This topic describes how the internal VRF-based forwarding feature uses a forwarding-match access control entry (ACE) to redirect packets that do not match predefined access control entries to an internal VRF (iVRF) for deep inspection through GRE tunneling.
Forwarding capabilities in VRFs are enhanced in the ingress direction to allow VRFs to redirect incoming packets to a different destination using GRE tunneling.
Feature history for Internal VRF-based forwarding
|
Feature Name |
Release Information |
Description |
|---|---|---|
|
Internal VRF based Forwarding |
Release 26.2.1 |
Introduced in this release on: Modular Systems (8800 [LC ASIC: P100]):* *This feature is supported on:
|
|
Internal VRF based Forwarding |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
|
Internal VRF based Forwarding |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on Cisco 8011-4G24Y4H-I routers. |
|
Internal VRF based Forwarding |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100, K100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) *This feature is supported on:
|
|
Internal VRF based Forwarding |
Release 24.2.11 |
Forwarding capabilities in VRFs are enhanced, allowing internal VRFs (iVRF) to redirect incoming packets to a different destination using GRE tunneling. This functionality can be used to examine packets that do not match the predefined access control entries. Instead of discarding these packets by default, a forwarding-match ACE sends them to a VRF that can forward them using GRE tunnels. This allows for a more thorough inspection of these discarded packets, helping to identify any hidden threats or attacks in the contents and improving network security. |