3.3 Network Virtualization Overlays: LISP and VXLAN Encapsulation Mechanics
Key Takeaways
Network virtualization overlays decouple logical topologies and tenant segmentation from physical underlay IP routing, eliminating Spanning Tree scaling boundaries across modern campus and data center fabrics.
The Locator/ID Separation Protocol (LISP; originally RFC 6830, now RFC 9300 and RFC 9301) splits IP semantics into Endpoint Identifiers (EID) representing device identity and Routing Locators (RLOC) representing device location.
LISP encapsulation prepends an outer IP header and UDP header on destination port 4341 with an 8-byte LISP shim header, adding 36 bytes of overhead for IPv4 underlays.
Virtual Extensible LAN (VXLAN, RFC 7348) encapsulates Layer 2 Ethernet frames in UDP destination port 4789 with a 24-bit Virtual Network Identifier (VNI), supporting over 16 million logical segments.
Multiprotocol BGP EVPN (RFC 7432) replaces traditional data-plane flood-and-learn mechanics with control-plane route advertisements (Type 2 MAC/IP, Type 3 BUM, Type 5 IP prefix), suppressing ARP flooding.
Network Virtualization Overlays: LISP and VXLAN Encapsulation Mechanics
Enterprise campus and data center fabrics require agile, non-blocking architectures capable of supporting multi-tenancy, pervasive Layer 2 mobility, and granular security segmentation. Traditional architectures that extended Layer 2 VLANs across distribution and core switches suffered from Spanning Tree loop vulnerabilities, link blocking, and rigid subnet boundaries.
Network virtualization overlays decouple logical network services from physical infrastructure. By encapsulating tenant traffic inside standard IP/UDP packets, overlay technologies transport Layer 2 frames and Layer 3 segments across an arbitrary, routed Layer 3 physical underlay fabric.
Principles of Overlay Networking: Underlay vs. Overlay
Overlay networking establishes a clean architectural separation between physical transport and virtualized network services:
- Underlay Network: The physical network of switches, routers, and high-speed point-to-point links configured with an Interior Gateway Protocol (such as IS-IS, OSPF, or BGP). The underlay provides reliable, high-speed, equal-cost multi-path (ECMP) packet delivery between edge switches. Underlay switches require zero knowledge of tenant MAC addresses, overlay VLANs, or client subnets.
- Overlay Network: The logical topology formed by tunneling protocols operating over the underlay. Edge devices encapsulate tenant traffic at the ingress boundary, forward the packet across the routed underlay using outer IP headers, and decapsulate it at the egress edge device. Overlays enable arbitrary Layer 2 or Layer 3 connectivity independent of the underlying physical topology.
Locator/ID Separation Protocol (LISP - RFC 9300/9301)
Standard IP addressing conflates two distinct concepts into a single address:
- Identity: Who the endpoint is (used by transport and application sessions).
- Location: Where the endpoint attaches to the network hierarchy (used by routers to forward packets).
When a host moves across subnets, its IP address must either change (breaking active sessions) or the network must inject host-specific /32 routes into global core routing tables, causing severe routing table bloat. Locator/ID Separation Protocol (LISP) resolves this challenge by dividing the address space into two distinct namespaces:
- Endpoint Identifier (EID): The IP address assigned to an end-host. EIDs remain constant regardless of endpoint location or mobility. EIDs are non-routable in the underlay core.
- Routing Locator (RLOC): The IP address of the LISP edge router connecting the site to the underlay. RLOCs are globally routable across the underlay core.
LISP Architecture and Device Roles
- Ingress Tunnel Router (ITR): Edge router that receives packets from local client EIDs destined for remote EIDs. The ITR queries the Map-Resolver to find the destination RLOC, encapsulates the packet in an outer LISP header, and transmits it across the underlay.
- Egress Tunnel Router (ETR): Edge router that receives LISP-encapsulated packets from the underlay, strips the outer headers, and forwards the native packet to the local destination EID. ETRs also register local EID prefixes with the Map-Server.
- Map-Server (MS): Centralized control plane database that receives authoritative
Map-Registermessages from ETRs and maintains the master EID-to-RLOC mapping table. - Map-Resolver (MR): Receives
Map-Requestqueries from ITRs and forwards them toward the Map-Server. The Map-Server either forwards the request to the authoritative ETR, which sends theMap-Replydirectly to the ITR, or answers on the ETR's behalf when proxy-reply is enabled, as in SD-Access. LISP control messages use UDP port 4342. - Proxy ITR (PITR) & Proxy ETR (PETR): Gateway routers bridging LISP sites with non-LISP Internet or legacy networks.
LISP Encapsulation and Header Breakdown
LISP encapsulates inner IP packets inside an outer IP header, an outer UDP header, and an 8-byte LISP header:
| Layer | Header Component | Size | Function |
|---|---|---|---|
| Outer IP | Delivery IPv4 Header | 20 Bytes | Source RLOC (ingress router) and Destination RLOC (egress router); IP protocol 17 (UDP). |
| Outer UDP | UDP Header | 8 Bytes | Destination port 4341; source port is a hash of the inner flow for underlay ECMP entropy. |
| LISP Shim | LISP Header | 8 Bytes | Contains LISP flags (N, L, E, V, I), a 24-bit Instance ID (for VRF segmentation), and nonce. |
| Payload | Original IP Packet | Variable | Original inner IP packet sent by the client endpoint. |
Total LISP encapsulation overhead is 36 bytes (20 bytes outer IPv4 + 8 bytes UDP + 8 bytes LISP).
Virtual Extensible LAN (VXLAN - RFC 7348)
Traditional enterprise networks relied on IEEE 802.1Q VLANs for Layer 2 segmentation. However, 802.1Q uses a 12-bit VLAN identifier, constraining networks to a maximum of 4,094 VLANs—insufficient for cloud-scale multi-tenant environments.
Virtual Extensible LAN (VXLAN) is an industry-standard network virtualization overlay protocol that addresses these limitations:
- 24-Bit Identifier: VXLAN introduces a 24-bit Virtual Network Identifier (VNI), supporting up to 16,777,216 (16 million) unique virtual networks.
- MAC-in-IP Encapsulation: VXLAN encapsulates complete Layer 2 Ethernet frames inside Layer 4 UDP datagrams, allowing Layer 2 domains to span across routed Layer 3 boundaries without Spanning Tree.
- VXLAN Tunnel Endpoint (VTEP): Network hardware switches (leaf nodes) or hypervisor virtual switches that perform VXLAN encapsulation and decapsulation. Each VTEP has an underlay IP address.
VXLAN Header Format
| Layer | Header Component | Size | Key Fields and Operational Characteristics |
|---|---|---|---|
| Outer L2 | Outer Ethernet Header | 14 Bytes | Next-hop physical MAC addresses traversed across intermediate underlay hops. |
| Outer L3 | Outer IPv4 Header | 20 Bytes | Source IP = Source VTEP underlay address; Destination IP = Remote VTEP underlay address. |
| Outer L4 | Outer UDP Header | 8 Bytes | Destination port 4789 (standardized in RFC 7348); source port is dynamic hash for ECMP. |
| Overlay | VXLAN Header | 8 Bytes | Includes 8-bit flags (I-flag set to 1 for valid VNI) and the 24-bit VXLAN Network Identifier (VNI). |
| Payload | Inner Client Ethernet Frame | Variable | Original Ethernet frame including client source/destination MAC, inner IP, and payload. |
Total VXLAN encapsulation overhead is 50 bytes (14 + 20 + 8 + 8). If an 802.1Q tag is preserved inside the inner frame, overhead increases to 54 bytes.
Underlay MTU Requirements
Because VXLAN adds 50 bytes of overhead, an unfragmented 1500-byte client Ethernet frame expands to 1550 bytes. To prevent packet drops or costly IP fragmentation at line rates, all intermediate underlay physical switch interfaces must support Jumbo frames, configured with an MTU of at least 1550–1600 bytes (enterprise best practice standardizes underlay MTU at 9100–9216 bytes).
Control Plane Evolution: Flood-and-Learn vs. BGP EVPN
Early VXLAN implementations (RFC 7348) relied strictly on data-plane flood-and-learn mechanics without an explicit control plane:
- Unknown unicast, broadcast, and multicast (BUM) traffic required mapping each overlay VNI to an underlay IP multicast group.
- Underlay networks were forced to run Protocol Independent Multicast (PIM), introducing high state overhead, operational complexity, and slow convergence.
Multiprotocol BGP EVPN (RFC 7432 / RFC 8365)
Modern enterprise and data center fabrics pair VXLAN data-plane encapsulation with Multiprotocol BGP Ethernet VPN (BGP EVPN) as the standardized control plane:
- Control-Plane Learning: Leaf switches discover local host MAC and IP addresses through snooping and 802.1X/DHCP, advertising them to other VTEPs via MP-BGP Address Family
l2vpn evpn. - ARP Suppression: VTEPs inspect incoming ARP requests locally against their BGP EVPN database. If the target MAC is known, the VTEP responds directly with a proxy ARP reply, completely suppressing ARP broadcasts across the fabric.
- Integrated Routing and Bridging (IRB): Supports symmetric and asymmetric routing between different VNIs directly on leaf switches.
Key BGP EVPN Route Types
- Route Type 2 (MAC/IP Advertisement): Advertises individual endpoint MAC addresses and optional host IP addresses, along with the advertising VTEP's IP and VNI.
- Route Type 3 (Inclusive Multicast Ethernet Tag): Discovers remote VTEPs participating in a specific VNI, enabling underlay ingress replication for BUM traffic without requiring underlay PIM multicast.
- Route Type 5 (IP Prefix Route): Advertises routed subnets or external default routes across the overlay fabric for Layer 3 inter-tenant routing.
Overlay Comparison: LISP vs. VXLAN
| Technical Attribute | Locator/ID Separation Protocol (LISP) | Virtual Extensible LAN (VXLAN) |
|---|---|---|
| Standard RFC | RFC 9300/9301 (originally RFC 6830) | RFC 7348 |
| Encapsulation Layer | Layer 3 (Encapsulates IP packets) | Layer 2 (Encapsulates full Ethernet frames) |
| UDP Destination Port | Port 4341 | Port 4789 |
| Segmentation Identifier | 24-bit Instance ID (IID) | 24-bit VXLAN Network Identifier (VNI) |
| Encapsulation Overhead | 36 Bytes (IPv4 outer) | 50 Bytes (Outer L2 + IP + UDP + VXLAN) |
| Primary Control Plane | Map-Server / Map-Resolver (Pull model) | MP-BGP EVPN (Push model) or Multicast |
| Fabric Architecture Role | Host tracking & control plane in Cisco SD-Access | Data-plane encapsulation in SD-Access & DC fabrics |
Which UDP destination port and network identifier size are standardized by RFC 7348 for Virtual Extensible LAN (VXLAN) encapsulation?
UDP port 4341 and a 16-bit Security Group Tag
UDP port 4789 and a 24-bit Virtual Network Identifier
UDP port 12346 and a 32-bit System IP address
UDP port 4500 and a 12-bit VLAN identifier
In the Locator/ID Separation Protocol (LISP) control plane, what is the primary operational responsibility of the Map-Resolver (MR)?
It intercepts external internet frames and translates 802.1Q tags to LISP Instance IDs
It encapsulates Layer 2 Ethernet frames into outer UDP packets using destination port 4789 before sending them to the ETR
It dynamically assigns IP addresses to roaming mobile endpoints by answering their DHCP discover messages at each new site
It receives Map-Requests from ITRs and forwards them toward the Map-Server for the authoritative answer
Which BGP EVPN route type is responsible for distributing endpoint MAC addresses and optional host IP addresses to enable unicast forwarding and suppress broadcast ARP flooding?
Route Type 2 (MAC/IP Advertisement Route)
Route Type 3 (Inclusive Multicast Ethernet Tag Route)
Route Type 4 (Ethernet Segment Route)
Route Type 5 (IP Prefix Route)
Sections you finish are checked off in the contents.