Summary
Leaked VPNv4 routes from a VRF are temporarily withdrawn from the default VRF during every commit, even when the configuration change is unrelated to BGP or VRF routing.
Version Information
- VyOS version: 2026.06.10-0053-rolling
- Release train: rolling
- Release flavor: generic
Environment
I have the following VRFs configured:
- default
- test
Routes are leaked from vrf test into the default VRF using VPNv4 route leaking.
Relevant Configuration
set vrf name test protocols bgp address-family ipv4-unicast export vpn set vrf name test protocols bgp address-family ipv4-unicast rd vpn export '12345:200' set vrf name test protocols bgp address-family ipv4-unicast route-target vpn export '12345:200' set protocols bgp address-family ipv4-unicast import vpn set protocols bgp address-family ipv4-unicast route-target vpn import '12345:200'
Problem Description
Whenever I run any commit, leaked routes imported from vrf test into the default VRF are briefly removed from the routing table.
This happens even when the configuration change has nothing to do with BGP, VRFs, route leaking, or routing policy.
For example:
set policy route-map test rule 10 action 'permit' commit
The route-map in this example is not attached to any BGP neighbor or routing policy, but during the commit process all leaked routes disappear from the default VRF and are reinstalled only after the commit finishes.
Impact
This causes a traffic interruption of approximately 20 - 30 seconds.
During that time, customers relying on the leaked routes lose connectivity, including Internet access.
In a production environment, this makes even minor unrelated configuration changes disruptive, because every commit briefly withdraws and then reinstalls the leaked routes.
Expected Behavior
Configuration changes unrelated to BGP VPN route leaking should not cause imported routes to be withdrawn and reinstalled.
Leaked routes should remain present in the routing table throughout the commit process, or the reconfiguration process should be handled in a way that avoids any traffic interruption.
Actual Behavior
During every commit:
- The leaked routes are removed from the kernel routing table.
- The routes disappear from tools such as:
- ip route show vrf default
- route -n
- The routes are restored only after the commit completes.
This behavior is reproducible on every commit, including changes that are completely unrelated to BGP, VRFs, or route leaking.
Additional Information
I tested a similar setup on a clean FRRouting installation on Debian and did not observe this behavior there. In that setup, the route leak remains intact during unrelated configuration changes.
This suggests the issue may be related to VyOS commit handling rather than to FRRouting itself.
Reproduction Steps
- Configure two VRFs: default and test.
- Configure VPNv4 route leaking from vrf test into default.
- Verify that leaked routes are present in the default VRF.
- Apply any unrelated configuration change.
- Run commit.
- Observe that leaked routes are removed temporarily and then restored after commit completes.