Management VRFs

Virtual routing and forwarding (VRF) allows routers to maintain multiple routing tables and forwarding tables on the same router. A management VRF can be configured to control the flow of management traffic as described in this section.

A management VRF is used to provide secure management access to the device by sending inbound and outbound management traffic through the VRF specified as a global management VRF and through the out-of-band management port, thereby isolating management traffic from the network data traffic.

Note: Management VRF is not supported on ICX 8100 devices.

By default, the inbound traffic is unaware of VRF and allows incoming packets from any VRF, including the default VRF. Outbound traffic is sent only through the default VRF. The default VRF consists of an out-of-band management port and all the LP ports that do not belong to any other VRFs.

Any VRF, except the default VRF, can be configured as a management VRF. When a management VRF is configured, the management traffic is allowed through the ports belonging to the specified VRF and the out-of-band management port. The management traffic through the ports belonging to the other VRFs and the default VRF are dropped, and the rejection statistics are incremented.

If the management VRF is not configured, the management applications follows default behavior. The management VRF is configured the same way for IPv4 and IPv6 management traffic.

Note: For information on configuring Multi-VRF, sometimes called VRF-Lite or Multi-VRF CE, refer to the RUCKUS FastIron Layer 3 Routing Configuration Guide.

The management VRF is supported by the following management applications:

  • SNMP server
  • SNMP trap generator
  • Telnet server
  • SSH server
  • Telnet client
  • RADIUS client
  • TACACS+ client
  • TFTP
  • SCP
  • Syslog
Note: Tap interface IP address gets displayed instead of interface IP address when telnet or SSH or web or SNMP session runs over the management VRF forwarded port. For example, if you are initiating a SSH session from an IPv4 or IPv6 address over management VRF, the syslog message and the show ip ssh command displays 220.1.1.x or ee00 accordingly.
Note: Any ping or traceroute commands use the VRF specified in the command or the default VRF if no VRF is specified.