Configuring VXLAN

Configuring a VXLAN gateway involves the following tasks.

  1. Configure a VXLAN gateway record.
  2. Set the VXLAN gateway type as a Layer 2 extension.
  3. Specify the loopback interface with the IP address that will be used as the source IP address for VXLAN tunnels.
    Note: The loopback interface must not belong to a user VRF. Be sure the specified IPv4 address is configured on this interface; otherwise, all VXLAN tunnels will be down.
  4. Map previously created VLANs, or a range of VLANs, to VXLAN Network Identifiers (VNIs).
  5. Configure one or more remote site records.
    • For each remote site, specify the primary IP address of the remote site VTEP and up to 15 secondary IP addresses. The primary IP address is used as the destination address for the VXLAN tunnel to that remote site. If the connection to the primary IP address fails and failure detection is enabled, the secondary IP addresses are used in the configured order based on the assigned index provided.
    • Make sure the remote VTEP IP addresses are reachable in the default VRF; otherwise, the VXLAN tunnel to the remote VTEP will be down.
  6. Configure failure detection.
    • Configure the interval (in seconds) at which a keep-alive message will be sent to the remote site (VTEP).
    • Configure the number of times (1 through 5) the keep-alive message is resent if no response is received.
  7. Extend each mapped VLAN, or range of VLANs, to the remote site.

Complete the following steps to configure a VXLAN overlay gateway.

Note: Only one overlay gateway can be configured.

  1. Name the overlay gateway and enter overlay-gateway configuration mode.
    device# configure terminal
    device(config)# overlay-gateway gate1
    device(config-overlay-gw-gate1)#
    
  2. Set the overlay gateway type as a Layer 2 extension.
    device(config-overlay-gw-gate1)# type layer2-extension
    
  3. Use the loopback interface command in overlay-gateway configuration mode to configure the IP interface for the overlay gateway.
    Note: You must use a loopback interface, rather than an explicit IPv4 address, as the source address.
    device(config-overlay-gw-gate1)# ip interface loopback 1
  4. Map a VLAN you intend to extend over the VXLAN segment (that is, over the overlay gateway) to a VXLAN Network Identifier (VNI).

    Note: A maximum of 256 VLAN to VNI pairs can be configured.
    Note: The default VLAN (typically, VLAN 1) cannot be mapped to a VNI or extended over a VXLAN segment.

    device(config-overlay-gw-gate1)# map vlan 2 to vni 3
  5. Create a remote site (VXLAN tunnel), and configure the IP addresses for the site.
    Note: Only IPv4 tunnels are supported.
    Note: A maximum of 32 remote sites can be created.
    Note: A maximum of 16 IP addresses; that is, one primary address and up to 15 secondary addresses can be configured per remote site. If the primary address fails, the secondary addresses will be tried in succession, based on the index number configured for each address. If a number has already been assigned to the IP address you configure, an error message is displayed. You must remove the existing configuration before you can reuse a configured number.
    device(config-overlay-gw-gate1)# site site1
    device(config-overlay-gw-gate1-site1)# ip address 67.67.67.1 primary
    device(config-overlay-gw-gate1-site1)# ip address 67.67.67.2 secondary 1
    device(config-overlay-gw-gate1-site1)# ip address 67.68.0.1 secondary 2
  6. Configure failure detection for the remote site. The allowable keep-alive interval is 1 through 20 seconds. The retry count can be configured as 1 through 5.
    device(config-overlay-gw-gate1-site1)# failure-detection keep-alive 20 retry 5
  7. Extend the mapped VLAN to the remote site.
    device(config-overlay-gw-gate1-site1)# extend vlan add 2
    

The following example configures overlay gateway gate1. VLAN 2 maps to VNI 3. A VXLAN tunnel is configured by creating a remote site (site1) and configuring its IP address (67.67.67.1) as the destination address. Redundant addresses and failure detection are configured for the remote site. The mapped VLAN (VLAN 2) is extended over the overlay gateway.

device# configure terminal
device(config)# overlay-gateway gate1
device(config-overlay-gw-gate1)# type layer2-extension
device(config-overlay-gw-gate1)# ip interface loopback 1
device(config-overlay-gw-gate1)# map vlan 2 to vni 3
device(config-overlay-gw-gate1)# site site1
device(config-overlay-gw-gate1-site1)# ip address 67.67.67.1 primary
device(config-overlay-gw-gate1-site1)# ip address 67.67.67.2 secondary 1
device(config-overlay-gw-gate1-site1)# ip address 67.68.0.1 secondary 2
device(config-overlay-gw-gate1-site1)# failure-detection keep-alive 20 retry 5
device(config-overlay-gw-gate1-site1)# extend vlan add 2
device(config-overlay-gw-gate1-site1)# end

device# show running-config overlay-gateway
overlay-gateway gateway1
 type layer2-extension
 ip interface Loopback 1
 map vlan 2 vni 3
 site site1
   ip address 67.67.67.1 primary
   ip address 67.67.67.2 secondary 1
   ip address 67.68.68.1 secondary 2
   extend vlan add 2

device# show overlay-gateway
Overlay Gateway Name    : gateway1
Type                    : layer2-extension
Source IP Interface     : loopback 1 (vrf: default-vrf, IP address: 32.32.31.13)
Total Mapped Vlans      : 1
Total Sites             : 1

The following example configures overlay gateway gate1. A range of VLANs (VLAN 200 through VLAN 300) maps to VNI 20000 and starts the VNI. A VXLAN tunnel is configured by creating a remote site (s1). The mapped VLANs (VLAN 200 through VLAN 300) are extended over the overlay gateway.

Note: This example is supported for router images only.
device# configure terminal
device(config)# overlay-gateway gate1
device(config-overlay-gw-gate1)# type layer2-extension
device(config-overlay-gw-gate1)# ip interface loopback 1
device(config-overlay-gw-gate1)# map vlan-range 200 to 300 vni-start 20000
device(config-overlay-gw-gate1)# site s1
device(config-overlay-gw-v1-site-s1)# extend vlan-range add 200 to 300

device# show overlay-gateway
Current configuration for overlay-gateway:
overlay-gateway v1
  type layer2-extension
  ip interface loopback 1
  map vlan-range 200 to 300 vni-start 20000
   map vlan 400 to vni 20400 
   site s1
     extend vlan-range add 200 to 300