1. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
Protocolo deProtocolo de
Comunicaciones:Comunicaciones:
MPLSMPLS
Daniel Díaz Ataucuri
Profesor Titular de Telecomunicaciones UNI/UNMSM
Director de Investigación y Desarrollo Tecnológico del INICTEL-UNI
ddiaz1610@gmail.com/ddiaz@inictel-uni.edu.pe
2. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND
FORWARDING-VRF
3. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING
VRF
VRF
VRF
Interfaz física
o lógica
Interfaz física
o lógica
Virtual Routing and Forwarding-VRF es una técnica de virtualizar las
tablas de enrutamiento de un router con el objetivo de que un Proveedor
de Servicios de Internet-ISP separe sus clientes.
Cisco hace suyo VRF
Juniper lo denomina
“routing instances”
Linux denomina
“network namespaces”
Huawei denomina “VPN Routing”
4. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING
192.10.20.1/30
60.60.60.1/30
Fa 0/0 Fa 2/0
Fa 1/0
10.10.10.1.1/30
C 192.10.20.0 is directly connected, fastethernet0/0
C 10.10.10.0 is directly connected, fastethernet0/1
C 60.60.60.0 is directly connected, fastethernet1/0
Tabla de enrutamiento global
192.10.20.1/30
60.60.60.1/30
10.10.10.1.1/30192.70.80.1/30
192.70.80.1/30
192.70.80.1/30VRF
VRF
VRF
Tabla
VRF
Tabla
VRF
Tabla
VRF
Fa 0/0 Fa 2/0
Fa 1/0
C 192.70.80.0 is directly connected, fastethernet2/0
Tabla de enrutamiento vrf celeste
C 192.70.80.0 is directly connected, fastethernet0/0
Tabla de enrutamiento vrf rojo
C 192.70.80.0 is directly connected, fastethernet1/0
Tabla de enrutamiento vrf amarillo
Los VRF emplean esencialmente el mismo concepto que VLAN y trunking, pero en la capa tres.
5. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING
192.10.20.1/30
60.60.60.1/30
10.10.10.1.1/30192.70.80.1/30
192.70.80.1/30
192.70.80.1/30VRF
VRF
VRF
Tabla
VRF
Tabla
VRF
Tabla
VRF
Fa 0/0 Fa 2/0
Fa 1/0
C 192.70.80.0 is directly connected, fastethernet2/0
Tabla de enrutamiento vrf celeste
C 192.70.80.0 is directly connected, fastethernet0/0
Tabla de enrutamiento vrf rojo
C 192.70.80.0 is directly connected, fastethernet1/0
Tabla de enrutamiento vrf amarillo
Pasos a seguir:
Definir cada vrf
Asignar un valor Router Distinguisher-rd
Asociar las interfaces a cada vrf
http://www.redescisco.net/sitio/2017/02/15/configuracion-basica-de-vrf/
6. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_01 CISCO
192.10.20.1/30
60.60.60.1/30
10.10.10.1.1/30192.70.80.1/30
192.70.80.1/30
192.70.80.1/30VRF
VRF
VRF
Tabla
VRF
Tabla
VRF
Tabla
VRF
Fa 0/0 Fa 2/0
Fa 1/0
C 192.70.80.0 is directly connected, fastethernet2/0
Tabla de enrutamiento vrf celeste
C 192.70.80.0 is directly connected, fastethernet0/0
Tabla de enrutamiento vrf rojo
C 192.70.80.0 is directly connected, fastethernet1/0
Tabla de enrutamiento vrf amarillo
Pasos a seguir:
Definir cada vrf
Asignar un valor Router Distinguisher-rd
Asociar las interfaces a cada vrf
R1(config)#ip vrf celeste
R1(config-vrf)#rd 10:1
R1(config-vrf)#exit
R1(config)#ip vrf rojo
R1(config-vrf)#rd 10:2
R1(config-vrf)#exit
R1(config)#ip vrf amarillo
R1(config-vrf)#rd 10:3
R1(config-vrf)#exit
R1(config)#
La numeración es referencial.
Permite al dispositivo distinguir qué
interfaz y que ruta pertenece a qué
dominio de enrutamiento interno.
In Cisco terminology, deployment of VRFs without MPLS is
known as VRF lite,
7. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_01 CISCO
192.10.20.1/30
60.60.60.1/30
10.10.10.1.1/30192.70.80.1/30
192.70.80.1/30
192.70.80.1/30VRF
VRF
VRF
Tabla
VRF
Tabla
VRF
Tabla
VRF
Fa 0/0 Fa 2/0
Fa 1/0
C 192.70.80.0 is directly connected, fastethernet2/0
Tabla de enrutamiento vrf celeste
C 192.70.80.0 is directly connected, fastethernet0/0
Tabla de enrutamiento vrf rojo
C 192.70.80.0 is directly connected, fastethernet1/0
Tabla de enrutamiento vrf amarillo
Pasos a seguir:
Definir cada vrf
Asignar un valor Router Distinguisher-rd
Asociar las interfaces a cada vrf
R1(config)#interface fastethernet2/0
R1(config-if)#ip vrf forwarding celeste
R1(config-if)#ip address 192.70.80.1 255.255.255.252
R1(config-if)#no shutdown
R1(config)#interface fastethernet0/0
R1(config-if)#ip vrf forwarding rojo
R1(config-if)#ip address 192.70.80.1 255.255.255.252
R1(config-if)#no shutdown
8. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_01 CISCO
R1(config)#interface fastethernet1/0
R1(config-if)#ip vrf forwarding amarillo
R1(config-if)#ip address 192.70.80.1 255.255.255.252
R1(config-if)#no shutdown
192.10.20.1/30
60.60.60.1/30
10.10.10.1.1/30192.70.80.1/30
192.70.80.1/30
192.70.80.1/30VRF
VRF
VRF
Tabla
VRF
Tabla
VRF
Tabla
VRF
Fa 0/0 Fa 2/0
Fa 1/0
C 192.70.80.0 is directly connected, fastethernet2/0
Tabla de enrutamiento vrf celeste
C 192.70.80.0 is directly connected, fastethernet0/0
Tabla de enrutamiento vrf rojo
C 192.70.80.0 is directly connected, fastethernet1/0
Tabla de enrutamiento vrf amarillo
Pasos a seguir:
Definir cada vrf
Asignar un valor Router Distinguisher-rd
Asociar las interfaces a cada vrf
9. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_01 CISCO
R1#show ip route
R1#
R1#show ip route vrf celeste
Routing Table: celeste
192.70.80.0/30 is subnetted, 1 subnets
C 192.70.80.0 is directly connected, FastEthernet2/0
R1#
R1#show ip route vrf rojo
Routing Table: rojo
192.70.80.0/30 is subnetted, 1 subnets
C 192.70.80.0 is directly connected, FastEthernet0/0
R1#
R1#show ip route vrf amarillo
Routing Table: amarillo
192.70.80.0/30 is subnetted, 1 subnets
C 192.70.80.0 is directly connected, FastEthernet1/0
R1#
20. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_02 CISCO
R4(config)#interface fastethernet2/0
R4(config-if)#no shutdown
R4(config-if)#exit
R4(config)#interface fastethernet2/0.1
R4(config-if)#ip vrf forwarding empresa_a
R4(config-if)#encapsulation dot1Q 1
R4(config-if)#ip address 20.20.20.6 255.255.255.252
R4(config-if)#no shutdown
R4(config-if)#exit
R4(config)#
R4(config)#interface fastethernet2/0.2
R4(config-if)#ip vrf forwarding empresa_b
R4(config-if)#encapsulation dot1Q 2
R4(config-if)#ip address 20.20.20.6 255.255.255.252
R4(config-if)#no shutdown
R4(config-if)#exit
EMPRESA A
EMPRESA B
20.20.20.4/30
20.20.20.0/30
20.20.20.0/30
20.20.20.8/30
20.20.20.8/30
.2
.2
.1
.1
.5 .6
.9
.10
.10
.9
R1
R2
R5
R6
R3 R4
Tabla VRF
EMPR_A
Tabla VRF
EMPR_B
Tabla VRF
EMPR_A
Tabla VRF
EMPR_B
f0/0
f1/0
f1/1 f2/0
f1/1
f0/0
20.20.20.4/30
f1/1 f2/0
.5 .6
Subinterfaz fa1/1.1 Subinterfaz fa2/0.1
Subinterfaz fa1/1.2 Subinterfaz fa2/0.2
R3 R4
21. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
R2#show ip route
20.0.0.0/30 is subnetted, 1 subnets
C 20.20.20.0 is directly connected, FastEthernet1/0
C 210.16.2.0/24 is directly connected, FastEthernet2/0
C 210.16.1.0/24 is directly connected, FastEthernet1/1
C 210.16.0.0/24 is directly connected, FastEthernet0/0
S* 0.0.0.0/0 [1/0] via 20.20.20.1
R2#
VIRTUAL ROUTING AND FORWARDING: Caso_02 CISCO
R1#show ip route
20.0.0.0/30 is subnetted, 1 subnets
C 20.20.20.0 is directly connected, FastEthernet0/0
C 210.16.2.0/24 is directly connected, FastEthernet1/1
C 210.16.1.0/24 is directly connected, FastEthernet1/0
C 210.16.0.0/24 is directly connected, FastEthernet2/0
S* 0.0.0.0/0 [1/0] via 20.20.20.1
R1#
22. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
R3#show ip route vrf empresa_b
Routing Table: empresa_b
S 200.200.0.0/24 [1/0] via 20.20.20.6
20.0.0.0/30 is subnetted, 2 subnets
C 20.20.20.4 is directly connected, FastEthernet1/1.2
C 20.20.20.0 is directly connected, FastEthernet1/0
S 200.200.1.0/24 [1/0] via 20.20.20.6
S 200.200.2.0/24 [1/0] via 20.20.20.6
S 210.16.2.0/24 [1/0] via 20.20.20.2
S 210.16.1.0/24 [1/0] via 20.20.20.2
S 210.16.0.0/24 [1/0] via 20.20.20.2
R3#
VIRTUAL ROUTING AND FORWARDING: Caso_02 CISCO
R3#show ip route vrf empresa_a
Routing Table: empresa_a
S 200.200.0.0/24 [1/0] via 20.20.20.6
20.0.0.0/30 is subnetted, 2 subnets
C 20.20.20.4 is directly connected, FastEthernet1/1.1
C 20.20.20.0 is directly connected, FastEthernet0/0
S 200.200.1.0/24 [1/0] via 20.20.20.6
S 200.200.2.0/24 [1/0] via 20.20.20.6
S 210.16.2.0/24 [1/0] via 20.20.20.2
S 210.16.1.0/24 [1/0] via 20.20.20.2
S 210.16.0.0/24 [1/0] via 20.20.20.2
R3#
R3#show ip route
R3#
23. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
R4#show ip route vrf empresa_b
Routing Table: empresa_b
S 200.200.0.0/24 [1/0] via 20.20.20.10
20.0.0.0/30 is subnetted, 2 subnets
C 20.20.20.4 is directly connected, FastEthernet2/0.2
C 20.20.20.8 is directly connected, FastEthernet0/0
S 200.200.1.0/24 [1/0] via 20.20.20.10
S 200.200.2.0/24 [1/0] via 20.20.20.10
S 210.16.2.0/24 [1/0] via 20.20.20.5
S 210.16.1.0/24 [1/0] via 20.20.20.5
S 210.16.0.0/24 [1/0] via 20.20.20.5
R4#
VIRTUAL ROUTING AND FORWARDING: Caso_02 CISCO
R4#show ip route vrf empresa_a
Routing Table: empresa_a
S 200.200.0.0/24 [1/0] via 20.20.20.10
20.0.0.0/30 is subnetted, 2 subnets
C 20.20.20.4 is directly connected, FastEthernet2/0.1
C 20.20.20.8 is directly connected, FastEthernet1/1
S 200.200.1.0/24 [1/0] via 20.20.20.10
S 200.200.2.0/24 [1/0] via 20.20.20.10
S 210.16.2.0/24 [1/0] via 20.20.20.5
S 210.16.1.0/24 [1/0] via 20.20.20.5
S 210.16.0.0/24 [1/0] via 20.20.20.5
R4#
R4#show ip route
R4#
24. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
R6show ip route
C 200.200.0.0/24 is directly connected, FastEthernet0/0
20.0.0.0/30 is subnetted, 1 subnets
C 20.20.20.8 is directly connected, FastEthernet1/0
C 200.200.1.0/24 is directly connected, FastEthernet1/1
C 200.200.2.0/24 is directly connected, FastEthernet2/0
S* 0.0.0.0/0 [1/0] via 20.20.20.9
R6#
VIRTUAL ROUTING AND FORWARDING: Caso_02 CISCO
R5#show ip route
C 200.200.0.0/24 is directly connected, FastEthernet1/0
20.0.0.0/30 is subnetted, 1 subnets
C 20.20.20.8 is directly connected, FastEthernet0/0
C 200.200.1.0/24 is directly connected, FastEthernet1/1
C 200.200.2.0/24 is directly connected, FastEthernet2/0
S* 0.0.0.0/0 [1/0] via 20.20.20.9
R5#
25. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_02 CISCO
PC-1> ping 200.200.0.20
84 bytes from 200.200.0.20 icmp_seq=1 ttl=60 time=131.544 ms
84 bytes from 200.200.0.20 icmp_seq=2 ttl=60 time=137.132 ms
84 bytes from 200.200.0.20 icmp_seq=3 ttl=60 time=131.475 ms
84 bytes from 200.200.0.20 icmp_seq=4 ttl=60 time=137.491 ms
84 bytes from 200.200.0.20 icmp_seq=5 ttl=60 time=131.436 ms
26. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_02 CISCO
PC-11> ping 210.16.2.2
84 bytes from 210.16.2.2 icmp_seq=1 ttl=60 time=131.378 ms
84 bytes from 210.16.2.2 icmp_seq=2 ttl=60 time=131.976 ms
84 bytes from 210.16.2.2 icmp_seq=3 ttl=60 time=131.537 ms
84 bytes from 210.16.2.2 icmp_seq=4 ttl=60 time=131.100 ms
84 bytes from 210.16.2.2 icmp_seq=5 ttl=60 time=137.849 ms
PC-11>
No hay captura
27. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_03 CISCO
… … … …
200.10.1.0/24 200.20.1.0/24 200.10.2.0/24200.20.2.0/24
192.168.55.0/30 10.20.30.0/30
Acceso de
Internet
invitados
Acceso de
Internet
coorporativa
Usuarios
invitados
Usuarios
invitados
Usuarios
coorporativos
Usuarios
coorporativos
Ra Rb
R1
R2 R3
Rc Rd
.1 .2 .2 .1
OSPFv2
f0/0 f1/0
f1/1
f0/0
f1/0f1/1
f0/0
f0/0
f2/0
f0/0
f1/0
f1/1
f0/0
f0/0
f1/0 f1/1 f1/0 f1/1
46. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_03 CISCO
… … … …
200.10.1.0/24 200.20.1.0/24 200.10.2.0/24200.20.2.0/24
192.168.55.0/30 10.20.30.0/30
Acceso de
Internet
invitados
Acceso de
Internet
coorporativa
Usuarios
invitados
Usuarios
invitados
Usuarios
coorporativos
Usuarios
coorporativos
Ra Rb
R1
R2 R3
Rc Rd
.1 .2 .2 .1
OSPFv2
192.16.55.4/30
10.20.30.4/30
10.20.30.8/30192.168.55.8/30
192.168.55.12/30
10.20.30.12/30
192.168.55.16/30
10.20.30.16/30
192.168.55.20/30
10.20.30.20/30
costo
7
costo
1
costo 2costo 2 costo 2costo
1
costo 2
costo
4
costo 2 costo 2
47. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_03 CISCO
R3#show ip route vrf invitados
Routing Table: invitados
O E2 200.10.1.0/24 [110/15] via 192.168.55.13, 00:48:22, FastEthernet0/0.10
S 200.10.2.0/24 [1/0] via 192.168.55.22
192.168.55.0/30 is subnetted, 6 subnets
C 192.168.55.20 is directly connected, FastEthernet1/1.10
O 192.168.55.16 [110/4] via 192.168.55.13, 00:48:22, FastEthernet0/0.10
C 192.168.55.12 is directly connected, FastEthernet0/0.10
C 192.168.55.8 is directly connected, FastEthernet1/0.10
O 192.168.55.4 [110/8] via 192.168.55.9, 00:48:22, FastEthernet1/0.10
O 192.168.55.0 [110/2] via 192.168.55.9, 00:48:22, FastEthernet1/0.10
O*E2 0.0.0.0/0 [110/1] via 192.168.55.9, 00:48:22, FastEthernet1/0.10
R3#
48. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_03 CISCO
R3#show ip route vrf coorporativos
Routing Table: coorporativos
O E2 200.20.1.0/24 [110/15] via 10.20.30.13, 00:12:45, FastEthernet0/0.20
S 200.20.2.0/24 [1/0] via 10.20.30.22
10.0.0.0/30 is subnetted, 6 subnets
O 10.20.30.0 [110/4] via 10.20.30.13, 00:12:45, FastEthernet0/0.20
O 10.20.30.4 [110/3] via 10.20.30.13, 00:12:45, FastEthernet0/0.20
C 10.20.30.8 is directly connected, FastEthernet1/0.20
C 10.20.30.12 is directly connected, FastEthernet0/0.20
O 10.20.30.16 [110/4] via 10.20.30.13, 00:12:45, FastEthernet0/0.20
C 10.20.30.20 is directly connected, FastEthernet1/1.20
O*E2 0.0.0.0/0 [110/1] via 10.20.30.13, 00:12:45, FastEthernet0/0.20
R3#
49. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
VIRTUAL ROUTING AND FORWARDING: Caso_03 CISCO
50. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
TAREA-01Enrutamiento
por defecto
… … … …
200.10.1.0/24 200.20.1.0/24 200.10.2.0/24200.20.2.0/24
Usuarios
invitados
Usuarios
invitados
Usuarios
coorporativos
Usuarios
coorporativos
R2
… …
200.10.1.0/24 200.20.1.0/24
Usuarios
invitados
Usuarios
coorporativos
R1
R6
R3
R4
R5
OSPFv2
Enrutamiento
por defectoEnrutamiento
por defecto
Rc
Rb
Ra
51. Profesor Daniel Díaz Ataucuri ddiaz1610@gmail.com2018
VIRTUAL ROUTING AND FORWARDING -VIRTUAL ROUTING AND FORWARDING -
VRFVRF
TAREA-02
Enrutamiento
por defecto
… …
200.20.1.0/24 200.10.2.0/24
Usuarios
invitados
Usuarios
coorporativos
R2
…
200.10.1.0/24
Usuarios
invitados
R1
R6
R3
R4
R5
OSPFv2
Enrutamiento
por defecto
Enrutamiento
por defecto
RcRb
Ra
…
200.20.2.0/24
Usuarios
coorporativos
Rd
…
200.10.3.0/24
Usuarios
invitados
ReEnrutamiento
por defecto
Enrutamiento
por defecto