An address alone does not identify the path
A connectivity request should identify source, destination, protocol, port and routing context. Two applications can use the same private address in different VRFs without representing the same destination. Start with the ingress interface and its associated VRF; then inspect routes in that context, next-hop resolution and the return path to the source actually used. During an incident, a capture omitting the VRF can appear to contradict another team’s report. Preserve that context in logs, monitor names and change evidence, including whether the flow uses IPv4 or IPv6.
Case: a shared service without merging networks
In a fictional APS example, FUNDS needs to send logs to a collector in SERVICES. Define the collector prefix, the source used by agents, transport, port, return path and access owner. Importing a route creates a forwarding possibility; it neither authenticates the agent nor verifies that a message reached the collector. If both VRFs already use the same prefix for different destinations, sharing requires resolving that ambiguity in the design. An additional import does not magically select the intended recipient. Also verify that other networks and services remain inaccessible according to the contract.
RD and RT answer different questions
When a design uses BGP VPN-IPv4 distribution, the route distinguisher distinguishes identical IPv4 prefixes in their VPN representation. The route target participates in the policy making a route eligible for import into a VRF. Do not conclude that matching or different RDs alone define communication between services. Even a matching RT does not establish final route installation, next-hop resolution, destination response or application authorization. This distinction helps review supplier proposals; the next lab executes neither BGP, MPLS nor RT import. Their absence from the exercise should accompany any readiness report.
Read configuration before changing the interface
The original IOS XE excerpt below is a reading exercise, with no Cisco execution in this environment. It shows creation of the FUNDS IPv4 context, interface association and inspection. It configures neither a shared service nor BGP route distribution. For a real change, record addresses and dependencies before associating an interface with another VRF; confirm the final state on the deployed version and platform. If an address or connected route is missing afterwards, investigate those facts before changing remote-route preferences. Retain recovery access that does not depend exclusively on the changed interface.
Layered acceptance and handover to RUN
Production teams need to know where to observe failures, not merely which command was applied. Acceptance records should connect interface, VRF, prefix, next hop, test source and result. A router ping measures a path from a specific source and is not equivalent to a client transaction. Test the intended service, return traffic and at least one access that should remain blocked. Define an owner, stop threshold and rollback. In international environments, use consistent VRF identifiers in tickets so that teams do not inspect different tables and declare conflicting results.
! Original reading exercise only; not executed on Cisco IOS XE.
vrf definition FUNDS
rd 65000:10
address-family ipv4
exit-address-family!
interface GigabitEthernet1
vrf forwarding FUNDS
ip address 192.0.2.1 255.255.255.0! Operational inspection, not configuration commands:
show vrf definition FUNDS
show ip route vrf FUNDS
show ip arp vrf FUNDS
The collector route exists in SERVICES; that does not establish that agents in FUNDS can use it.
Common pitfalls
Inspecting only the global table; omitting source; confusing RD with import policy; accepting a route as proof of log delivery.
Related topics: VRF: isolation and recovery lab · Virtualization, VRFs and overlays
Identify context and validate forwarding, return traffic and service separately.
Reference: Configuring VRF-lite · 350-401 ENCOR v1.2, effective 2026-03-19; core component of CCNP Enterprise