The problem it solves
PVLANs control local forwarding permissions. VXLAN solves a different problem: carrying a logical Ethernet segment across a routed network. Two servers sit in different racks; the switches between the racks route IP, but the servers need to be in the same logical segment. VXLAN wraps the original Ethernet frame so it can travel across that IP network.
Four essential terms
| Term | Meaning |
|---|---|
| Underlay | The IP network that connects the tunnel endpoints |
| Overlay | The logical network carried over the underlay |
| VTEP | VXLAN Tunnel End Point: adds and removes the encapsulation |
| VNI | VXLAN Network Identifier: identifies one logical segment |
The underlay provides reachability between VTEPs; the overlay is the endpoints' logical network.
A packet journey
Assume the destination information is already known:
| Component | Example |
|---|---|
| Server A | 192.168.20.10/24 |
| Server B | 192.168.20.20/24 |
| Sending VTEP | 10.255.0.11 |
| Receiving VTEP | 10.255.0.12 |
| Logical segment | VNI 10020 |
- 1. An ordinary frame. Server A sends a normal Ethernet frame toward Server B.
- 2. Encapsulated. VTEP 1 adds VXLAN (VNI 10020), UDP and outer IP headers addressed to VTEP 2.
- 3. Routed by the underlay. Underlay routers forward using the outer VTEP addresses only; they never look inside.
- 4. Decapsulated. VTEP 2 removes the outer headers and delivers the original frame to Server B.
Headers and port numbers
| Outside → inside | Carries |
|---|---|
| Outer Ethernet | Next-hop delivery on the physical link |
| Outer IP | Source and destination VTEP addresses |
| UDP | Destination port 4789 (the sending VTEP picks the source port) |
| VXLAN | The VNI |
| Inner Ethernet | The original endpoint frame |
The VNI is 24 bits, about 16.7 million identifier values, compared with 4094 usable VLAN IDs. That's an identifier range, not a promise that any device can hold that many segments.
Why EVPN is often used
VXLAN only defines the encapsulation. Something still has to tell each VTEP which MAC and IP addresses sit behind which other VTEP. BGP EVPN distributes that overlay reachability, including MAC/IP advertisements. Keeping the jobs separate helps troubleshooting: underlay reachability, overlay information and local endpoint forwarding are three different checks.
Practical limits
- MTU: with common IPv4 framing the outer headers add 50 bytes (counting the outer Ethernet header). Extra tags or an IPv6 underlay change the number. An MTU mismatch lets small tests pass while larger traffic is dropped.
- No encryption: VXLAN doesn't encrypt traffic on its own.
- Loops: a routed underlay doesn't remove every possible Layer 2 loop in the endpoint networks attached to it.
- Configuration labs need a named platform (for example a specific Nexus model), software image, underlay routing design and EVPN design. Generic VLAN commands aren't enough for a complete fabric, so this introduction doesn't give one.
Practice with explained answers
Which IP addresses do underlay routers use to forward VXLAN traffic?
Small pings between Server A and Server B work, but large transfers stall.
What does BGP EVPN add that VXLAN alone doesn't provide?