Featured Developer Sponsor • Zero-Token Protection
RFC 7432 BGP EVPN
RFC 7348 VXLAN Overlay
Spine-Leaf Clos Fabric
Symmetric IRB
BGP EVPN & VXLAN Datacenter Fabric Architecture Studio
Simulate BGP EVPN control plane route advertisements (Route Type 2 MAC/IP, Type 3 IMET, Type 5 IP Prefix), dissect 50-byte VXLAN packet encapsulation, model Symmetric vs Asymmetric IRB routing, and export production FRRouting and Arista EOS configs.
100% Client-Side Engine
EVPN Route Type Generator
16.7M tenant segments (e.g. VNI 10010 = Tenant Web Subnet)
BGP NLRI Attributes & Extended Communities
ARP Suppression Status
ACTIVE
Zero data-plane ARP flood
BUM Replication Method
Head-End (HER)
No PIM Multicast in Underlay
Frequently Asked Technical Questions
Why did BGP EVPN and VXLAN replace legacy Spanning Tree Protocol (STP) and 802.1Q VLANs in modern datacenters?+
Legacy enterprise datacenters relied on Layer 2 Spanning Tree Protocol (STP) and 802.1Q VLANs. STP had two fatal architectural flaws: (1) It disabled redundant links to prevent bridge loops, stranding up to 50% of expensive switch bandwidth; (2) 802.1Q tags are only 12 bits wide, capping total isolated tenant networks to 4,096 VLANs. Modern hyperscale datacenters deploy a Spine-and-Leaf Clos topology with BGP EVPN (RFC 7432) and VXLAN (RFC 7348): (1) The Underlay network is pure Layer 3 routed (using eBGP or OSPF/IS-IS), utilizing Equal-Cost Multi-Path (ECMP) across all links with zero disabled ports; (2) VXLAN encapsulates Layer 2/3 frames inside UDP packets with a 24-bit Virtual Network Identifier (VNI), supporting over 16.7 million isolated virtual networks; (3) BGP EVPN serves as a unified control plane, advertising MAC and IP reachability via BGP NLRI routes, eliminating broadcast-based data-plane flood-and-learn.
What are the core BGP EVPN Route Types defined in RFC 7432 and what purpose does each serve?+
BGP EVPN defines five standard Route Types within the L2VPN EVPN address family (AFI 25, SAFI 70): (1) Route Type 1 (Ethernet Auto-Discovery): Used for fast convergence and multi-homing split-horizon filtering when a server is dual-connected to two Leaf switches; (2) Route Type 2 (MAC/IP Advertisement): Advertises a host MAC address, optional IP address, and associated VNI. When Leaf A learns a host MAC on a local port, it sends a Type 2 route across BGP to all other Leaves, allowing them to install the forwarding entry without receiving a single broadcast packet; (3) Route Type 3 (Inclusive Multicast Ethernet Tag, IMET): Advertises a VTEP IP for a specific VNI, allowing remote Leaves to construct an automated Head-End Replication (HER) list for handling Broadcast, Unknown unicast, and Multicast (BUM) frames without requiring multicast in the underlay; (4) Route Type 4 (Ethernet Segment Route): Discovers redundant Leaf peers participating in the same active-active Multi-Chassis Link Aggregation (MLAG/ESI) group; (5) Route Type 5 (IP Prefix Route): Distributes inter-subnet routed prefixes (/24, /28) alongside VRF Route Targets for tenant L3 routing.
What is the 50-byte VXLAN encapsulation header overhead and why does it necessitate jumbo frames?+
When an original Ethernet frame is encapsulated in VXLAN (RFC 7348), the host or Leaf switch attaches 50 bytes of outer headers: (1) Outer Ethernet Header: 14 bytes (Outer Dst MAC, Src MAC, EtherType 0x0800); (2) Outer IPv4 Header: 20 bytes (Outer Src IP = local VTEP, Outer Dst IP = remote VTEP); (3) Outer UDP Header: 8 bytes (Dst Port 4789, Src Port = hash of inner packet flow for ECMP load balancing); (4) VXLAN Header: 8 bytes (Flags with VNI bit set, 24-bit VNI, reserved fields). If tenant VMs transmit standard 1,500-byte MTU packets, the encapsulated frame reaches 1,550 bytes. To prevent catastrophic IP packet fragmentation, datacenter physical switches must configure Jumbo Frames (typically 9,000 to 9,216 bytes MTU) across all physical underlay spine-leaf links.
What is the difference between Symmetric IRB and Asymmetric IRB in EVPN routing?+
Integrated Routing and Bridging (IRB) defines how traffic travels between two different subnets (e.g. Subnet 10 / VNI 10001 to Subnet 20 / VNI 10002) across an EVPN overlay: (1) Asymmetric IRB: The ingress Leaf switch performs BOTH routing and bridging. It routes the packet from VNI 10001 into VNI 10002 locally, and then bridges it across the VXLAN tunnel on VNI 10002. The egress Leaf merely bridges the packet out to the destination server. While conceptually simple, Asymmetric IRB requires every Leaf switch to configure EVERY tenant VNI and default gateway, causing severe MAC address table explosion on large networks; (2) Symmetric IRB: The ingress Leaf routes the packet into a dedicated Layer 3 transit VNI (L3VNI). The packet crosses the VXLAN tunnel on the L3VNI. The egress Leaf receives the packet, decapsulates it, and routes it from the L3VNI into the local destination L2VNI. Symmetric IRB requires Leaf switches to only configure the VNIs locally present on their physical ports, scaling to hundreds of thousands of tenants.
How does EVPN ARP Suppression eliminate the classic Broadcast Storm problem in large subnets?+
In a traditional Layer 2 network, when a host resolves an IP address, it broadcasts an ARP Request (FF:FF:FF:FF:FF:FF) across the entire broadcast domain, forcing every single switch to flood the frame to every connected port. In an EVPN fabric, when a host connects and sends its first packet, the local Leaf switch snoops its MAC and IP and broadcasts an EVPN Route Type 2 across the BGP control plane. Every remote Leaf switch caches this mapping in its local ARP/ND proxy table. When a remote host later issues an ARP request for that IP, the local Leaf intercepts the request and responds immediately from its local EVPN cache (ARP Suppression) without forwarding a single frame across the VXLAN fabric.
What is an Anycast Distributed Gateway in EVPN and why does it eliminate VRRP failover delays?+
In legacy networks, the default gateway was hosted on a pair of central aggregation switches running Virtual Router Redundancy Protocol (VRRP). Traffic from server A to server B in different subnets had to travel up to the core gateway and back down (traffic tromboning). Furthermore, only the active VRRP master could forward traffic. EVPN introduces Distributed Anycast Gateways: EVERY Leaf switch in the datacenter is configured with the EXACT same Virtual IP address and the EXACT same Virtual MAC address (e.g. IP 10.1.1.1, MAC 00:00:5E:00:01:01) for each subnet. A server connects to its default gateway on the very first switch hop. If a virtual machine migrates (vMotion / Live Migration) to a completely different rack, its default gateway IP and MAC remain identical and traffic routes locally with zero VRRP renegotiation or packet loss.
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement