Thanks man.. Good sub!

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    You're very welcome!

  • @CanecaProductions
    @CanecaProductions4 жыл бұрын

    Subbed!!!

  • @Johanneslol11
    @Johanneslol115 жыл бұрын

    amazing vid !

  • @aadishbahati188
    @aadishbahati1886 жыл бұрын

    awesome!

  • @NetworkDirection

    @NetworkDirection

    6 жыл бұрын

    Thanks!

  • @igorlifanov8333
    @igorlifanov83333 жыл бұрын

    how come adding the router will allow hosts from different VLANs to communicate with each other? (without additional config. like a router on a stick.)

  • @NetworkDirection

    @NetworkDirection

    3 жыл бұрын

    Generally they will have an IP address in each of those VLANs, and will be able to pass packets from one to the other

  • @Buildingmachines
    @Buildingmachines Жыл бұрын

    I want to install an SOHO network please I need guidelines on how to do it

  • @rarab8714
    @rarab87145 жыл бұрын

    very good

  • @premarajagopalan8610
    @premarajagopalan86102 жыл бұрын

    Concept well explained.Ty. What is the difference btn vrf and vrf-lite.Need to know how both works and their respective configuration as well.

  • @NetworkDirection

    @NetworkDirection

    2 жыл бұрын

    Part 4 will explain this better, but in short, VRF uses MPLS or similar technology to share informatio with other routers. VRF-Lite does not.

  • @vincekimcostales6658
    @vincekimcostales66582 жыл бұрын

    How to do static route with VRF in Cisco iOS ?

  • @SanDiegoSalesAcademycom
    @SanDiegoSalesAcademycom2 жыл бұрын

    Good

  • @NetworkDirection

    @NetworkDirection

    2 жыл бұрын

    Thanks

  • @youtubeaccountid489
    @youtubeaccountid489 Жыл бұрын

    Good🎉

  • @angelaiacob4955
    @angelaiacob49555 жыл бұрын

    I couldnt understand gi 0/3 sub interface, as per your diagrams there are .9 and .13 interface towards firewall and not .3 interface ..?

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    Looking at 9:58, it is .13, not .3 Is that the part you mean, or is there somewhere else I'm missing?

  • @landro3552
    @landro35525 жыл бұрын

    Hey man. I've done the 9 Network fundamental videos. This video makes very little sense to me.I don't really understand the concepts and purpose here. Could you give me some info about it and what I should learn now. (cuz this is too advanced for me) I appreciate your job man keep up.

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    Yeah, the VRF videos are going to be a bit more advanced than the fundamental ones. I would suggest looking at reading up on CCENT or CCNA to fill in a few gaps before moving into the deeper topics.

  • @bernardgarrett3897

    @bernardgarrett3897

    3 жыл бұрын

    Nice ansswer

  • @mymediapc9521
    @mymediapc95216 жыл бұрын

    Thank you for the video, much appreciated. You mention the global routing table can still be used even with the VRF tables, is there a common instance where you would want to use both?

  • @NetworkDirection

    @NetworkDirection

    6 жыл бұрын

    In one case, I use the global routing table to carry infrastructure routes. How to get from one environment to another, that sort of thing Then I use VRFs for the tenant traffic. That was a good question!

  • @techno_ocean1938

    @techno_ocean1938

    6 жыл бұрын

    @@NetworkDirection can you explain with more easier scenario?

  • @NetworkDirection

    @NetworkDirection

    6 жыл бұрын

    On using the global routing table with VRF's? Sure. I like to use the global routing table for infrastructure. If I have a few routers, I will connect them and get BGP (or some routing protocol) working in the global routing table. Then a customer comes along. I don't want them knowing about all my routes. I just want to help them move packets around while keeping my infrastructure secure. That's when I would create a VRF. Customers will have their own routes, and they will all go in the VRF. Extra customers get their own VRF's too. As you get to part 3 of this series, this will probably make more sense.

  • @igorlifanov8333
    @igorlifanov83333 жыл бұрын

    he is pinging (ping vrf custB 10.20.0.1) unsuccessfully. How it could be successful; he did not define the route to 10.20.0.0 for custB vrf?

  • @prasadpardeshi2231
    @prasadpardeshi22314 жыл бұрын

    Thnxxxxxxxxxxx!!!!!

  • @Brian-nz6ns
    @Brian-nz6ns4 жыл бұрын

    I've never heard of VRF's before. Is this new? What products support this feature? How do we know if a certain product supports this feature?

  • @memyselfimemyselfi496

    @memyselfimemyselfi496

    4 жыл бұрын

    I had the same question. Please answer!!!!!!!!!

  • @tusharnaik4710
    @tusharnaik47106 жыл бұрын

    is it possible for you two create video scenerio like:- one router with two ISP and router runnning two routing protocol rip and osp.rip for acitve and ospf for standby

  • @NetworkDirection

    @NetworkDirection

    6 жыл бұрын

    In part 2, I'll show you how to configure dynamic routing (OSPF and EIGRP) with VRF's, which might be similar to what you're asking for. I'm not sure how you would use RIP for active and OSPF for secondary though. For dual-ISP, I would use BGP

  • @tusharnaik4710

    @tusharnaik4710

    6 жыл бұрын

    yes but i have seen such senerio..customer having one router with two isp one nomal and 2ndar 3g cellular link..abd only ospf and rip config are there..i can share you config if you provide me email....nowa days i am too much confuse about this

  • @NetworkDirection

    @NetworkDirection

    6 жыл бұрын

    Sure, send it through. My details are on the website.

  • @Leonhart1982
    @Leonhart19825 жыл бұрын

    Amazing Explanation about VRF. Great work bro !!! How can the overlapping ip subnet 10.10.0.0/24 exchange between them ? what is the feature in the FW that can allow it ?

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    The only way to have overlapping subnets communicate with each other is by sending the traffic to an L3 device (router or firewall), where there is no VRF, or the traffic is in the same VRF. This device then needs to use NAT to make the networks appear unique. It's a complicated scenario, so avoid it if you can

  • @ithereos9554

    @ithereos9554

    4 жыл бұрын

    @@NetworkDirection It does sound complicated, is it something you'd usually see in real networks? Why would companies do that besides bad design?

  • @NetworkDirection

    @NetworkDirection

    4 жыл бұрын

    @@ithereos9554 I've done it myself in some cases. I've used it when working for a cloud provider. We had different customers connected through WAN links. We couldn't control their IP space, and they couldn't control ours. So in a case like this, we can use NAT. However, if you have control, use unique subnets to avoid using NAT.

  • @surb0nt

    @surb0nt

    3 жыл бұрын

    @@ithereos9554 Service Providers use this to divide customer overlapping 10/8 rfc1918 networks. And customers can communicate over Service Provider MPLS network separately. You can do this always when you have many customers and you need to separate them into domains.

  • @bhasker1999
    @bhasker19995 жыл бұрын

    How come Core1 router ports(.1 and .5) are in the same network, Aren't they suppose to be on different network ?

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    They are in different networks. They are /30's

  • @bhasker1999

    @bhasker1999

    5 жыл бұрын

    @@NetworkDirection yes yes, thank you .will need to refresh my subnetting..thanks again.

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    No worries, glad to help. I have some IP addressing and subnetting videos coming in about two weeks if you're interested

  • @bhasker1999

    @bhasker1999

    5 жыл бұрын

    @@NetworkDirection that would be great..subscribe and enabled notification..

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    Good to hear 😀

  • @bumpthecrypto3059
    @bumpthecrypto30594 жыл бұрын

    Are custa and b 10.10.0.0 networks on different interface and if so are they sub interfaces?

  • @NetworkDirection

    @NetworkDirection

    4 жыл бұрын

    The 10.0.0.0 network are on different routers. Is that what you mean?

  • @Pete_H312
    @Pete_H3125 жыл бұрын

    Why does the vrf definition command not work on my IOS? I have to use # IP VRF CustA on my router. Also, ADDRESS-FAMILY IPV4 command not recognised in vrf configuration mode. What IOS are you using?

  • @NetworkDirection

    @NetworkDirection

    5 жыл бұрын

    Have you tried downloading the labs from the site?

  • @ThuyThanh-nz1ez
    @ThuyThanh-nz1ez2 жыл бұрын

    how did you do it can you share with me , thank you

  • @NetworkDirection

    @NetworkDirection

    2 жыл бұрын

    How did I create the VRF do you mean?

  • @sepbla178
    @sepbla1784 жыл бұрын

    I don't get your explanation at all. You show some topology with IPs, when you configure the routes in the vRFs they are all differents. :| I'm totally confused by this video.

  • @NetworkDirection
    @NetworkDirection6 жыл бұрын

    Here's the lab files (Patreon): networkdirection.net/VRF+Lab+1

  • @DemonKamikaze

    @DemonKamikaze

    6 жыл бұрын

    Really nice video! built something like this for my employer a couple of years ago, now spans multiple VRFs for internal divisions and individual business clients we process data for, inter VRF routing is accomplished with OSPF :)

  • @NetworkDirection

    @NetworkDirection

    6 жыл бұрын

    It works really well doesn't it? Rock solid

  • @abdellahchadid7382
    @abdellahchadid7382 Жыл бұрын

    It's 2023 and you still charge in order to view some firewall configuration!!. Make it free man.. specially your old labs. 6$ for some firewall config🦂