A company uses VRF-lite to separate management traffic (VRF MGMT) from user traffic (VRF USER) on a Cisco Catalyst 3850 stack. The management network is 10.0.0.0/24, and the user network is 192.168.1.0/24. The engineer wants to allow SSH access from the user network to the management network for device administration. The switch has an SVI for each VRF. What is the simplest way to achieve this while maintaining VRF isolation?
This is correct because VRF route leaking explicitly permits the USER VRF to learn a route to the management SVI in the MGMT VRF without merging the two routing tables. By configuring a static route in VRF USER with the MGMT SVI IP as the next hop, and then enabling route leaking (for example, via import/export route targets or an appropriate leak statement), the switch installs only the necessary prefix into USER's RIB. This allows SSH from USER hosts to reach the MGMT VRF while all other traffic remains isolated, preserving the path-isolation requirement with minimal configuration overhead.
Why this answer
VRF-lite inherently isolates routing tables, so to allow SSH from VRF USER to VRF MGMT while maintaining isolation, you must leak routes between the VRFs. A static route in VRF USER pointing to the VRF MGMT SVI IP address, combined with route leaking (e.g., using `route-map` and `import/export` commands), enables the necessary reachability without merging the VRFs. This is the simplest method as it avoids additional hardware or complex configurations.
Exam trap
Cisco often tests the misconception that VRFs are completely isolated and cannot communicate without breaking isolation, but route leaking is the correct method to allow selective inter-VRF traffic while maintaining VRF separation.
How to eliminate wrong answers
Option B is wrong because placing both SVIs in the same VRF breaks VRF isolation entirely, defeating the purpose of separating management and user traffic. Option C is wrong because introducing a firewall is unnecessary and adds complexity; VRF-lite with route leaking can achieve the goal natively on the switch without external devices. Option D is wrong because configuring the switch to use the global routing table for SSH traffic only is not a standard or supported feature in VRF-lite; SSH traffic still follows the VRF routing table unless explicit route leaking is configured.