Hi I am looking at consolidating some Virtual routers installs into physical ccr1036 (&72) Current my vm's handle public internet and private p-t-p links. My thought was to use VRF to isolate the routing tables on the new consolidated ccr's. I am presuming all the interfaces that where the old private would get tagged with a vrf tag=??? And all the internet packet would get tagged with a different vrf tag. On the router I would have these interfaces A) Internet - B) Private - C) FromInside. I want to allow C to A or B and A to C or B to C. but never A <=> B (don't want to act as a transit). On B I am using bgp to clients and on A I am using BGP to ISP's. I was going to use a private BGP AS for the private links and not to mix it with my public AS on the internet. This sounds like stock standard stuff. Any gotchas to look for ? A