3.3 Network Virtualization Overlays: LISP and VXLAN Encapsulation Mechanics

Key Takeaways

  • Network virtualization overlays decouple logical topologies and tenant segmentation from physical underlay IP routing, eliminating Spanning Tree scaling boundaries across modern campus and data center fabrics.

  • The Locator/ID Separation Protocol (LISP; originally RFC 6830, now RFC 9300 and RFC 9301) splits IP semantics into Endpoint Identifiers (EID) representing device identity and Routing Locators (RLOC) representing device location.

  • LISP encapsulation prepends an outer IP header and UDP header on destination port 4341 with an 8-byte LISP shim header, adding 36 bytes of overhead for IPv4 underlays.

  • Virtual Extensible LAN (VXLAN, RFC 7348) encapsulates Layer 2 Ethernet frames in UDP destination port 4789 with a 24-bit Virtual Network Identifier (VNI), supporting over 16 million logical segments.

  • Multiprotocol BGP EVPN (RFC 7432) replaces traditional data-plane flood-and-learn mechanics with control-plane route advertisements (Type 2 MAC/IP, Type 3 BUM, Type 5 IP prefix), suppressing ARP flooding.

Last updated: October 2026

Network Virtualization Overlays: LISP and VXLAN Encapsulation Mechanics

Enterprise campus and data center fabrics require agile, non-blocking architectures capable of supporting multi-tenancy, pervasive Layer 2 mobility, and granular security segmentation. Traditional architectures that extended Layer 2 VLANs across distribution and core switches suffered from Spanning Tree loop vulnerabilities, link blocking, and rigid subnet boundaries.

Network virtualization overlays decouple logical network services from physical infrastructure. By encapsulating tenant traffic inside standard IP/UDP packets, overlay technologies transport Layer 2 frames and Layer 3 segments across an arbitrary, routed Layer 3 physical underlay fabric.

Principles of Overlay Networking: Underlay vs. Overlay

Overlay networking establishes a clean architectural separation between physical transport and virtualized network services:

  • Underlay Network: The physical network of switches, routers, and high-speed point-to-point links configured with an Interior Gateway Protocol (such as IS-IS, OSPF, or BGP). The underlay provides reliable, high-speed, equal-cost multi-path (ECMP) packet delivery between edge switches. Underlay switches require zero knowledge of tenant MAC addresses, overlay VLANs, or client subnets.
  • Overlay Network: The logical topology formed by tunneling protocols operating over the underlay. Edge devices encapsulate tenant traffic at the ingress boundary, forward the packet across the routed underlay using outer IP headers, and decapsulate it at the egress edge device. Overlays enable arbitrary Layer 2 or Layer 3 connectivity independent of the underlying physical topology.

Locator/ID Separation Protocol (LISP - RFC 9300/9301)

Standard IP addressing conflates two distinct concepts into a single address:

  1. Identity: Who the endpoint is (used by transport and application sessions).
  2. Location: Where the endpoint attaches to the network hierarchy (used by routers to forward packets).

When a host moves across subnets, its IP address must either change (breaking active sessions) or the network must inject host-specific /32 routes into global core routing tables, causing severe routing table bloat. Locator/ID Separation Protocol (LISP) resolves this challenge by dividing the address space into two distinct namespaces:

  • Endpoint Identifier (EID): The IP address assigned to an end-host. EIDs remain constant regardless of endpoint location or mobility. EIDs are non-routable in the underlay core.
  • Routing Locator (RLOC): The IP address of the LISP edge router connecting the site to the underlay. RLOCs are globally routable across the underlay core.

LISP Architecture and Device Roles

  • Ingress Tunnel Router (ITR): Edge router that receives packets from local client EIDs destined for remote EIDs. The ITR queries the Map-Resolver to find the destination RLOC, encapsulates the packet in an outer LISP header, and transmits it across the underlay.
  • Egress Tunnel Router (ETR): Edge router that receives LISP-encapsulated packets from the underlay, strips the outer headers, and forwards the native packet to the local destination EID. ETRs also register local EID prefixes with the Map-Server.
  • Map-Server (MS): Centralized control plane database that receives authoritative Map-Register messages from ETRs and maintains the master EID-to-RLOC mapping table.
  • Map-Resolver (MR): Receives Map-Request queries from ITRs and forwards them toward the Map-Server. The Map-Server either forwards the request to the authoritative ETR, which sends the Map-Reply directly to the ITR, or answers on the ETR's behalf when proxy-reply is enabled, as in SD-Access. LISP control messages use UDP port 4342.
  • Proxy ITR (PITR) & Proxy ETR (PETR): Gateway routers bridging LISP sites with non-LISP Internet or legacy networks.

LISP Encapsulation and Header Breakdown

LISP encapsulates inner IP packets inside an outer IP header, an outer UDP header, and an 8-byte LISP header:

LayerHeader ComponentSizeFunction
Outer IPDelivery IPv4 Header20 BytesSource RLOC (ingress router) and Destination RLOC (egress router); IP protocol 17 (UDP).
Outer UDPUDP Header8 BytesDestination port 4341; source port is a hash of the inner flow for underlay ECMP entropy.
LISP ShimLISP Header8 BytesContains LISP flags (N, L, E, V, I), a 24-bit Instance ID (for VRF segmentation), and nonce.
PayloadOriginal IP PacketVariableOriginal inner IP packet sent by the client endpoint.

Total LISP encapsulation overhead is 36 bytes (20 bytes outer IPv4 + 8 bytes UDP + 8 bytes LISP).

Virtual Extensible LAN (VXLAN - RFC 7348)

Traditional enterprise networks relied on IEEE 802.1Q VLANs for Layer 2 segmentation. However, 802.1Q uses a 12-bit VLAN identifier, constraining networks to a maximum of 4,094 VLANs—insufficient for cloud-scale multi-tenant environments.

Virtual Extensible LAN (VXLAN) is an industry-standard network virtualization overlay protocol that addresses these limitations:

  • 24-Bit Identifier: VXLAN introduces a 24-bit Virtual Network Identifier (VNI), supporting up to 16,777,216 (16 million) unique virtual networks.
  • MAC-in-IP Encapsulation: VXLAN encapsulates complete Layer 2 Ethernet frames inside Layer 4 UDP datagrams, allowing Layer 2 domains to span across routed Layer 3 boundaries without Spanning Tree.
  • VXLAN Tunnel Endpoint (VTEP): Network hardware switches (leaf nodes) or hypervisor virtual switches that perform VXLAN encapsulation and decapsulation. Each VTEP has an underlay IP address.

VXLAN Header Format

LayerHeader ComponentSizeKey Fields and Operational Characteristics
Outer L2Outer Ethernet Header14 BytesNext-hop physical MAC addresses traversed across intermediate underlay hops.
Outer L3Outer IPv4 Header20 BytesSource IP = Source VTEP underlay address; Destination IP = Remote VTEP underlay address.
Outer L4Outer UDP Header8 BytesDestination port 4789 (standardized in RFC 7348); source port is dynamic hash for ECMP.
OverlayVXLAN Header8 BytesIncludes 8-bit flags (I-flag set to 1 for valid VNI) and the 24-bit VXLAN Network Identifier (VNI).
PayloadInner Client Ethernet FrameVariableOriginal Ethernet frame including client source/destination MAC, inner IP, and payload.

Total VXLAN encapsulation overhead is 50 bytes (14 + 20 + 8 + 8). If an 802.1Q tag is preserved inside the inner frame, overhead increases to 54 bytes.

Underlay MTU Requirements

Because VXLAN adds 50 bytes of overhead, an unfragmented 1500-byte client Ethernet frame expands to 1550 bytes. To prevent packet drops or costly IP fragmentation at line rates, all intermediate underlay physical switch interfaces must support Jumbo frames, configured with an MTU of at least 1550–1600 bytes (enterprise best practice standardizes underlay MTU at 9100–9216 bytes).

Control Plane Evolution: Flood-and-Learn vs. BGP EVPN

Early VXLAN implementations (RFC 7348) relied strictly on data-plane flood-and-learn mechanics without an explicit control plane:

  • Unknown unicast, broadcast, and multicast (BUM) traffic required mapping each overlay VNI to an underlay IP multicast group.
  • Underlay networks were forced to run Protocol Independent Multicast (PIM), introducing high state overhead, operational complexity, and slow convergence.

Multiprotocol BGP EVPN (RFC 7432 / RFC 8365)

Modern enterprise and data center fabrics pair VXLAN data-plane encapsulation with Multiprotocol BGP Ethernet VPN (BGP EVPN) as the standardized control plane:

  • Control-Plane Learning: Leaf switches discover local host MAC and IP addresses through snooping and 802.1X/DHCP, advertising them to other VTEPs via MP-BGP Address Family l2vpn evpn.
  • ARP Suppression: VTEPs inspect incoming ARP requests locally against their BGP EVPN database. If the target MAC is known, the VTEP responds directly with a proxy ARP reply, completely suppressing ARP broadcasts across the fabric.
  • Integrated Routing and Bridging (IRB): Supports symmetric and asymmetric routing between different VNIs directly on leaf switches.

Key BGP EVPN Route Types

  • Route Type 2 (MAC/IP Advertisement): Advertises individual endpoint MAC addresses and optional host IP addresses, along with the advertising VTEP's IP and VNI.
  • Route Type 3 (Inclusive Multicast Ethernet Tag): Discovers remote VTEPs participating in a specific VNI, enabling underlay ingress replication for BUM traffic without requiring underlay PIM multicast.
  • Route Type 5 (IP Prefix Route): Advertises routed subnets or external default routes across the overlay fabric for Layer 3 inter-tenant routing.

Overlay Comparison: LISP vs. VXLAN

Technical AttributeLocator/ID Separation Protocol (LISP)Virtual Extensible LAN (VXLAN)
Standard RFCRFC 9300/9301 (originally RFC 6830)RFC 7348
Encapsulation LayerLayer 3 (Encapsulates IP packets)Layer 2 (Encapsulates full Ethernet frames)
UDP Destination PortPort 4341Port 4789
Segmentation Identifier24-bit Instance ID (IID)24-bit VXLAN Network Identifier (VNI)
Encapsulation Overhead36 Bytes (IPv4 outer)50 Bytes (Outer L2 + IP + UDP + VXLAN)
Primary Control PlaneMap-Server / Map-Resolver (Pull model)MP-BGP EVPN (Push model) or Multicast
Fabric Architecture RoleHost tracking & control plane in Cisco SD-AccessData-plane encapsulation in SD-Access & DC fabrics
Test Your Knowledge

Which UDP destination port and network identifier size are standardized by RFC 7348 for Virtual Extensible LAN (VXLAN) encapsulation?

A

UDP port 4341 and a 16-bit Security Group Tag

B

UDP port 4789 and a 24-bit Virtual Network Identifier

C

UDP port 12346 and a 32-bit System IP address

D

UDP port 4500 and a 12-bit VLAN identifier

Test Your Knowledge

In the Locator/ID Separation Protocol (LISP) control plane, what is the primary operational responsibility of the Map-Resolver (MR)?

A

It intercepts external internet frames and translates 802.1Q tags to LISP Instance IDs

B

It encapsulates Layer 2 Ethernet frames into outer UDP packets using destination port 4789 before sending them to the ETR

C

It dynamically assigns IP addresses to roaming mobile endpoints by answering their DHCP discover messages at each new site

D

It receives Map-Requests from ITRs and forwards them toward the Map-Server for the authoritative answer

Test Your Knowledge

Which BGP EVPN route type is responsible for distributing endpoint MAC addresses and optional host IP addresses to enable unicast forwarding and suppress broadcast ARP flooding?

A

Route Type 2 (MAC/IP Advertisement Route)

B

Route Type 3 (Inclusive Multicast Ethernet Tag Route)

C

Route Type 4 (Ethernet Segment Route)

D

Route Type 5 (IP Prefix Route)

Sections you finish are checked off in the contents.