VXLAN configuration considerations

  • Only one overlay-gateway is supported.

  • Only one-to-one mapping is allowed between VLAN and VNI.

  • The default VLAN cannot be mapped to a VNI.

  • No ports on the VLAN mapped to VNI can have an IP address configured.

  • A VNI can be carried by one or more VXLAN tunnels.

  • A loopback interface address must be configured to be used as the source IP address for the VXLAN tunnels on the VXLAN gateway.

  • The underlay (or transport) network cannot belong to a user VRF. The loopback interface must belong to the default VRF.

  • Routing In and Out of VXLAN tunnels (RIOT) is not supported. As a result, a VLAN with VE configuration cannot be mapped to a VNI. Likewise, VE configuration is not allowed on a VLAN mapped to a VNI.

  • Routing functionality for the mapped VLANs should be provided by another router that is not part of the VXLAN gateway.

  • VXLAN encapsulation adds approximately 50 bytes of overhead to the MAC frame, which would cause frames to be rejected if the Maximum Transmission Unit (MTU) on the transport network cannot accommodate the extra bytes. Therefore, the MTU on the transport network port must be configured with a value greater than 1550 (1500 + 50) bytes. (The typical host MTU is 1500.)

  • Jumbo-frame support in the transport network is required if the overlay applications uses a frame size larger than 1500 bytes.

  • A LAG or Ethernet port on the VTEP that is connected to the VXLAN underlay (transport) network cannot be a route-only interface. In other words, the route-only feature cannot be enabled on a LAG or physical port on which remote VTEPs are reachable.

  • If multiple VTEPs are reachable via the same Ethernet or LAG port, then the Next-hop (port or LAG id, MAC address, VLAN id) information to reach the VTEPs should be the same.

  • Because the static-ingress-replication method is used to send BUM traffic over VXLAN tunnels, all VTEPs must be provisioned in full-mesh mode as far as VLAN extension is concerned.

Scaling considerations

  • A maximum of 256 VLANS can be mapped to VNIs.

  • A maximum of 32 remote sites (VXLAN tunnels) can be configured.

  • The total number of Ethernet or LAG ports in all mapped VLANs cannot exceed 8000.

Protocol considerations

  • VXLAN remote sites support IPv4 addressing only.
  • The VXLAN gateway feature is not supported in a Campus Fabric configuration. As a result, SPX must be disabled before you can configure an overlay-gateway (you can change the configuration to no cb spx enable).

  • A VLAN with multicast snooping enabled cannot be mapped to a VNI. Likewise, you cannot enable multicast snooping on a VLAN that is mapped to a VNI. You can configure the no multicast active or the no multicast passive command to disable multicast snooping on a VLAN. If multicast snooping is enabled globally, you can configure the no ip multicast active, no ip multicast passive, no ipv6 multicast active, or no ipv6 multicast passive command to disable global multicast snooping.
  • VXLAN is not supported on MCT cluster devices.
  • A VLAN with router interface ve enabled cannot be mapped to a VNI. Likewise, you cannot configure router ve interface on a VLAN that is mapped to a VNI.

VXLAN feature support

Functionality on VXLAN enabled VLAN Support on VXLAN access port Support on VXLAN network port Comments
MAC FDB Yes Yes  
Mac Learning Disable Yes No  
MAC learning rate control No No Feature not supported on FastIron ICX devices
Flow-based MAC address learning No No Feature not supported on FastIron ICX devices
MAC address move notification Yes No  
Mac-notification traps Yes No No MIB for VXLAN
Port-based VLANs
  • - Tagged
  • - Untagged
Yes NA  
Default VLAN No Yes VXLAN cannot be enabled on the default VLAN.
Static MAC Yes No  
Static MMAC No No  
Port MAC security Yes No  

Link aggregation

- static LAG

- LACP

- Keep-alive LAG

Yes NA Layer 3 connection to underlay network can be single port, LAG, ECMP.
LAG Hardware Failover Yes NA  
802.1D Spanning Tree Yes NA  
802.1s Multiple Spanning Tree Yes NA  
802.1W Rapid Spanning Tree Protocol (RSTP) Yes NA  
PVST/PVST+ compatibility Yes NA  
SAV/Q-in-Q NA NA No Q-in-VNI support at this time.
Topology Group Yes NA  
VLAN Group Yes NA  
VLAN Range Yes NA  
Metro Ring Protocol (MRP) No NA  
Private VLAN No NA  
UDLD No NA  
VSRP No NA  
Loop Detect No NA  
MCT No NA  
LOAM No NA  
Ethernet remote loopback No NA  

Layer 3 Features and Capabilities Support on VXLAN
Routing on VXLAN enable VLAN No
ARP No
IPV6 ND No
Layer 3 Routing Protocol Packets No

Security Features Support on VXLAN enabled VLAN
IEEE 802.1x No