Cisco Support Community

VRF-aware syslogging with 2921

I typically use a VRF for management of border routers, partially for secure access via SSH/SNMP, and partially so they can send syslog traps to the syslog server without setting up firewall rules and NATs.

This works fine with a 6500, but trying to use the same configuration on a 2921 I have no luck.  Connectivity seems to be there but I see no messages going through.  TACACs is also configured to use the VRF and works just fine, so the issue is specific to syslog. 

#show run | inc vrf MGMT

ip vrf MGMT

ip route vrf MGMT

logging source-interface Port-channel1.100 vrf MGMT

logging host vrf MGMT

#ping vrf MGMT

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to, timeout is 2 seconds:


Success rate is 100 percent (5/5), round-trip min/avg/max = 4/4/8 ms

IOS version is 15.1(4)M7

Everyone's tags (4)
Community Member

VRF-aware syslogging with 2921

is it port-channel 1.100 on vrf MGMT?

if not that's the problem

it it is.... the config is good so you should try using a loopback in vrf MGMT because probably a bug is causing that problem

kind regards

CreatePlease to create content