Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Filtering methods inside a VRF in MPLS VPN

Hi,

we have a network with MPLS VPN and several VRFs involved.

Inside a certain VRF I need to avoid that two particular networks can talk to each other.

Can you give me a hint of what can be a solution to implement this ?

Thanks

Regards

Marco

1 REPLY

Re: Filtering methods inside a VRF in MPLS VPN

Hi Marco,

To prevent connectivity between two networks where a MPLS VPN is involved you can apply the same methods as in a "normal" router network. Just think of the complete MPLS VPN (PE to PE) as being one big "router simulator".

You could either implement ACLs on the interfaces connecting to the PE or filter routing updates between sites - depending on your topology. When filtering routing updates seems the way to go, you should also have a look into selective import or export. With the help of a route-map one can selectively insert single networks into a VPN by selectively attaching route-targets to BGP updates.

Regards, Martin

197
Views
0
Helpful
1
Replies