VRF (Virtual Routing and Forwarding) in VyOS
VRF (Virtual Routing and Forwarding) in VyOS lets you create isolated virtual routers within a single physical device, each with its own independent routing table.
VRF Concept
Core principles
VRF provides:
- Isolation of routing tables between different customers/services
- The ability to use overlapping IP addresses across different VRFs
- Logical separation of network traffic on a single device
- Independent routing protocol configuration for each VRF
Key components:
- VRF Instance: A named VRF instance with its own routing table
- Route Distinguisher (RD): A unique VRF identifier for BGP
- Route Target (RT): A mechanism for importing/exporting routes between VRFs
- VRF Interface: A network interface bound to a specific VRF
VRF architecture
Physical VyOS Router
+--------------------------------------------------+
| |
| VRF "CUSTOMER-A" VRF "CUSTOMER-B" |
| ┌──────────────────┐ ┌──────────────────┐ |
| │ RT: 10.0.0.0/24 │ │ RT: 10.0.0.0/24 │ |
| │ eth1.100 │ │ eth1.200 │ |
| │ BGP AS 65001 │ │ BGP AS 65002 │ |
| └──────────────────┘ └──────────────────┘ |
| |
| VRF "MANAGEMENT" Global Table |
| ┌──────────────────┐ ┌──────────────────┐ |
| │ RT: 192.168.1.0/24│ │ Default routing │ |
| │ eth2 │ │ eth0 (WAN) │ |
| └──────────────────┘ └──────────────────┘ |
+--------------------------------------------------+Basic VRF configuration
Creating VRF instances
configure
# Create a VRF for customer A
set vrf name CUSTOMER-A table '100'
set vrf name CUSTOMER-A description 'Customer A isolated network'
# Create a VRF for customer B
set vrf name CUSTOMER-B table '200'
set vrf name CUSTOMER-B description 'Customer B isolated network'
# Create a VRF for management
set vrf name MANAGEMENT table '300'
set vrf name MANAGEMENT description 'Management network'
commit
saveBinding interfaces to a VRF
# Interface for Customer A
set interfaces ethernet eth1 vif 100 address '10.0.1.1/24'
set interfaces ethernet eth1 vif 100 vrf 'CUSTOMER-A'
# Interface for Customer B
set interfaces ethernet eth1 vif 200 address '10.0.1.1/24'
set interfaces ethernet eth1 vif 200 vrf 'CUSTOMER-B'
# Interface for Management
set interfaces ethernet eth2 address '192.168.1.1/24'
set interfaces ethernet eth2 vrf 'MANAGEMENT'
commitStatic routes in a VRF
# Static route in VRF CUSTOMER-A
set vrf name CUSTOMER-A protocols static route 172.16.0.0/16 next-hop 10.0.1.254
# Static route in VRF CUSTOMER-B
set vrf name CUSTOMER-B protocols static route 172.16.0.0/16 next-hop 10.0.1.254
# Default route in the MANAGEMENT VRF
set vrf name MANAGEMENT protocols static route 0.0.0.0/0 next-hop 192.168.1.254
commitUsing VRF with routing protocols
BGP with VRF
configure
# BGP configuration for VRF CUSTOMER-A
set vrf name CUSTOMER-A protocols bgp system-as '65001'
set vrf name CUSTOMER-A protocols bgp neighbor 10.0.1.2 remote-as '65100'
set vrf name CUSTOMER-A protocols bgp neighbor 10.0.1.2 address-family ipv4-unicast
set vrf name CUSTOMER-A protocols bgp parameters router-id '10.0.1.1'
# Announcing networks in BGP
set vrf name CUSTOMER-A protocols bgp address-family ipv4-unicast network 10.0.1.0/24
# BGP configuration for VRF CUSTOMER-B
set vrf name CUSTOMER-B protocols bgp system-as '65002'
set vrf name CUSTOMER-B protocols bgp neighbor 10.0.1.2 remote-as '65200'
set vrf name CUSTOMER-B protocols bgp neighbor 10.0.1.2 address-family ipv4-unicast
set vrf name CUSTOMER-B protocols bgp parameters router-id '10.0.1.1'
commit
saveOSPF with VRF
# OSPF configuration for VRF CUSTOMER-A
set vrf name CUSTOMER-A protocols ospf area 0 network '10.0.1.0/24'
set vrf name CUSTOMER-A protocols ospf parameters router-id '10.0.1.1'
# OSPF configuration for VRF CUSTOMER-B
set vrf name CUSTOMER-B protocols ospf area 0 network '10.0.1.0/24'
set vrf name CUSTOMER-B protocols ospf parameters router-id '10.0.1.1'
commitRIP with VRF
# RIP configuration for a VRF
set vrf name CUSTOMER-A protocols rip interface eth1.100
set vrf name CUSTOMER-A protocols rip network '10.0.1.0/24'
commitAdvanced VRF configuration
Route leaking between VRFs
Route leaking lets you selectively share routes between VRFs:
# Import routes from CUSTOMER-A into CUSTOMER-B
set vrf name CUSTOMER-B protocols static route 10.100.0.0/16 next-hop-vrf 'CUSTOMER-A'
# Create a route-map for filtering
set policy route-map VRF-LEAK rule 10 action 'permit'
set policy route-map VRF-LEAK rule 10 match ip address prefix-list 'ALLOWED-PREFIXES'VRF with NAT
# NAT for VRF CUSTOMER-A
set nat source rule 100 source address '10.0.1.0/24'
set nat source rule 100 outbound-interface name 'eth0'
set nat source rule 100 translation address 'masquerade'
# Bind NAT to the VRF through the interface
set interfaces ethernet eth1 vif 100 vrf 'CUSTOMER-A'Firewall for a VRF
# Firewall for traffic in VRF CUSTOMER-A
set firewall ipv4 name VRF-CUSTOMER-A-IN default-action 'drop'
set firewall ipv4 name VRF-CUSTOMER-A-IN rule 10 action 'accept'
set firewall ipv4 name VRF-CUSTOMER-A-IN rule 10 state established
set firewall ipv4 name VRF-CUSTOMER-A-IN rule 10 state related
set firewall ipv4 name VRF-CUSTOMER-A-IN rule 20 action 'accept'
set firewall ipv4 name VRF-CUSTOMER-A-IN rule 20 source address '10.0.1.0/24'
# Apply to the VRF interface
set interfaces ethernet eth1 vif 100 firewall in name 'VRF-CUSTOMER-A-IN'DHCP Server in a VRF
# DHCP server for VRF CUSTOMER-A
set service dhcp-server shared-network-name CUSTOMER-A-NETWORK subnet 10.0.1.0/24 range 0 start '10.0.1.10'
set service dhcp-server shared-network-name CUSTOMER-A-NETWORK subnet 10.0.1.0/24 range 0 stop '10.0.1.200'
set service dhcp-server shared-network-name CUSTOMER-A-NETWORK subnet 10.0.1.0/24 default-router '10.0.1.1'
set service dhcp-server shared-network-name CUSTOMER-A-NETWORK subnet 10.0.1.0/24 name-server '8.8.8.8'
set service dhcp-server shared-network-name CUSTOMER-A-NETWORK vrf 'CUSTOMER-A'VRF use cases
1. Multi-tenancy for cloud services
Isolating customers in a cloud environment:
configure
# A VRF for each customer
set vrf name TENANT-001 table '1001'
set vrf name TENANT-002 table '1002'
set vrf name TENANT-003 table '1003'
# Bind VLANs to VRFs
set interfaces ethernet eth1 vif 1001 address '10.1.0.1/24'
set interfaces ethernet eth1 vif 1001 vrf 'TENANT-001'
set interfaces ethernet eth1 vif 1002 address '10.1.0.1/24'
set interfaces ethernet eth1 vif 1002 vrf 'TENANT-002'
set interfaces ethernet eth1 vif 1003 address '10.1.0.1/24'
set interfaces ethernet eth1 vif 1003 vrf 'TENANT-003'
# BGP for each tenant
set vrf name TENANT-001 protocols bgp system-as '65001'
set vrf name TENANT-002 protocols bgp system-as '65002'
set vrf name TENANT-003 protocols bgp system-as '65003'
commit2. Separating services (Management, Production, Development)
# Production VRF
set vrf name PRODUCTION table '100'
set interfaces ethernet eth1 vif 100 address '10.10.0.1/24'
set interfaces ethernet eth1 vif 100 vrf 'PRODUCTION'
# Development VRF
set vrf name DEVELOPMENT table '200'
set interfaces ethernet eth1 vif 200 address '10.20.0.1/24'
set interfaces ethernet eth1 vif 200 vrf 'DEVELOPMENT'
# Management VRF (access to both)
set vrf name MANAGEMENT table '300'
set interfaces ethernet eth2 address '192.168.0.1/24'
set interfaces ethernet eth2 vrf 'MANAGEMENT'
# Route leaking for management access
set vrf name MANAGEMENT protocols static route 10.10.0.0/24 next-hop-vrf 'PRODUCTION'
set vrf name MANAGEMENT protocols static route 10.20.0.0/24 next-hop-vrf 'DEVELOPMENT'3. Internet Service Provider (ISP) architecture
# ISP Customer VRFs with BGP
set vrf name CUSTOMER-A table '100'
set vrf name CUSTOMER-A protocols bgp system-as '65000'
set vrf name CUSTOMER-A protocols bgp neighbor 10.1.1.2 remote-as '65001'
set vrf name CUSTOMER-B table '200'
set vrf name CUSTOMER-B protocols bgp system-as '65000'
set vrf name CUSTOMER-B protocols bgp neighbor 10.2.1.2 remote-as '65002'
# Separate routing policies per customer
set vrf name CUSTOMER-A protocols bgp neighbor 10.1.1.2 address-family ipv4-unicast route-map import 'CUSTOMER-A-IN'
set vrf name CUSTOMER-A protocols bgp neighbor 10.1.1.2 address-family ipv4-unicast route-map export 'CUSTOMER-A-OUT'4. Test environment alongside production
# Production VRF
set vrf name PROD table '100'
set interfaces ethernet eth1 vif 100 vrf 'PROD'
set vrf name PROD protocols bgp system-as '65100'
# Test VRF (isolated copy of production)
set vrf name TEST table '200'
set interfaces ethernet eth1 vif 200 vrf 'TEST'
set vrf name TEST protocols bgp system-as '65200'
# Identical IP ranges, but isolated
set interfaces ethernet eth1 vif 100 address '10.0.0.1/24'
set interfaces ethernet eth1 vif 200 address '10.0.0.1/24'Integrating VRF with cloud platforms
Yandex Cloud
Typical scenarios:
- VRF for separating environments (production, staging, development)
- Isolating customer networks in multi-tenant solutions
- A dedicated management VRF with access through Yandex Cloud VPC
configure
# Production VRF for a Yandex Cloud network
set vrf name YC-PROD table '100'
set interfaces ethernet eth1 vif 100 address '10.128.0.1/24'
set interfaces ethernet eth1 vif 100 vrf 'YC-PROD'
set interfaces ethernet eth1 vif 100 description 'Yandex Cloud Production'
# Development VRF
set vrf name YC-DEV table '200'
set interfaces ethernet eth1 vif 200 address '10.129.0.1/24'
set interfaces ethernet eth1 vif 200 vrf 'YC-DEV'
set interfaces ethernet eth1 vif 200 description 'Yandex Cloud Development'
# Static routes in Yandex Cloud
set vrf name YC-PROD protocols static route 0.0.0.0/0 next-hop 10.128.0.2
# BGP peering with Yandex Cloud
set vrf name YC-PROD protocols bgp system-as '65000'
set vrf name YC-PROD protocols bgp neighbor 10.128.0.2 remote-as '65001'
commitIntegration with Yandex Cloud Services:
# VRF for accessing Object Storage
set vrf name YC-STORAGE table '300'
set vrf name YC-STORAGE protocols static route 213.180.193.0/24 next-hop 10.128.0.2
set vrf name YC-STORAGE protocols static route 213.180.204.0/24 next-hop 10.128.0.2VK Cloud
Typical scenarios:
- Separating customer projects
- Isolating the DMZ from internal networks
- A separate VRF for Kubernetes clusters
# VK Cloud Production
set vrf name VK-PROD table '100'
set interfaces ethernet eth1 vif 100 address '10.0.10.1/24'
set interfaces ethernet eth1 vif 100 vrf 'VK-PROD'
# VK Cloud Kubernetes
set vrf name VK-K8S table '200'
set interfaces ethernet eth1 vif 200 address '10.0.20.1/24'
set interfaces ethernet eth1 vif 200 vrf 'VK-K8S'
# DMZ VRF
set vrf name VK-DMZ table '300'
set interfaces ethernet eth1 vif 300 address '10.0.30.1/24'
set interfaces ethernet eth1 vif 300 vrf 'VK-DMZ'
# Route leaking: the DMZ can talk to PROD, but not the other way around
set vrf name VK-DMZ protocols static route 10.0.10.0/24 next-hop-vrf 'VK-PROD'VRF monitoring and diagnostics
VRF display commands
# List all VRFs
show vrf
# Detailed VRF information
show vrf detail
# Routing table for a specific VRF
show ip route vrf CUSTOMER-A
# BGP status in a VRF
show bgp vrf CUSTOMER-A summary
# OSPF in a VRF
show ospf vrf CUSTOMER-A neighbor
# Interfaces in a VRF
show interfaces vrf CUSTOMER-ADiagnostic commands
# Ping from a VRF
ping 8.8.8.8 vrf CUSTOMER-A
# Traceroute from a VRF
traceroute 8.8.8.8 vrf CUSTOMER-A
# TCP dump on a VRF interface
monitor traffic interface eth1.100
# View connections in a VRF
show conntrack vrf CUSTOMER-AVRF logging
# Enable detailed logging for a VRF
set system syslog global facility local7 level 'info'
# View logs
show log | match vrf
show log | match CUSTOMER-AVRF design best practices
Planning the VRF architecture
Naming Convention: Use clear VRF names
- CUSTOMER-{NAME} for customer VRFs
- {ENV}-{SERVICE} for internal services (PROD-APP, DEV-DB)
- MGMT or MANAGEMENT for management
Table ID Assignment: Reserve table ID ranges
- 100-199: Production VRFs
- 200-299: Development/Staging VRFs
- 300-399: Management VRFs
- 1000+: Customer VRFs
IP Address Planning: Document IP usage for each VRF
- You can use the same private ranges across different VRFs
- Plan route leaking in advance
Route Distinguisher: Use unique RDs for BGP VRFs
- Format: ASN:NN (65000:100, 65000:200)
- Or IP:NN (10.0.0.1:100)
VRF security
- Firewall between VRFs: Always apply a firewall when route leaking
set firewall ipv4 name VRF-TO-VRF default-action 'drop'
set firewall ipv4 name VRF-TO-VRF rule 10 action 'accept'
set firewall ipv4 name VRF-TO-VRF rule 10 source address '10.1.0.0/24'- Management isolation: A dedicated VRF for management
- Access Control: Restrict access between VRFs
- Audit Logging: Log all inter-VRF communications
Performance
- Hardware Forwarding: VRF uses kernel routing; verify performance
- Table Size: Monitor the size of routing tables in each VRF
- BGP Scaling: Limit the number of prefixes per VRF
- Connection Tracking: Monitor conntrack entries for each VRF
Management and monitoring
- Documentation: Document the purpose of each VRF
- Monitoring: Set up monitoring of routes and VRF state
- Alerting: Alerts when the number of routes changes
- Backup: Regular configuration backups
Troubleshooting VRF
Problem: Traffic does not pass through the VRF
Symptoms:
- Packets are sent but do not reach the destination
- No connectivity in the VRF
Solution:
# Check that the interface is in the correct VRF
show interfaces
# Check the VRF routing table
show ip route vrf CUSTOMER-A
# Check that a default route exists
show ip route vrf CUSTOMER-A 0.0.0.0/0
# Check the firewall rules
show firewall
# Debug routing
set vrf name CUSTOMER-A protocols static route 0.0.0.0/0 next-hop 10.0.1.254Problem: Route leaking does not work
Symptoms:
- Routes do not appear in the target VRF
- No connectivity between VRFs
Solution:
# Check the route leaking configuration
show vrf name CUSTOMER-A protocols static
# Check that the source route exists
show ip route vrf SOURCE-VRF
# Check next-hop-vrf
set vrf name DEST-VRF protocols static route 10.0.0.0/24 next-hop-vrf 'SOURCE-VRF'
# Check the firewall between VRFs
show firewallProblem: BGP does not establish a session in the VRF
Symptoms:
- The BGP neighbor is in the Idle or Active state
- No BGP routes in the VRF
Solution:
# Check the BGP configuration
show bgp vrf CUSTOMER-A summary
# Check that the neighbor is reachable
ping <neighbor-ip> vrf CUSTOMER-A
# Check the router-id
show bgp vrf CUSTOMER-A
# Debug BGP
set vrf name CUSTOMER-A protocols bgp parameters log-neighbor-changes
# Check the firewall for BGP (TCP 179)
show firewallProblem: Overlapping IP addresses conflict
Symptoms:
- Routing loops
- Incorrect routing between VRFs
Solution:
# Make sure the interfaces are in the correct VRFs
show interfaces detail
# Check that there is no accidental route leaking
show vrf name CUSTOMER-A protocols static
# Check the NAT configuration
show nat source rulesProblem: DHCP does not work in the VRF
Symptoms:
- Clients do not receive IP addresses
- The DHCP server does not respond
Solution:
# Check that the DHCP server is bound to the VRF
show service dhcp-server
# Check that it listens on the correct interface
show service dhcp-server shared-network-name
# Make sure the VRF is specified
set service dhcp-server shared-network-name CUSTOMER-A-NET vrf 'CUSTOMER-A'
# Check the DHCP lease
show dhcp server leasesAdditional resources
- VyOS VRF Documentation
- RFC 4364 - BGP/MPLS IP Virtual Private Networks (VPNs)
- Linux VRF Documentation
- FRRouting VRF Configuration
Note: VRF is a powerful tool for network segmentation. Plan your VRF architecture carefully before deploying it in a production environment. Detailed configuration examples for specific cloud scenarios will be added in future updates.