RE: Cisco ASA and VRF

From: Brian McGahan (bmcgahan@internetworkexpert.com)
Date: Sat Mar 31 2007 - 11:50:34 ART


Peter,

        There is a feature called Virtual Firewalls or "Security
Contexts" that is essentially like VRFs for the ASA. It splits the
device into multiple logical firewalls that have separate routing,
xlate, and connection tables. With the current 7.2 release security
contexts do not support OSPF and RIP, only static routing. It may be
supported in version 8 when released but I haven't seen any specifics on
it.

HTH,

Brian McGahan, CCIE #8593 (R&S/SP)
bmcgahan@internetworkexpert.com

Internetwork Expert, Inc.
http://www.InternetworkExpert.com
Toll Free: 877-224-8987 x 705
Outside US: 775-826-4344 x 705
24/7 Support: http://forum.internetworkexpert.com
Live Chat: http://www.internetworkexpert.com/chat/

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
Peter Grewal
Sent: Saturday, March 31, 2007 9:20 AM
To: ccielab@groupstudy.com
Subject: Cisco ASA and VRF

Is anyone aware if its possible to have a Cisco ASA participate with a
set
of routers/switches using VRF-lite ? I'm looking at a setup where I need
to
differentiate multiple OSPF incidences with a firewall involved.

Does anyone know if the Junipers firewall virtual router functionality
would
work with Cisco VRF-lite implementation. I'm assuming since there not
based
on any real standard that they don't.

Thank you.

Peter.



This archive was generated by hypermail 2.1.4 : Sun Apr 01 2007 - 06:35:53 ART