Networking · Concept · 11 min read

What Is VRF? One Router Behaving as Several

A VLAN divides a switch and a VRF divides a router. Here is what that buys, the two very different ways it gets deployed, and the one use that belongs in every ordinary network.

Written by Marko Ristic, Editor Updated Sep 12, 2026
1VRF per interface, which is what decides the lookup
0Routes that cross between VRFs on their own
2Deployments sharing the name: VRF lite and MPLS L3VPN
1Use every network has for it, which is management
Short answer

VRF lets one router hold several completely separate routing tables. Each interface belongs to one VRF, and a packet is looked up only in that table. Two VRFs cannot reach each other unless a route is deliberately leaked, and they can hold the same addresses without conflict.

  • Each VRF is an independent routing table on one router
  • Overlapping address space becomes possible, and often is the reason
  • Nothing crosses between VRFs without a deliberate route leak
  • VRF lite needs no MPLS and no BGP
  • A management VRF is the use most small networks should adopt
On this page

FundamentalsWhat a VRF actually is

A router without VRFs has one routing table. Every route it learns goes in it, every packet is forwarded from it, and any two networks the router knows about can reach each other unless a rule says otherwise.

A router with VRFs has multiple tables, and the choice of which one to use for forwarding is made by the interface the packet arrived on.

Assign interface A to VRF RED and interface B to VRF BLUE, and a packet arriving on A is looked up in RED's table only. If RED has no route to the destination, the packet is dropped, even if BLUE has a perfectly good route to it.

Three consequences follow, and the third is the one people find surprising.

The separation is complete by default. Not a filter, not an access list, not a rule that could be misconfigured. The route simply is not in the table being consulted.

Each VRF runs its own routing. A VRF can have its own default route, its own OSPF or BGP process, its own static routes. Multiple routing processes coexist on the device and none of them sees the others.

Address space can overlap. Two VRFs can each contain the 10.0.0.0/24 address range with different machines in it, and neither knows the other exists. This is impossible on a single routing table and it is the reason this network technology gets deployed after a company acquires another one that also used 10.0.0.0/24.

Against VLANsVRF and VLAN, which are not alternatives

The comparison people reach for is VLAN, and the relationship is layered rather than competitive.

A VLAN is a layer 2 boundary. It divides a switch so frames cannot cross between groups of ports. A VRF is a layer 3 boundary. It divides a router so traffic cannot cross between forwarding tables.

They stack in the obvious way. Each VLAN normally carries one subnet. Each subnet is reached through an interface on the router. That interface belongs to a VRF. So a VRF typically contains multiple VLANs, and the networks inside one VRF can route to each other while nothing routes to the networks in another VRF.

VLANVRF
Layer23
What it dividesA switchA router
What it separatesBroadcast domainsRouting tables
Crossing it requiresA routerA deliberate route leak
Overlapping addresses allowedNot usefullyYes
IdentifierA 12 bit tagA name, and an RD in MPLS
Typical relationshipSeveral per VRFOne per group of VLANs

The practical shorthand: VLANs stop frames, VRFs stop forwarding, and a real network usually wants both.

Two deploymentsVRF lite, and the full version

Two deployments share the name and differ enormously in effort.

VRF liteMPLS L3VPN
Needs MPLSNoYes
Needs BGPNoYes, with the VPN address family
Carrying VRFs between routersOne subinterface eachOne session for all of them
Route distinguishersNot usedRequired
Route targetsNot usedHow sharing is expressed
Scales toA handful of VRFs and routersThousands of customers
Who runs itAlmost every enterpriseService providers

VRF lite is the technology on its own. Interfaces are assigned to VRFs, each VRF has its own routes, and that is the whole configuration. No MPLS, no BGP, nothing distributed. It works within one router, or across multiple routers if every link between them is configured per VRF, which usually means a subinterface or a VLAN for each one.

That last part is the honest limit of VRF lite. Carrying five VRFs between two routers means five subinterfaces on the link between them, and five neighbor relationships if a routing protocol is involved. It scales to a handful of virtual networks and a handful of routers, which is exactly the size most business networks are.

MPLS L3VPN is the service provider version. Instead of a separate link per VRF, one BGP session carries the routes of multiple VRFs together, and two extra pieces of information keep them straight.

The route distinguisher is a value prefixed to each route to make it unique. Two customers both advertising 10.0.0.0/24 produce two identical prefixes; with different route distinguishers they become two different routes that BGP can carry side by side.

The route target decides which VRFs a route is imported into. Each VRF exports its routes with a target and imports routes carrying targets it cares about. This is what makes selective sharing between multiple VRFs a configuration line rather than a redesign.

If you are running a network for one organization, VRF lite is almost certainly what you want. The full version exists because a service provider carries thousands of customer networks over shared equipment.

Route leakingRoute leaking, and why to be careful with it

Complete separation is the default and it is often too complete. A guest VRF still needs the internet. Every VRF needs to reach the DNS servers, the monitoring system and the patching infrastructure, which are shared network services. Sharing specific routes between multiple VRFs is called route leaking.

Two mechanisms exist, matching the two deployments.

Static routes in VRF lite. A route in one VRF pointing at a next hop reachable in another. Explicit, small, and easy to read six months later.

Route targets in MPLS. A shared services VRF exports with a target that every other VRF imports, so one line of configuration makes a set of servers reachable from all of them.

The care is warranted for one specific reason: a leak is a hole in the thing you built the VRFs for. The separation was the point, and every leaked route is a deliberate exception to it. Three habits keep that manageable.

Leak specific prefixes, not defaults. A leaked default route means everything, which is rarely what anyone meant.

Leak traffic in one direction where you can. The guest VRF reaching a DNS server is not the same as the DNS server network reaching the guests.

Write down why each leak exists. A leak whose reason nobody remembers is one nobody dares remove, and they accumulate.

Management VRFThe one every network should have: a management VRF

Most material about this technology is written for service providers, and there is one use that belongs in an ordinary business network.

Configure the management interfaces of your switches, routers and firewalls into a VRF of their own, reachable only from the machines that administer the network.

Two things follow, and both are worth having.

A routing mistake cannot lock you out. If the management addresses live in the main routing table and somebody breaks the default route, the device is unreachable at exactly the moment you need to fix it. In a separate VRF, management routing is unaffected by whatever happened to production routing.

The security surface shrinks to a defined set. Every device login page is reachable only from the VRF that holds the administration machines. That is a stronger security statement than an access list, because there is no forwarding path at all rather than a rule that could be wrong.

Most enterprise switches ship with a management VRF already defined and the dedicated management port already in it, and it goes unused because the port is not cabled. Cabling it is an afternoon and it is one of the better afternoons available.

PitfallsWhere people go wrong

Expecting two VRFs to reach each other. They cannot, by design. If something needs to work across them, a route has to be leaked deliberately.

Forgetting the VRF on a command. Almost every show and ping command needs to be told which VRF to use, and without it you are querying the default forwarding table. A ping that fails from a device that is working perfectly is usually this.

Leaking a default route. It reconnects everything the VRF was created to separate, and it looks like a small change.

Running VRF lite at a scale it does not fit. Ten virtual networks across six routers means sixty subinterfaces and a routing configuration nobody can hold in their head. That is the point at which the full version starts to earn its complexity.

Assuming a VRF encrypts anything. It separates routing and forwarding tables. Traffic in a VRF is as readable as any other network traffic to anybody on the path.

Putting the management addresses in the production VRF. It is the default and it is the reason a routing change becomes an outage that has to be fixed on site.

Treating a VRF as a substitute for firewall rules. Between VRFs it is stronger than a rule. Inside one, it does nothing at all, and everything in a VRF can reach everything else in it.

ONE ROUTER, TWO ROUTING TABLES, THE SAME PREFIX IN BOTHVRF RED10.0.0.0/24 via Gi0/10.0.0.0/0 via 198.51.100.1nothing else existsVRF BLUE10.0.0.0/24 via Gi0/20.0.0.0/0 via 203.0.113.1nothing else existsThe same prefix in two tables, on two interfaces, going to two different places.A single routing table cannot do that at all, which is why a merged company reaches for this.VRF MGMT, the one an ordinary network should haveThe management addresses of every switch, router and firewall, and nothing elseReachable only from the administration machines, with no path from productionA routing mistake in production cannot make the devices unreachable, since their routing is elsewhere.That is a stronger statement than an access list: there is no path, rather than a rule that could be wrong.
Two tables holding the same prefix is the demonstration. The band underneath is the use an ordinary network has for the same mechanism.

ComparisonThree ways to separate routing, and the one a mistake cannot undo

CriterionVRFVLANSeparate router
SeparatesRouting tablesBroadcast domainsEverything
Layer32Physical
Overlapping addressesYesNoYes
Cost to add anotherA configurationA configurationA router
Survives a misconfigurationNoNoYes
Carries across devices easilyNeeds a link per VRFYes, a trunkNot applicable
Right for a management networkYesPartlyOverkill

The fifth row is the same honest limit that applies to every form of virtual separation. A VRF is a configuration, and a configuration can be wrong. For the few things where being wrong is unacceptable, separate hardware is still the stronger answer.

FAQFrequently asked questions

What is VRF?

Virtual routing and forwarding: multiple independent routing tables on one router. Each interface belongs to one of them, and a packet is forwarded using only the table for the interface it arrived on.

What is the difference between a VRF and a VLAN?

A VLAN separates broadcast domains at layer 2. A VRF separates routing tables at layer 3. They stack: a VRF usually contains several VLANs.

Can two VRFs use the same IP addresses?

Yes, and it is one of the main reasons to use them. Each routing table is independent, so 10.0.0.0/24 can exist in two VRFs with different machines in it.

How do two VRFs communicate?

Only through route leaking, which is a deliberate configuration. Static routes in a simple deployment, route targets in an MPLS one.

What is VRF lite?

Virtual routing and forwarding without MPLS or BGP: interfaces assigned to VRFs, each with its own routes. It is what almost every enterprise network deployment actually is.

What is a route distinguisher?

A value prefixed to a route so that identical prefixes from different VRFs stay distinct when BGP carries them together. It is part of MPLS L3VPN, not of VRF lite.

What is a route target?

A tag that controls which VRFs a route is imported into. It is how selective sharing between VRFs is expressed in an MPLS deployment.

Does a VRF improve security?

Between VRFs, yes, and more strongly than a firewall rule, because there is no path rather than a rule that could be misconfigured. Inside a VRF it does nothing.

Does a VRF encrypt network traffic?

No. It separates routing and forwarding tables. The traffic itself is unchanged and as readable as anything else on the wire.

Why do my commands fail on a device with VRFs?

Because most commands default to the main routing table. Ping, traceroute and the show commands all need to be told which VRF to use.

What is a management VRF?

A VRF holding the management interfaces of network devices, reachable only from the administration machines. It keeps management reachable when production routing breaks, and it is the use case most worth adopting in an ordinary network.

Do I need MPLS to use VRFs?

No. VRF lite needs neither MPLS nor BGP. MPLS L3VPN exists because carrying many VRFs between many routers needs something better than a link per VRF.

How does this compare with VXLAN?

VXLAN carries layer 2 networks across a routed fabric; VRFs separate layer 3 routing tables. In a modern data center they are used together, with each tenant getting both.

Read next · Routing OSPF Explained Each VRF runs its own routing process, so a protocol like this one is configured per VRF rather than per router. Open this next12 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.