Academy/VCAP — VCF Networking (3V0-25.25)/Lab NN2: VRF-Lite & Route Leaking for Multi-Tenant Isolation
This lab targets VCF 9.0

Lab NN2: VRF-Lite & Route Leaking for Multi-Tenant Isolation

VCF 9.0Intermediatevcap-advanced⏱ 75 min

Objectives

  • Implement VRF-based isolation across tenants with controlled route leaking for shared services.

Prerequisites

VCF lab environment deployed and operational

Lab Environment

Standard VCF lab environment for Advanced VCF 9.0 Networking (NSX & Advanced Routing)

Tasks

Task 1 Lab NN2: VRF-Lite & Route Leaking for Multi-Tenant Isolation

Implement VRF-based isolation across tenants with controlled route leaking for shared services.

Step 1

Create 3 VRFs on T0 for tenants A, B, C plus a Shared-Services VRF.

Step 2

Configure route leaking so tenants reach shared services but not each other.

Step 3

Apply per-VRF BGP policies to upstream ToR.

Step 4

Validate with traceroute and packet captures.

Step 5

Stress test with scale: 100 prefixes per VRF, observe Edge CPU.

Validation Gate

Check: Verify lab completion

Expected: Lab exercise completed successfully

Common Errors

VRF route leaking allowing unintended cross-tenant traffic
Fix: Route leaking between VRFs must be explicit and controlled. Leak only the specific routes needed (e.g., shared services subnet), not the entire VRF routing table. Use route maps on the leak configuration to filter permitted routes. Audit leaked routes regularly.
Overlapping IP address spaces between tenants without VRF
Fix: Without VRF, overlapping tenant IP ranges cause routing conflicts. VRF-Lite on NSX T0 creates isolated routing tables per tenant. Each tenant can use 10.0.0.0/8 without conflict. Verify VRF isolation with traceroute from each tenant — traffic should never cross VRF boundaries unless explicitly leaked.
Not configuring separate BGP ASN per VRF for external peering
Fix: If multiple VRFs peer with the same physical router, each VRF should use a unique BGP ASN to prevent route confusion. Alternatively, use VRF-aware BGP on the physical router with separate sessions per VRF.

Final Validation

Lab completed successfully

✓ All steps completed → No errors observed

Cleanup / Restore

• Revert to snapshot if needed

Design Reflection (VCDX)

Multi-tenant networking with VRF shows enterprise design capability. VCDX panelists test isolation guarantees and how you handle shared services across tenants.

⚠ Known Pitfalls (from Community KB)

Leaking full routing tables between VRFs — defeats the purpose of tenant isolation.
Using the same BGP ASN across VRFs when peering with a single physical router — causes route confusion.
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.