Wanguard 6.2 User Guide
Appendix 4 – Network Integration Guideline for Wanguard Filter
•
in order to assure normal routing between these two VRF’s, MPBGP have to be activated on “
the
router
”; no MPBGP neighbor have to be defined
•
on VRF’s definitions special policies for import/export Route-Targets(RT) have to be defined in the
following manner:
▪
e.g. mark outside routes with RT 65000:100 and inside routes RT 65000:200
▪
on
VRF-outside
:
•
import the routes having outside-RT(e.g. 65000:100) and also inside-RT(e.g. 65000:200)
•
export routes with outside-RT – excepting the redirect/diversion routes
▪
on
VRF-inside:
•
import the routes having inside-RT and specific routes having outside-RT: the default-route
and/or all other outside routes excepting the routes for diversion learned from
Filter
•
export routes with inside-RT
In this way, the inside routing table will not know about the /32 redirect prefix and will forward/route traffic
normally.
For a better understanding please refer to
Figure-6
and configuration on “
router
” using Cisco-CLI as
example:
Figure-6.
Logical Diagram Layer 3 Forwarding using VRF-Lite (
*
same steps as per Fig.1
)
- 124 -
Summary of Contents for wanguard 6.2
Page 1: ......