cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
323
Views
0
Helpful
2
Replies

Bridging a WAN and a LAN interface and using VRFs

nsheridan
Level 1
Level 1

Say I have a router with an Internal Company WAN, and a Internal Company LAN interfaces - these are associated with VRF "internal". I also have and External Internet WAN and an External Internet LAN interfaces associated with VRF "internet".

Is there any way I can get the two interfaces associated with the "internet" VRF to pass traffic from WAN to LAN transparently, and thereby enabling me to avoid configuring an IP address on either interface and hence reducing security exposure? I would rather not use ACLs or access-classes and route but pass internet traffic straight trough to an internal firewall, essentially by bridging the two interfaces.

Thanks in advance, Nik.

2 Replies 2

royalblues
Level 10
Level 10

You cannot have 2 VRFs associated with a single interface.

What you can do is probably leak a default route for the internet on the internal VRF or import the route-targets as necessary

HTH

Narayan

Sorry - I meant say i have a pair of interfaces, one pair assigned to VRF "internet" and another pair "internal". I want to get the internet interfaces to pass layer 2.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card