Routelearn.net
Course menu

Course 4: VLANs and TrunksLesson 1.7 (7 of 7 in this course)15 of 91 in the CCNA series

VXLAN introduction

Carrying a logical Ethernet segment across a routed IP network by wrapping frames inside IP packets.

Advanced · 8 min read · Before this: VLAN, IP Addressing

VXLAN (Virtual Extensible LAN) is an overlay technology that carries Layer 2 Ethernet frames across a routed Layer 3 network by encapsulating them in UDP/IP packets. Tunnel endpoints called VTEPs add and remove the VXLAN header, whose 24-bit VNI identifies the segment and allows about 16 million segments, compared with roughly 4,000 VLANs.

In simple terms: VXLAN wraps Ethernet frames inside IP packets, so devices in different places can behave as if they were on the same switch even though routers sit between them.

The problem it solves

PVLANs control local forwarding permissions. VXLAN solves a different problem: carrying a logical Ethernet segment across a routed network. Two servers sit in different racks; the switches between the racks route IP, but the servers need to be in the same logical segment. VXLAN wraps the original Ethernet frame so it can travel across that IP network.

Four essential terms

TermMeaning
UnderlayThe IP network that connects the tunnel endpoints
OverlayThe logical network carried over the underlay
VTEPVXLAN Tunnel End Point: adds and removes the encapsulation
VNIVXLAN Network Identifier: identifies one logical segment

The underlay provides reachability between VTEPs; the overlay is the endpoints' logical network.

A packet journey

Assume the destination information is already known:

ComponentExample
Server A192.168.20.10/24
Server B192.168.20.20/24
Sending VTEP10.255.0.11
Receiving VTEP10.255.0.12
Logical segmentVNI 10020
Server A192.168.20.10VTEP 110.255.0.11Underlay routerVTEP 210.255.0.12Server B192.168.20.20
  1. 1. An ordinary frame. Server A sends a normal Ethernet frame toward Server B.
  2. 2. Encapsulated. VTEP 1 adds VXLAN (VNI 10020), UDP and outer IP headers addressed to VTEP 2.
  3. 3. Routed by the underlay. Underlay routers forward using the outer VTEP addresses only; they never look inside.
  4. 4. Decapsulated. VTEP 2 removes the outer headers and delivers the original frame to Server B.

Headers and port numbers

Outside → insideCarries
Outer EthernetNext-hop delivery on the physical link
Outer IPSource and destination VTEP addresses
UDPDestination port 4789 (the sending VTEP picks the source port)
VXLANThe VNI
Inner EthernetThe original endpoint frame

The VNI is 24 bits, about 16.7 million identifier values, compared with 4094 usable VLAN IDs. That's an identifier range, not a promise that any device can hold that many segments.

Why EVPN is often used

VXLAN only defines the encapsulation. Something still has to tell each VTEP which MAC and IP addresses sit behind which other VTEP. BGP EVPN distributes that overlay reachability, including MAC/IP advertisements. Keeping the jobs separate helps troubleshooting: underlay reachability, overlay information and local endpoint forwarding are three different checks.

Practical limits

  • MTU: with common IPv4 framing the outer headers add 50 bytes (counting the outer Ethernet header). Extra tags or an IPv6 underlay change the number. An MTU mismatch lets small tests pass while larger traffic is dropped.
  • No encryption: VXLAN doesn't encrypt traffic on its own.
  • Loops: a routed underlay doesn't remove every possible Layer 2 loop in the endpoint networks attached to it.
  • Configuration labs need a named platform (for example a specific Nexus model), software image, underlay routing design and EVPN design. Generic VLAN commands aren't enough for a complete fabric, so this introduction doesn't give one.

Practice with explained answers

Predict · scenario 1

Which IP addresses do underlay routers use to forward VXLAN traffic?

Predict · scenario 2

Small pings between Server A and Server B work, but large transfers stall.

Predict · scenario 3

What does BGP EVPN add that VXLAN alone doesn't provide?