VXLAN configuration considerations
Only one overlay-gateway is supported.
Only one-to-one mapping is allowed between VLAN and VNI.
The default VLAN cannot be mapped to a VNI.
No ports on the VLAN mapped to VNI can have an IP address configured.
A VNI can be carried by one or more VXLAN tunnels.
A loopback interface address must be configured to be used as the source IP address for the VXLAN tunnels on the VXLAN gateway.
The underlay (or transport) network cannot belong to a user VRF. The loopback interface must belong to the default VRF.
Routing In and Out of VXLAN tunnels (RIOT) is not supported. As a result, a VLAN with VE configuration cannot be mapped to a VNI. Likewise, VE configuration is not allowed on a VLAN mapped to a VNI.
Routing functionality for the mapped VLANs should be provided by another router that is not part of the VXLAN gateway.
VXLAN encapsulation adds approximately 50 bytes of overhead to the MAC frame, which would cause frames to be rejected if the Maximum Transmission Unit (MTU) on the transport network cannot accommodate the extra bytes. Therefore, the MTU on the transport network port must be configured with a value greater than 1550 (1500 + 50) bytes. (The typical host MTU is 1500.)
Jumbo-frame support in the transport network is required if the overlay applications uses a frame size larger than 1500 bytes.
A LAG or Ethernet port on the VTEP that is connected to the VXLAN underlay (transport) network cannot be a route-only interface. In other words, the route-only feature cannot be enabled on a LAG or physical port on which remote VTEPs are reachable.
If multiple VTEPs are reachable via the same Ethernet or LAG port, then the Next-hop (port or LAG id, MAC address, VLAN id) information to reach the VTEPs should be the same.
Because the static-ingress-replication method is used to send BUM traffic over VXLAN tunnels, all VTEPs must be provisioned in full-mesh mode as far as VLAN extension is concerned.
Scaling considerations
Protocol considerations
- VXLAN remote sites support IPv4 addressing only.
The VXLAN gateway feature is not supported in a Campus Fabric configuration. As a result, SPX must be disabled before you can configure an overlay-gateway (you can change the configuration to
no cb spx enable).- A VLAN with multicast snooping enabled
cannot be mapped to a VNI. Likewise, you cannot enable multicast snooping on
a
VLAN that is mapped to a VNI. You can configure the
no multicast activeor theno multicast passivecommand to disable multicast snooping on a VLAN. If multicast snooping is enabled globally, you can configure theno ip multicast active,no ip multicast passive,no ipv6 multicast active, orno ipv6 multicast passivecommand to disable global multicast snooping. - VXLAN is not supported on MCT cluster devices.
A VLAN with
router interface veenabled cannot be mapped to a VNI. Likewise, you cannot configurerouter ve interfaceon a VLAN that is mapped to a VNI.
VXLAN feature support
| Layer 3 Features and Capabilities | Support on VXLAN |
|---|---|
| Routing on VXLAN enable VLAN | No |
| ARP | No |
| IPV6 ND | No |
| Layer 3 Routing Protocol Packets | No |
| Security Features | Support on VXLAN enabled VLAN |
|---|---|
| IEEE 802.1x | No |