VRF Production Readiness Checklist
Checklist discipline. Every item is meant to be answered yes / no with evidence. Items marked critical are non-negotiable; items marked warn are judgement calls; items marked info are baseline expectations.
Items
- VRF naming convention consistent (severity: info)
- VRF table IDs unique and documented (severity: info)
- Every VRF-bound interface configured with description (severity: info)
- VRF-aware routing protocols configured per VRF (severity: info)
- Default-deny inter-VRF routing (no leaks without explicit policy) (severity: critical)
- Every route leak approved by change ticket (severity: critical)
- Firewall policy per VRF applied to inter-VRF path (severity: critical)
- VRF route tables monitored (severity: info)
- VRF documentation current (severity: info)
Severity legend
- info: baseline expectation
- warn: judgement call; production-grade depends on context
- critical: non-negotiable; a missed critical item is a release blocker
Evidence retention
The completed checklist is evidence for the change ticket, the audit, and the post-incident review. Store it where it can be recovered if the router is lost.