VXLAN Configuration Considerations

  • Only one overlay gateway is supported.
  • Only one-to-one mapping is allowed between a VLAN and a VNI.
  • The default VLAN cannot be mapped to a VNI.
  • No ports on the VLAN mapped to a VNI can have an IP address configured.
  • A VNI can be carried by one or more VXLAN tunnels.
  • Mapping a range of VLANs to a VNI for a VXLAN overlay gateway is supported. Consider the following limitations when mapping a range of VLANs to a VNI for a VXLAN overlay gateway:
    • For RUCKUS ICX 7850devices, no more than 2 access ports per VLAN should be configured. 4080 VLAN VNI mappings are supported. In order to support 4080 VLAN to VNI mappings, the forwarding profile needs to be changed from profile 1 (the default) to profile 2. Refer to the forwarding-profile command in the RUCKUS FastIron Command Reference and to the RUCKUS FastIron Management Configuration Guide for configuration information pertaining to forwarding profiles.
    • For RUCKUS ICX 7550 devices, no more than two access ports per VLAN should be configured. 3072 VLAN to VNI mappings are supported when a maximum of two access ports is configured for each VXLAN-mapped VLAN. 4080 VLAN to VNI mappings are supported when a maximum of one access port is configured for each VXLAN-mapped VLAN. To support these scaling numbers, the forwarding profile must be changed from profile 1 (the default) to profile 2.
    • For RUCKUS ICX 8200 devices, no more than two access ports per VLAN should be configured. 32 VLAN to VNI mappings are supported.
  • Extending a range of mapped VLANs over a VXLAN overlay gateway is supported.
  • An interface must be configured for which the IP address is to be used as a source for the VxLAN tunnels on VxLAN Gateway. Only loopback and VE interfaces are supported.
  • The underlay (or transport) network cannot belong to a user VRF. The source interface must be on the default VRF.
  • VXLAN Routing In and Out of VXLAN Tunnels (RIOT) is supported for RUCKUS ICX 7550 and ICX 7850 devices only. A VLAN with a VE configuration can be mapped to a VNI. Also, a VE configuration is allowed on a VLAN mapped to a VNI.
  • VXLAN encapsulation adds approximately 50 bytes of overhead to the MAC frame, which may cause frames to be rejected if the Maximum Transmission Unit (MTU) on the transport network cannot accommodate the extra bytes. Therefore, the MTU on the transport network port must be configured with a value greater than 1550 (1500 + 50) bytes. The typical host MTU is 1500 bytes.
  • Jumbo frame support in the transport network is required if the overlay applications use a frame size larger than 1500 bytes.
  • A LAG or Ethernet port on the VTEP that is connected to the VXLAN underlay (transport) network cannot be a route-only interface. In other words, route-only cannot be enabled on a LAG or physical port on which remote VTEPs are reachable.
  • If multiple VTEPs are reachable through the same Ethernet or LAG port, the next-hop information (port or LAG ID, MAC address, VLAN ID) to reach the VTEPs must be the same.
  • Because the static-ingress replication method is used to send BUM traffic over VXLAN tunnels, all VTEPs must be provisioned in full-mesh mode as far as VLAN extension is concerned.

Scaling Considerations

  • For RUCKUS ICX 7850 devices, a maximum of 4080 VLANS can be mapped to VNIs when no more than two access ports per VLAN are configured.
  • RUCKUS ICX 7550 devices, a maximum of 4080 VLANs can be mapped to VNIs when no more than one access port is configured. A maximum of 3072 VLANs can be mapped to VNIs when no more than two access ports are configured.
  • For RUCKUS ICX 8200 devices, 32 VLAN to VNI mappings are supported. However, a maximum of four remote sites can be configured.
  • A maximum of 32 remote sites (VXLAN tunnels) can be configured for RUCKUS ICX 7550 and ICX 7850 devices.
  • A maximum of 16 IPv4 addresses can be configured for each VXLAN remote site (VTEP); that is, one primary IP address and up to 15 secondary IP addresses.
  • The total number of Ethernet or LAG ports in all mapped VLANs cannot exceed 8000.

Protocol Considerations

  • VXLAN remote sites support IPv4 addressing only.
  • A VLAN with multicast snooping enabled cannot be mapped to a VNI. Likewise, you cannot enable multicast snooping on a VLAN that is mapped to a VNI. You can configure the no multicast active or the no multicast passive command to disable multicast snooping on a VLAN. If multicast snooping is enabled globally, you can configure the no ip multicast active, no ip multicast passive, no ipv6 multicast active, or no ipv6 multicast passive command to disable global multicast snooping.
  • VXLAN is not supported on MCT cluster devices.
  • VXLAN RIOT is disabled by default. To enable a VE interface on a VXLAN-mapped VLAN, VXLAN RIOT must be enabled first. Refer to VXLAN Routing In and Out of Tunnels (RIOT).
  • OSPF (and VXLAN RIOT in general) is supported only on overlay VE interfaces. An untagged Ethernet or LAG interface in a mapped VLAN cannot be used as an overlay interface.

VXLAN Feature Support

VXLAN Feature Support

Functionality on VXLAN-Enabled VLAN Support on VXLAN Access Port Support on VXLAN Network Port Comments
MAC FDB Yes Yes  
MAC learning disable Yes No  
MAC learning rate control No No Feature not supported on ICX devices.
Flow-based MAC address learning No No Feature not supported on ICX devices.
MAC address move notification Yes No  
MAC notification traps Yes No No MIB for VXLAN.
Port-based VLANs

- Tagged

- Untagged

Yes N/A  
Default VLAN No Yes VXLAN cannot be enabled on the default VLAN.
Static MAC Yes No  
Static MMAC No No  
Port MAC security Yes No  

Link aggregation

- Static LAG

- LACP

- Keep-alive LAG

Yes N/A Layer 3 connection to underlay network can be single port, LAG, ECMP.
LAG Hardware Failover Yes N/A  
VXLAN Tunnel Keep-Alive N/A Yes  
IEEE 802.1D Spanning Tree Yes N/A  
IEEE 802.1s Multiple Spanning Tree Yes N/A  
IEEE 802.1W Rapid Spanning Tree Protocol (RSTP) Yes N/A  
PVST/PVST+ compatibility Yes N/A  
SAV/Q-in-Q N/A N/A No Q-in-VNI support at this time.
Topology Group Yes N/A  
VLAN Group Yes N/A  
VLAN Range Yes N/A  
Metro Ring Protocol (MRP) No N/A  
Private VLAN No N/A  
UDLD No N/A  
VSRP No N/A  
Loop Detect No N/A  
MCT No N/A  
LOAM No N/A  
Ethernet remote loopback No N/A  

Layer 3 Feature Support

Layer 3 Features and Capabilities Support on VXLAN
Routing on VXLAN-enabled VLAN Yes with RIOT
ARP Yes with RIOT
Overlay ICMP Ping Yes
Routing Protocols on Overlay Only OSPF over Overlay is supported.
Static Routes on Overlay Yes
IPv6 ND No
Layer 3 Routing Protocol Packets No

Security Feature Support

Security Features Support on VXLAN-Enabled VLAN
IEEE 802.1x No