VXLAN Configuration Considerations
- Only one overlay gateway is supported.
- Only one-to-one mapping is allowed between a VLAN and a VNI.
- The default VLAN cannot be mapped to a VNI.
- No ports on the VLAN mapped to a VNI can have an IP address configured.
- A VNI can be carried by one or more VXLAN tunnels.
- Mapping a range of VLANs to a VNI for a VXLAN
overlay gateway is supported. Consider the following limitations when mapping
a
range of VLANs to a VNI for a VXLAN overlay gateway:
- For RUCKUS
ICX 7850devices, no more than 2 access ports per VLAN should be
configured. 4080 VLAN VNI mappings are supported. In order to support 4080
VLAN to VNI mappings, the forwarding profile needs to be changed from
profile 1 (the default) to profile 2. Refer to the
forwarding-profilecommand in the RUCKUS FastIron Command Reference and to the RUCKUS FastIron Management Configuration Guide for configuration information pertaining to forwarding profiles. - For RUCKUS ICX 7550 devices, no more than two access ports per VLAN should be configured. 3072 VLAN to VNI mappings are supported when a maximum of two access ports is configured for each VXLAN-mapped VLAN. 4080 VLAN to VNI mappings are supported when a maximum of one access port is configured for each VXLAN-mapped VLAN. To support these scaling numbers, the forwarding profile must be changed from profile 1 (the default) to profile 2.
- For RUCKUS ICX 8200 devices, no more than two access ports per VLAN should be configured. 32 VLAN to VNI mappings are supported.
- For RUCKUS
ICX 7850devices, no more than 2 access ports per VLAN should be
configured. 4080 VLAN VNI mappings are supported. In order to support 4080
VLAN to VNI mappings, the forwarding profile needs to be changed from
profile 1 (the default) to profile 2. Refer to the
- Extending a range of mapped VLANs over a VXLAN overlay gateway is supported.
- An interface must be configured for which the IP address is to be used as a source for the VxLAN tunnels on VxLAN Gateway. Only loopback and VE interfaces are supported.
- The underlay (or transport) network cannot belong to a user VRF. The source interface must be on the default VRF.
- VXLAN Routing In and Out of VXLAN Tunnels (RIOT) is supported for RUCKUS ICX 7550 and ICX 7850 devices only. A VLAN with a VE configuration can be mapped to a VNI. Also, a VE configuration is allowed on a VLAN mapped to a VNI.
- VXLAN encapsulation adds approximately 50 bytes of overhead to the MAC frame, which may cause frames to be rejected if the Maximum Transmission Unit (MTU) on the transport network cannot accommodate the extra bytes. Therefore, the MTU on the transport network port must be configured with a value greater than 1550 (1500 + 50) bytes. The typical host MTU is 1500 bytes.
- Jumbo frame support in the transport network is required if the overlay applications use a frame size larger than 1500 bytes.
- A LAG or Ethernet port on the VTEP that is connected to the VXLAN underlay (transport) network cannot be a route-only interface. In other words, route-only cannot be enabled on a LAG or physical port on which remote VTEPs are reachable.
- If multiple VTEPs are reachable through the same Ethernet or LAG port, the next-hop information (port or LAG ID, MAC address, VLAN ID) to reach the VTEPs must be the same.
- Because the static-ingress replication method is used to send BUM traffic over VXLAN tunnels, all VTEPs must be provisioned in full-mesh mode as far as VLAN extension is concerned.
Scaling Considerations
- For RUCKUS ICX 7850 devices, a maximum of 4080 VLANS can be mapped to VNIs when no more than two access ports per VLAN are configured.
- RUCKUS ICX 7550 devices, a maximum of 4080 VLANs can be mapped to VNIs when no more than one access port is configured. A maximum of 3072 VLANs can be mapped to VNIs when no more than two access ports are configured.
- For RUCKUS ICX 8200 devices, 32 VLAN to VNI mappings are supported. However, a maximum of four remote sites can be configured.
- A maximum of 32 remote sites (VXLAN tunnels) can be configured for RUCKUS ICX 7550 and ICX 7850 devices.
- A maximum of 16 IPv4 addresses can be configured for each VXLAN remote site (VTEP); that is, one primary IP address and up to 15 secondary IP addresses.
- The total number of Ethernet or LAG ports in all mapped VLANs cannot exceed 8000.
Protocol Considerations
- VXLAN remote sites support IPv4 addressing only.
- A VLAN with multicast snooping enabled cannot be mapped
to a VNI. Likewise, you cannot enable multicast snooping on a VLAN that is
mapped to a VNI. You can configure the
no multicast activeor theno multicast passivecommand to disable multicast snooping on a VLAN. If multicast snooping is enabled globally, you can configure theno ip multicast active,no ip multicast passive,no ipv6 multicast active, orno ipv6 multicast passivecommand to disable global multicast snooping. - VXLAN is not supported on MCT cluster devices.
- VXLAN RIOT is disabled by default. To enable a VE interface on a VXLAN-mapped VLAN, VXLAN RIOT must be enabled first. Refer to VXLAN Routing In and Out of Tunnels (RIOT).
- OSPF (and VXLAN RIOT in general) is supported only on overlay VE interfaces. An untagged Ethernet or LAG interface in a mapped VLAN cannot be used as an overlay interface.
VXLAN Feature Support
VXLAN Feature Support
Layer 3 Feature Support
| Layer 3 Features and Capabilities | Support on VXLAN |
|---|---|
| Routing on VXLAN-enabled VLAN | Yes with RIOT |
| ARP | Yes with RIOT |
| Overlay ICMP Ping | Yes |
| Routing Protocols on Overlay | Only OSPF over Overlay is supported. |
| Static Routes on Overlay | Yes |
| IPv6 ND | No |
| Layer 3 Routing Protocol Packets | No |