1. What Is VXLAN EVPN?
VXLAN EVPN is a data center networking architecture that combines VXLAN, which provides the data-plane overlay, with Ethernet VPN (EVPN), which provides the control plane for distributing endpoint and network reachability information. Cisco describes VXLAN BGP EVPN as an overlay protocol suite that enables scalable Layer 2 and Layer 3 connectivity, uses BGP EVPN to advertise MAC/IP bindings, and supports multi-tenant network virtualization.
The easiest way to remember the relationship is: VXLAN carries the traffic; EVPN tells the network where endpoints and prefixes are. The physical network underneath is the underlay, while the logical tenant network is the overlay.
This combination is widely associated with modern leaf-spine data center fabrics because it separates the scalable IP transport from the logical Layer 2 and Layer 3 services delivered to workloads.
2. Why Data Centers Use VXLAN EVPN
Traditional VLAN-based designs can become difficult to scale across large leaf-spine environments. VLAN identifiers are limited, Layer 2 domains can become unnecessarily large, and flood-and-learn behavior can create operational challenges.
VXLAN expands the segmentation space through a 24-bit VXLAN Network Identifier (VNI), allowing a much larger number of logical segments than the 12-bit VLAN ID space. EVPN adds a BGP-based control plane that can distribute MAC and IP reachability information instead of relying only on data-plane learning.
| Challenge | Traditional VLAN Approach | VXLAN EVPN Approach |
|---|---|---|
| Segmentation scale | VLAN ID space | VNI-based overlay segmentation |
| Fabric transport | Often extended Layer 2 | IP routed underlay |
| Endpoint discovery | Can rely heavily on flood-and-learn | BGP EVPN distributes reachability |
| Multi-tenancy | VLAN/VRF combinations | VNIs, VRFs and EVPN policy |
| Path utilization | Design dependent | ECMP-friendly IP underlay |
| Workload mobility | Can require L2 extension | Overlay can extend logical segments across VTEPs |
3. VXLAN vs EVPN: What Does Each Technology Do?
| Technology | Primary Role | Simple Mental Model |
|---|---|---|
| VXLAN | Data-plane encapsulation | How the packet travels |
| EVPN | Control-plane signaling | How the network learns where destinations are |
| BGP | Routing/signaling protocol used for EVPN | How reachability information is distributed |
| VTEP | VXLAN tunnel endpoint | Where VXLAN starts or ends |
| VNI | VXLAN segment identifier | The overlay equivalent of a logical segment identifier |
| Underlay | IP transport network | The roads beneath the overlay |
A common beginner mistake is to treat VXLAN and EVPN as competing technologies. In a BGP EVPN VXLAN fabric, they solve different parts of the same architecture.
4. VXLAN EVPN Architecture
A typical VXLAN EVPN data center uses a spine-leaf topology. Leaf switches act as VTEPs and connect to servers or other endpoints. Spine switches provide the routed transport between leaves and can also act as BGP route reflectors in common designs.
Cisco’s current design guide describes the VXLAN BGP EVPN fabric as a routed fabric. The underlay provides Layer 3 ECMP between leaf and spine nodes, while the overlay uses MP-BGP EVPN to distribute endpoint and prefix reachability.
| Component | Role |
|---|---|
| Leaf / VTEP | Connects endpoints and encapsulates/decapsulates VXLAN traffic |
| Spine | Provides IP transport and can provide BGP EVPN route-reflector services |
| NVE interface | Logical interface used for VXLAN tunnel operation |
| VNI | Identifies a VXLAN segment |
| MP-BGP EVPN | Overlay control plane |
| Underlay routing | Provides VTEP-to-VTEP reachability |
| Route Reflector | Reduces the need for a full-mesh iBGP EVPN topology |
| Border Leaf / Gateway | Provides connectivity to external networks or other domains |
5. Core Components: VTEP, VNI, NVE and BGP
5.1 VTEP
A VXLAN Tunnel Endpoint (VTEP) is the device that performs VXLAN encapsulation and decapsulation. In a typical data center fabric, a leaf switch acts as the VTEP.
When traffic enters the overlay from a locally attached endpoint, the ingress VTEP can encapsulate the original Ethernet frame in a VXLAN/UDP/IP packet. The remote VTEP removes the VXLAN encapsulation and forwards the original traffic toward the destination endpoint.
5.2 VNI
The VXLAN Network Identifier is a 24-bit identifier carried in the VXLAN header. It identifies the logical VXLAN segment to which the encapsulated traffic belongs.
Layer 2 VNIs commonly represent bridge domains or VLAN-backed segments. Layer 3 VNIs can represent tenant VRF contexts in integrated routing and bridging designs.
5.3 NVE Interface
The Network Virtualization Edge interface is the logical interface through which VXLAN tunnel functionality is configured on supported platforms. Cisco documentation shows NVE interfaces using a source interface, commonly a loopback, and associating Layer 2 VNIs or Layer 3 VNIs with the NVE interface.
5.4 MP-BGP EVPN
BGP with the L2VPN EVPN address family is used as the control plane. It distributes information such as MAC/IP bindings, VTEP reachability and IP prefixes, depending on the route type and design.
6. Underlay vs Overlay
Understanding the underlay/overlay relationship is one of the most important skills for troubleshooting VXLAN EVPN.
| Layer | What It Does | Typical Technologies |
|---|---|---|
| Underlay | Provides IP reachability between fabric nodes/VTEPs | OSPF, IS-IS or eBGP; ECMP |
| Overlay | Provides logical tenant connectivity | VXLAN + BGP EVPN |
| Endpoint edge | Connects servers/workloads to the fabric | VLANs, port-channels, vPC or supported multihoming |
| External edge | Connects fabric to WAN, Internet or other networks | eBGP, OSPF, static routing, VRF-Lite or other supported mechanisms |
A critical troubleshooting principle follows from this architecture: if the underlay cannot reach the remote VTEP loopback, the overlay tunnel cannot work correctly. Always validate the transport before debugging the EVPN policy layer.
7. How VXLAN Encapsulation Works
VXLAN encapsulates an original Layer 2 Ethernet frame inside a UDP/IP packet. The outer IP header uses the source and destination VTEP addresses, while the VXLAN header carries the VNI.
| Header / Element | Purpose |
|---|---|
| Original Ethernet frame | The tenant/workload traffic being transported |
| VXLAN header | Carries the VNI and VXLAN-specific information |
| UDP | Provides transport for VXLAN; VXLAN commonly uses UDP destination port 4789 |
| Outer IP header | Carries the packet between source and destination VTEPs |
| Underlay routing | Forwards the outer IP packet across the fabric |
The important point is that intermediate underlay switches do not need to understand the tenant’s original Layer 2 frame. They route the outer IP packet toward the destination VTEP.
8. How BGP EVPN Works as the Control Plane
Without a control plane, a VXLAN fabric can use flood-and-learn techniques to discover remote MAC addresses. EVPN changes that model by using BGP to advertise endpoint reachability information.
Cisco’s documentation describes BGP EVPN as a standards-based control plane that supports dynamic endpoint discovery and efficient traffic forwarding. The exact route advertisements used depend on whether the fabric is carrying MAC/IP host routes, inclusive multicast information, or IP prefixes.
| Control-Plane Function | What EVPN Provides |
|---|---|
| Endpoint reachability | MAC and, where applicable, IP information |
| VTEP discovery | Information used to identify remote VTEPs and replication peers |
| IP prefix advertisement | Prefix reachability through EVPN Type 5 |
| Mobility | Control-plane signaling for endpoint movement |
| Multihoming | EVPN mechanisms for redundant Ethernet segments |
| Policy/segmentation | Route-target import/export controls which routes enter a VRF or EVPN instance |
9. EVPN Route Types You Need to Know
EVPN defines multiple BGP route types. For data center VXLAN work, network engineers should be comfortable with at least Type 2, Type 3 and Type 5. EVPN multihoming also introduces Ethernet Segment-related route types.
| Route Type | Name | Common Purpose |
|---|---|---|
| Type 1 | Ethernet Auto-Discovery (EAD) | Ethernet segment discovery and multihoming functions |
| Type 2 | MAC/IP Advertisement | Advertises MAC and IP host reachability |
| Type 3 | Inclusive Multicast Ethernet Tag (IMET) | Advertises VTEP/replication information for a VNI |
| Type 4 | Ethernet Segment | Supports Ethernet segment discovery and multihoming procedures |
| Type 5 | IP Prefix | Advertises IPv4/IPv6 prefixes without requiring a MAC in the route key |
Cisco’s current Nexus documentation explicitly identifies Type 2 for MAC/IP host information, Type 3 for VTEP information used for ingress replication, and Type 5 for IPv4/IPv6 prefixes. Exact behavior can vary with platform and deployment mode.
10. Layer 2 and Layer 3 VXLAN
10.1 Layer 2 VXLAN
Layer 2 VXLAN extends a logical Ethernet segment across an IP fabric. A VLAN or bridge-domain segment at one VTEP can be represented by a VNI and reached through another VTEP.
This is useful when workloads in different physical locations need to remain in the same logical Layer 2 segment, subject to the design and operational requirements of the environment.
10.2 Layer 3 VXLAN
Layer 3 VXLAN uses VRFs and Layer 3 VNIs to provide tenant routing across the overlay. Instead of stretching every VLAN everywhere, a fabric can route between subnets at the leaf while preserving tenant separation.
This is a major reason VXLAN EVPN is useful for modern data centers: the fabric can provide both Layer 2 bridging and Layer 3 routing through a unified architecture.
11. Integrated Routing and Bridging (IRB)
Integrated Routing and Bridging (IRB) combines Layer 2 bridging and Layer 3 routing functions in the EVPN VXLAN fabric. Cisco documents EVPN VXLAN integrated routing and bridging designs using Layer 2 and Layer 3 VNIs.
Two concepts commonly appear in design discussions: symmetric IRB and asymmetric IRB. The key distinction is where routing occurs and how the fabric carries the tenant context between ingress and egress VTEPs.
| Approach | High-Level Idea |
|---|---|
| Asymmetric IRB | Routing and bridging occur in a way that can require the receiving VTEP to resolve the destination in the destination bridge domain context. |
| Symmetric IRB | Uses a Layer 3 VNI/VRF context to carry routed traffic across the fabric, keeping the routing model more consistent across VTEPs. |
Exact forwarding behavior should be learned from the platform-specific Cisco documentation and lab captures rather than reduced to a single generic packet diagram.
12. Distributed Anycast Gateway
A distributed anycast gateway gives hosts a consistent default-gateway address across multiple leaf switches. Each participating leaf can provide the same gateway identity locally, allowing hosts to use their local leaf for first-hop routing.
This reduces the need to hairpin inter-subnet traffic to a centralized gateway and is a common building block for distributed Layer 3 forwarding in VXLAN EVPN fabrics.
The exact anycast gateway implementation and configuration syntax depend on the platform and software release.
13. EVPN Multihoming and Redundancy
Data center endpoints often need redundant connections to the network. EVPN provides standards-based mechanisms for Ethernet multihoming using Ethernet Segment Identifier (ESI) concepts. Cisco also supports vPC-based multihoming designs on Nexus platforms.
| Mechanism | Purpose |
|---|---|
| vPC | Cisco multichassis link aggregation mechanism commonly used for endpoint redundancy |
| EVPN ESI multihoming | Standards-based EVPN approach for representing a shared Ethernet segment |
| Anycast gateway | Provides consistent first-hop gateway behavior across leaf switches |
| ECMP | Uses multiple equal-cost underlay paths for resilient forwarding |
Do not assume every Nexus model and NX-OS release supports every EVPN multihoming feature identically. Always verify the platform-specific feature matrix.
14. VXLAN EVPN Multi-Site
VXLAN EVPN Multi-Site is designed to interconnect separate EVPN sites or fabrics over an IP network. Cisco documents Border Gateways (BGWs) as the devices that terminate and interconnect sites while providing a control boundary for traffic enforcement and failure containment.
The multi-site model is different from simply extending one large fabric. Each site can retain its own local EVPN control plane and IP forwarding domain while BGWs provide the inter-site boundary.
| Concept | Role |
|---|---|
| Site | A distinct VXLAN EVPN fabric/domain |
| Border Gateway | Terminates local overlay and connects the site to another site |
| Inter-site IP network | Provides transport between sites |
| Site separation | Provides a control and failure boundary between fabrics |
15. Traffic Flow: Step-by-Step Examples
15.1 Same Subnet, Different Leaf
- Host A sends an Ethernet frame to Host B.
- Ingress leaf identifies the destination using local/EVPN-learned information.
- The ingress leaf encapsulates the frame in VXLAN with the appropriate VNI.
- The underlay routes the outer IP packet across the spine toward the destination VTEP.
- The egress leaf decapsulates VXLAN and forwards the original frame to Host B.
15.2 Different Subnets
- Host A sends traffic to its default gateway.
- The local leaf provides the distributed gateway function.
- The leaf performs the Layer 3 lookup in the appropriate tenant VRF.
- The routed traffic is carried across the VXLAN EVPN fabric using the selected IRB model.
- The destination leaf forwards the traffic into the destination subnet.
15.3 External Network
For external connectivity, a border leaf or other supported gateway node connects the tenant VRF to an external routed domain. EVPN can carry the internal reachability while external routing protocols exchange prefixes with the outside network. Cisco documents per-VRF external connectivity using mechanisms such as eBGP, with other protocols supported depending on the design.
16. VXLAN EVPN vs Traditional VLAN Networking
| Area | Traditional VLAN-Based Design | VXLAN EVPN |
|---|---|---|
| Identifier space | 12-bit VLAN ID | 24-bit VNI |
| Transport | Often Layer 2 extension | Routed IP underlay |
| Control plane | Can rely on STP/flood-and-learn | BGP EVPN control plane |
| Scale | Constrained by VLAN/L2 design | Designed for larger logical segmentation |
| Routing | Often centralized or topology dependent | Distributed routing commonly supported |
| Multitenancy | VLAN/VRF combinations | VNI + VRF + EVPN |
| Mobility | Can require L2 extension | Overlay can provide logical segment mobility |
| Path utilization | Depends on topology | ECMP is fundamental to routed underlays |
17. VXLAN EVPN Troubleshooting Framework
Troubleshooting should move from the bottom of the architecture upward. Avoid starting with EVPN route tables if the underlay itself is broken.
| Layer | Questions to Ask |
|---|---|
| 1. Physical | Are links, optics, interfaces and port-channels up? |
| 2. Underlay | Can every relevant VTEP reach the remote VTEP loopback? Are routing adjacencies established? |
| 3. BGP EVPN | Is the EVPN address family established? Are routes being received and advertised? |
| 4. VTEP/NVE | Is the NVE interface operational? Are VNIs active and mapped correctly? |
| 5. EVPN routes | Do Type 2/3/5 routes exist where expected? |
| 6. VLAN/VNI mapping | Is the VLAN mapped to the correct VNI? |
| 7. VRF/L3 VNI | Is the tenant VRF associated with the correct Layer 3 VNI? |
| 8. Endpoint | Is the endpoint learned on the expected leaf/interface? |
| 9. Policy | Are route targets, filters or external routing policies preventing reachability? |
| 10. Packet path | Can you trace the expected ingress VTEP → spine → egress VTEP path? |
Common Troubleshooting Symptoms
- BGP EVPN session is down.
- Remote MAC/IP route is missing.
- NVE is up but the VNI is not operational.
- VTEP loopback is unreachable through the underlay.
- Correct VNI exists but VLAN-to-VNI mapping is wrong.
- Layer 2 works but inter-subnet routing fails.
- External prefixes are missing from the tenant VRF.
- MTU is too small for VXLAN encapsulation.
- A multihomed endpoint shows inconsistent forwarding behavior.
18. VXLAN EVPN and Cisco Data Center Certifications
VXLAN is directly relevant to Cisco data center networking training. NetMet Solutions’ current CCIE Data Center training materials list VXLAN and MP-BGP L2 EVPN within the Nexus module, and its current CCNP Data Center training page also lists VXLAN among the Nexus L2/L3 connectivity topics.
For certification preparation, learn VXLAN EVPN as an integrated architecture rather than as isolated commands: underlay routing, BGP EVPN, VTEPs, VNIs, endpoint learning, route types, IRB, multihoming and troubleshooting should fit into one mental model.
| Certification Preparation Area | What to Study |
|---|---|
| Nexus foundations | NX-OS, VLANs, vPC, routing and interface fundamentals |
| Underlay | OSPF, IS-IS or eBGP, loopbacks and ECMP |
| VXLAN | VTEP, NVE, VNI, encapsulation and MTU |
| EVPN | MP-BGP EVPN, route targets and route types |
| Routing | VRF, L3 VNI and IRB |
| High availability | Anycast gateway, vPC/EVPN multihoming |
| External connectivity | Border leaf/gateway, eBGP and prefix exchange |
| Troubleshooting | Control-plane verification, route inspection and packet-path analysis |
19. Common Learning Mistakes
- Memorising VXLAN commands without understanding the packet format.
- Treating VXLAN and EVPN as the same technology.
- Skipping underlay routing and jumping straight into BGP EVPN.
- Learning route types as numbers without knowing what information each carries.
- Confusing VTEP, VNI and NVE.
- Ignoring MTU requirements for encapsulation.
- Learning only Layer 2 VXLAN and skipping Layer 3 VNIs/VRFs.
- Not understanding the difference between symmetric and asymmetric IRB.
- Using a single vendor-independent diagram to explain platform-specific behavior.
- Troubleshooting the overlay before proving underlay reachability.
20. Beginner-to-Advanced Learning Path
| Stage | Focus | Practical Goal |
|---|---|---|
| 1. Beginner | Ethernet, VLANs, routing, BGP basics | Understand the network foundations |
| 2. Core VXLAN | VXLAN header, VTEP, VNI, NVE, encapsulation | Trace an encapsulated packet |
| 3. EVPN | MP-BGP EVPN and route types | Explain how endpoints are advertised |
| 4. Fabric | Leaf-spine, underlay, ECMP | Build and validate VTEP reachability |
| 5. L3 | VRFs, L3 VNIs, IRB, anycast gateway | Trace inter-subnet traffic |
| 6. Advanced | Multihoming, vPC, ESI, route type 5 | Design resilient fabrics |
| 7. Multi-site | BGWs and inter-site connectivity | Understand fabric boundaries |
| 8. Troubleshooting | Failures at every layer | Diagnose without guesswork |
| 9. Automation | APIs, templates, Ansible/Python where applicable | Make deployment repeatable |
A useful lab progression is: BGP underlay → VTEP reachability → Layer 2 VXLAN → BGP EVPN → Type 2/3 routes → Layer 3 VNI/IRB → anycast gateway → external routing → multihoming → multi-site scenarios. NetMet’s current lab-oriented material also uses VXLAN scenarios that vary VLAN/VNI/subnet and multicast combinations, which is useful for moving beyond simple configuration exercises.
21. Frequently Asked Questions
What is VXLAN EVPN?
VXLAN EVPN combines VXLAN as the data-plane overlay with BGP EVPN as the control plane for distributing endpoint and prefix reachability.
What is the difference between VXLAN and EVPN?
VXLAN defines how traffic is encapsulated and transported across the IP fabric; EVPN provides the BGP-based control plane that distributes reachability information.
What is a VTEP?
A VXLAN Tunnel Endpoint encapsulates and decapsulates VXLAN traffic. In typical data center fabrics, leaf switches act as VTEPs.
What is a VNI?
A VXLAN Network Identifier is a 24-bit identifier used to identify a logical VXLAN segment.
Why is BGP used with EVPN?
BGP provides a scalable control-plane mechanism for distributing MAC/IP bindings, VTEP information and IP prefixes through the EVPN address family.
What is EVPN Type 2?
Type 2 is the MAC/IP Advertisement route used to advertise MAC and IP host reachability.
What is EVPN Type 3?
Type 3 is the Inclusive Multicast Ethernet Tag route, commonly used to advertise information needed for VTEP/replication behavior.
What is EVPN Type 5?
Type 5 is the IP Prefix route used to advertise IPv4 or IPv6 prefixes without a MAC address in the route key.
What is a distributed anycast gateway?
It provides the same logical first-hop gateway identity on multiple leaf switches so hosts can route locally to their nearest leaf.
What is IRB?
Integrated Routing and Bridging combines Layer 2 bridging and Layer 3 routing functions within an EVPN VXLAN architecture.
Does VXLAN EVPN use an IP underlay?
Yes. A typical VXLAN BGP EVPN fabric uses a routed IP underlay with ECMP between leaf and spine nodes.
Is VXLAN EVPN part of Cisco data center training?
Yes. Current NetMet CCIE and CCNP Data Center training material lists VXLAN among its Nexus topics, including MP-BGP L2 EVPN in the CCIE material.
22. Conclusion
VXLAN EVPN can look complicated because it combines several technologies: a routed leaf-spine underlay, VXLAN encapsulation, VTEPs, VNIs, MP-BGP EVPN, route types, VRFs and distributed routing. The architecture becomes much easier to understand when each component has a clear job.
Think of the fabric in layers: the underlay answers ‘How do VTEPs reach each other?’; VXLAN answers ‘How is tenant traffic carried?’; EVPN answers ‘How does the fabric learn and advertise reachability?’; VRFs and VNIs answer ‘Which logical network does this traffic belong to?’; and IRB/anycast gateway answer ‘Where does routing happen?’
For network engineers, the most valuable skill is not memorising isolated commands. It is being able to predict the control-plane information, follow the packet path, verify each layer and troubleshoot failures systematically. That is the foundation for working with modern Cisco data center fabrics and preparing for advanced data center networking certifications.