-----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Jerome Durand Subject: Re: [c-nsp] Management stuff in VRFs
>We went in that direction in our latest deployment and discovered also >that many pieces were missing in IOS and IOS-XR to have full management >in a dedicated VRF for all our devices. >At this stage we have the VRF but not all management goes there... so >there is more complexity and network is no more secure... I must admit >IOS-XR gives us more troubles as more management features are missing in >VRF's. The most effective way to do this I've seen so far essentially turns your network inside out. The "Global" portion of the router is management, in RFC1918 space, and your "internet/public" IP's/traffic/etc are all carried in a dedicated VRF. Taking a production network NOT designed that way, and doing the inside-out... well.... that's every bit as hard as it sounds... _______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
