Vrf for Internet Access

Hello,
i'd like to configure a dedicated vrf for Internet access only. On my CE router i configured three vrf (Internet, red and blue) in the vrf internet i import the route target from blue and red, and the vrf blue and red i import only the default route. Everything is working fine, only one thing bothers me, i can ping from the vrf red destinations in the vrf blue and vice versa. How can i prevent this routing?
thanks in advanced.
Alex
here the config of my router.
ip prefix-list internet seq 5 permit 0.0.0.0/0
route-map internet permit 10
match ip address prefix-list internet
set extcommunity rt 100:200
ip vrf internet
rd 100:100
route-target both 100:100
route-target import 100:110
route-tarbet import 100:120
export map internet
ip vrf red
rd 100:110
route-target both 100:110
route-target import 100:200
ip vrf blue
rd 100:120
route-target both 100:120
route-target import 100:200

Hi Alex,
Given the FW is the next hop for the default route, the traffic from one vrf to the other goes through the FW and get routed back to the CE and then to the respective vrf router. You could add the rules on the FW to prevent
traffic being routed between FW.
Regards

Similar Messages

  • Can I hook up a windows computer to my airport time capsule for internet access?

    We have hooked up our time capsule for the first time today.  It works wonderful on our apple products BUT can I connect a windows based computer to it for internet access? 

    Yes. Both Ethernet and 802.11 are cross-platform.
    (109122)

  • User Authentication for Internet access

    Hi,
    Is it possible to configure authentication for internal (LAN) users to Authenticate (local/RADIUS/LDAP) for any kind of internet access through the ISA550/570? (like cut-through authentication proxy in ASA.)
    And Can the ISA550/570 act as a Web proxy?
    Thanks in advance.

    HI Sulu,
    You can configure captive portal for internal LAN users to authenticate (local/Radius/LDAP) for internet
    access through ISA500. (see attached screenshot)
    ISA500 cannot act as a web proxy. what is your use case ?
    Regards,
    Wei

  • Using 2nd Built-In Ethernet port for internet access?

    Hello,
    I have a Quad-G5 running 10.4.8. In its current configuration, all its network communications, including web access, go over the active ethernet port (Built-in 1).
    Does anyone know how I could use the second built-in port for internet access only? I'd like to route local traffic over the first port, but go "out" over the second.
    The machine is on a corporate network, and proxy access is slowwww. I have the ability to use a direct connect to the internet, but still need to be connected locally. Any thoughts? Many thanks . . . JD

    Easy. Go to System Preferences > Network > Network Port Configurations and drag the port connected to the internet to the top, so that it has priority over the port connected to your LAN. This prevents DNS time-out when loading a website, but still allows LAN traffic over the other port because that traffic is most likely going to use ARP rather than DNS. For good measure, you can add your company's domain (such as "my_company.lan") to System Preferences > Network > Internal_Ethernet > TCP/IP > Search Domains.

  • I have to restart ipad each time for internet access.  Why?

    I have to restart ipad each time for internet access and some games.  Never happened until about 2 weeks ago.  ?

    Firefox is a browser: it doesn't require you to 'sign in'.
    It sounds to me like you have some kind of malware installed if you're required to 'sign in' every time you use it.
    I'd recommend you use Internet Explorer (''assuming that doesn't require you to 'sign in' too'') to go to http://www.malwarebytes.org/ and download the free version. It will quarantine any malware it finds so restart Firefox afterwards to see whether the problem recurs or not.

  • How many ghz should I get if I plan on using my IPAD2 for internet access, email, facebook and games for my children?

    How many ghz should I get if I plan on using my IPad2 for internet access, email, facebook and games for my daughters children?

    Ghz is the CPU speed and that is fixed for each iPad model.
    The GB is the number of Gigabytes of storage.
    I had a 32G iPad1 and filled it up with 5000 songs, 20,000 photos and about 50 apps.  It doesn't sound like you will need anything larger than that.  If you are just talking about a few dozen apps and email, the 16G version should be adequate.

  • Can tata photon plus be used with apple i pad mini for internet access

    can tata photon plus be used with apple i pad mini for internet access?

    No, you will not be able to use a wired connection. If you have a iPad wifi, it can be used only with a wifi and if you have a iPad wifi+cellular, it can be used with both wifi and 2G/3G and 4G.

  • Have a static IP for internet access - how do I replace my Linksys wireless router with Time Capsule?

    Have 5 macs on an ethernet network - some wired and some wireless to a Linksys router.  My provider uses static IP and DSL for internet access.  I am replacing an existing Linksys router with the Time Capsule.  The Static IP settings I have are IP address, Gateway, Mask, primary DNS and secondary DNS.  The Airport Utility is not as straight forward as the Linksys setup.  There is not a place to list gateway.  Consequently I am unable to connect to the internet and am back on the Linksys router until I get this resolved.  Any suggestions would be much appreciated !

    You enter the static public IP address info on the TCP/IP tab within the Airport Utility. For a static address, use Configure IPv4 = Manually. You use the Router field for the Gateway address.

  • Is it possible to be connected with a 3G modem for internet access and a WiFi router for printer sharing at the same time?

    For our only internet access we have a 3G wireless modem. I have since purchased a WiFi printer and router to connect all the comptuters to in the house. The PCs have no problem with using both the 3G connection and the WiFi signal at the same time to print, however, the MacBook Pro will not connect to the 3G network and the router, it will drop the internet access from the modem and attempt to connect via WiFi (which has no internet access). Is there a solution that is available to remedy this? I attempted to create an adhoc printer network, however, the macbooks again will not print off of this, only the PCs. And I'm getting a bit frustrated overall with this.

    The 3G wireless modem is on one of the PC's correct?
    Why don't you pass the Internet through the Ethernet port to the router via Cat5 cable, then have that transmit a Wifi signal that everything else can use, then connect the printer to the router for print sharing?
    You would have to turn off the wifi on the comptuer with the 3G modem as it's physically connected to the router and can't connect to the other machines as they are all connected to the router for sharing.
    The Mac has the ability to pass, Internet Sharing in the System Preferences.
    Do you have software for the Mac to run the 3G modem?

  • I created a wireless network with my Time Capsule but would like to connect this network to a WiFi Hotspot for Internet Access

    I have created a Wirelss Network at home with the Time Capsule and would like to connect this network to the Internet.
    I can't use LAN Cable to connect to it anything becasuse I usually use the WiFi that runs through my building.
    Can I connect the Time Capsule to the WiFi hotspot somehow so that all computers on my network have Internet access and if so, what do I need?
    I need this done because the computers can only be connected to either the WiFi network or to my Time Capsule Network at any given time.
    Or is there a way to be connected to both networks simultaneously?
    I have two PC's and two Macs.
    Thank you for any support and I apologise for my ignorance. I am not too good with networking.
    I have tried the silliest of things like connecting a router to the TC only to then realise that the TC had an inbuilt router.
    I tried connecting a USB WiFI adapter to the USB Port on the TC but it doesnt detect it that way apparently.
    Please help!

    I have a kinda same problem @ https://discussions.apple.com/thread/3531642
    Please reply (somebody)!
    JeremyZ

  • Setting up a Router & Switch for internet access

    Hi all,
    I need help setting up internet access on my cisco router.
    It's a Cisco 2600, this is the setup.
    I have a Cisco 3560 switch, and 5 clients connects to this switch.
    I have one vlan defined VLAN 5.
    I have a trunk port between the router and the switch.
    My question is how to setup internet access between my switch and router?
    Please if you can send config commands? I am not that fimiliar with router setup.
    I know I need to setup a routing protocol, but need to know the command for that.

    Hi,
    You need to nat on the 2600 router and you need a default route on the router.
    How is router connected to WAN ?
    Have you got multiple vlans on the switch? Is the switch doing routing or is it Layer2 ?
    Post your config so that we can give you the missing commands
    Regards
    Alain
    Don't forget to rate helpful posts.

  • Just ordered new iMac do I still need a modem/router for Internet access

    Just  converted to apple,ordered a new IMAC but little confused on Internet access.
    does the extreme still need a modem/router,just a little confused after reading all the comments about poor connections etc.
    Old windows soldier sorry if a little vague .

    The AirPort Extreme is a router, but it is not a modem. You still need your existing cable or DSL modem. That device is usually supplied by your ISP and may or may not include the functions of a router.

  • How to get iphones / ipad user agent for internet access

    Hi.
    We recently setup some wireless, and I'm wondering how I can get iphones and ipads connected to the internet without prompting for a username and password. Even if it does prompt and we put in our domain credentials, things don't work.. it's like it heavily restricts access. However if you put DOMAINNAME\ in front of your user name, then it seems to work.
    Without making static IP reservations and attaching those ip's to no authentication in IronPort... isn't there a way to assign these devices to a policy via their user agent string? Problem is finding that string amongst different versions of iphones and ipads.
    I visited www.ipchicken.com on my iphone and it said Browser: Mozilla/5.0 (iPhone; U; CPU iPhone OS 4_3_2 like Mac OS X; en-us)
    AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8H7 Safari/6533.18.5
    What part of this do I copy into the user agents field for my no autnentication identity that I'm trying to alter? I tried putting AppleWebKit in, but it still blocks almost everything.
    Right now in this Allowed User Agents identiy i have Windows Update checked, as well as these:
    (MSOffice\x2014)
    Microsoft NCSI
    SSLSoapClient
    AppleWebKit (does not seem to work)
    Thanks for the help!

    I think I figured it out.  Followed this closely:
    https://ironport.custhelp.com/cgi-bin/ironport.cfg/php/enduser/std_adp.php?p_faqid=1426&p_sid=ODIeCGuk&p_lva=1713&p_li=cF91c2VyaWQ9MXJvblAwcnQmcF9wYXNzd2Q9Zm8wQmE1
    Also do you guys know if the custom user agent field can accept wildcards?  Problem is, every version of iOS for iPhone 1, 3G, 3GS, 4, and iPad 1 & 2, or ipod touch (various generations) all have variations in their user strings.  If I could just do a blanket statement for like *iphone* , *ipad*, etc.... that would be easier.
    So are there any wildcards or txt masks that can be put in and interpreted in the custom user agents field?

  • Parental controls for internet access

    I would like to be able use my macbook pro to manage our 4 children's access to the internet. Most importantly times of access but also some internet policing.
    We have an airport extreme base station and airport express.
    The children all have iPads of varying age and model number.
    Can this be done and if so how?

    You can set restrictions in the devices. Settings > General > Restrictions > Enable Restrictions. You would do this on each of their devices. Be sure you use different passcodes for each device and make them strong passcode. Write them down somewhere and keep them hidden so your children cannot find them.
    If the kids also have access to a computer, then you can control it by opening Users & Groups and creating Managed user accounts for them to use. Clicking on Parental Controls will allow you to determine what they have access to.

  • E71x Dial-up connection for internet access on ph...

    When I lived in Africa I would use either google talk or skype to speak with my family back in the States. Wifi was extremely rare especially in my area so I had to connect via a dial-up connection. When I bought my E71x, I installed "Fring" on it (an amazing app) and I am able to call and speak to someone on google talk or skype over my phone. My question is, how do I setup a dialup access point for my cell phone so that I can access the internet and google talk/skype by that connection? Thanks, Joshua

    I don't use either Fring or Skype in my handset, I use a program called truphone from www.truphone.com and the network settings enable you to use it via 3G GPRS or WiFi.
    You should check with your network operator that this is permitted, as most see VoIP services as revenue loss and will disable the ports or charge extra for the service.
    Shunts...
    I will mostly be communicating with a Nokia E72 Zodium Black
    Nokia E72-1 with Vr 051.018.207.04 Software
    If this post helped... Add some kudos!!

Maybe you are looking for

  • How can i optimise my iweb site

    how do I optimise my web site is the software in iweb?  Is this done before I publish or after I publish through the FTP server host?

  • Creating jar file for entity bean

    I am trying to deploy an entity bean..i compiled all the java files and created a dir by name META_INF and copied ejb-jar.xml and the other two .xml files which are needed to this dir. then using ,ant i tried to create the jar file ,,but it is giving

  • Firewall software prevents remote control for AirTunes?

    I recently turned on the built-in firewall on my MacBook Pro. Ever since doing so, every time a run iTunes, get the following message: [quote] Your computer is using firewall software that prevents you from using a remote control for AirTunes. To use

  • Apps are really slow to open on bound machines

    Hi Guys, i have a problem that's quite a head-scratcher. I'm assisting a departmental tech at the school I work for with a funny OD problem. There are three problems, and I am not sure if they are related: 1) Initially the problem was that new users

  • Como puedo reiniciar las claves

    me he olvidado de algunas claves en mi mac y necesito reiniciarlas y si se puede trabajar sin estas