Virtual Routing and Forwarding (VRF)
A router feature that keeps several separate routing and forwarding tables on one device, so traffic in one instance has no route into another unless routes are deliberately shared.
Virtual Routing and Forwarding runs several independent routing and forwarding tables on one physical router or layer-3 switch. Each VRF instance owns a set of interfaces and knows only its own routes, so traffic in one instance has no route to another unless an administrator deliberately shares routes between them (commonly called route leaking). Two instances can reuse the same private address ranges. The ISC2 exam outline lists virtual routing and forwarding under logical segmentation in Domain 4.
Service providers use VRFs to keep customers apart on shared equipment, notably in the provider VPNs of RFC 4364, where MPLS carries each customer’s traffic between VRFs on different routers. Enterprises use VRFs without MPLS, for example to keep guest traffic apart from corporate traffic. Candidates commonly confuse the layer: a VLAN separates broadcast domains at layer 2, a VRF separates routing at layer 3, and a virtual domain separates a device’s whole policy and administration. A VRF gives separation, not inspection. It has no rule set of its own, and a careless route leak joins networks meant to stay apart.
Exam relevance: a scenario is likely to describe one router keeping customers or zones apart, perhaps with overlapping addresses. Candidates are expected to identify VRF as layer-3 logical network segmentation that still needs a separate control where traffic must be filtered.