In a VXLAN overlay without a control plane, what does flood-and-learn mean, and what is BUM traffic?
answer
- nobody tells the VTEP in advance
- three kinds of multi-destination frame
- unknown is treated like broadcast
- learn from what you decapsulate
basics
~20 sFlood-and-learn is VXLAN's data-plane learning: a VTEP floods any frame it cannot send to one known VTEP to every VTEP in the segment, and learns MAC-to-VTEP mappings from frames it decapsulates. BUM means broadcast, unknown-unicast and multicast frames.
solid answer
~40 sRFC 7348 describes VXLAN with no separate control plane: the mapping from a host's MAC address to the IP address of the VTEP behind it is found by *source-address learning*. When a VTEP decapsulates a packet, it records the inner source MAC against the outer source IP, per VNI. A frame it cannot send to one known VTEP is **BUM** traffic — **broadcast** (an ARP request), **unknown unicast** (a unicast MAC it has not learned yet) and **multicast** — and it must reach every VTEP that hosts the segment, either through an underlay IP multicast group mapped to the VNI or as one unicast copy per peer VTEP (ingress replication). The flood is what feeds the learning: the first ARP request teaches every VTEP in the segment where its sender lives.
go deeper
Recall what the three letters of BUM stand for and the two halves of the name: flood what you cannot place, learn from what you receive.
Explain that the learned key is the VNI plus the inner source MAC, the value is the outer source IP, and floods reach peers by underlay multicast or per-peer unicast copies.
Show you know the cost: every VTEP in a segment carries every flood, silent hosts trigger unknown-unicast floods, and a mapping exists only because traffic happened to pass.
Frame flood-and-learn as letting traffic double as signalling, and weigh that against a control plane that distributes mappings before any frame needs them.
## The problem a VTEP has to solve A **VXLAN Tunnel End Point (VTEP)** sits between hosts and a routed IP network. A host sends an ordinary Ethernet frame; the VTEP wraps it in an outer IP and UDP header plus an 8-byte VXLAN header carrying a 24-bit **VXLAN Network Identifier (VNI)**, and sends it across the layer 3 underlay to another VTEP, which unwraps it. To do that for a unicast frame, the VTEP must know one thing: **behind which remote VTEP does this destination MAC address live?** There are two families of answers. A **control plane** — a directory, or a routing protocol such as BGP EVPN — can tell every VTEP the mappings before any frame needs them. Or the VTEPs can work it out from the traffic itself. RFC 7348, the Informational RFC that defines VXLAN, describes the second scheme and calls it **data-plane learning**; operators call it **flood-and-learn**. ## The "learn" half When a VTEP receives and decapsulates a VXLAN packet, it reads two addresses: - the **inner source MAC** — the host that sent the original frame; - the **outer source IP** — the address of the VTEP that encapsulated it. It stores `(VNI, inner source MAC) → outer source IP`. The next time one of its own hosts sends a frame to that MAC in that VNI, the VTEP encapsulates it as **one unicast packet** to that VTEP address. RFC 7348 §4.1 states the purpose plainly: the mapping is stored so that the reply needs no "unknown destination" flooding. The VNI is part of the key because RFC 7348 lets different segments reuse the same MAC addresses without traffic crossing over. ## The "flood" half — what counts as BUM Some frames cannot go to a single known VTEP. Together they are called **BUM** traffic: | Letter | Frame | Why it cannot go to one VTEP | |---|---|---| | **B** | Broadcast, such as an ARP request | Every host in the segment must see it | | **U** | Unknown unicast | A unicast MAC with no learned mapping yet | | **M** | Multicast | Any host in the segment might be a receiver | **Known unicast** — a destination MAC the VTEP has already learned, on a local port or behind a remote VTEP — is the only traffic that is *not* flooded. A broadcast is flooded every time, however many mappings the VTEP has learned. ## How a flood reaches the other VTEPs A VTEP floods a BUM frame to **every VTEP that hosts the same VNI**, in one of two ways: 1. **Underlay IP multicast.** RFC 7348 maps each VNI to an IP multicast group (the mapping is supplied by the management layer). VTEPs join the group, and the routed underlay copies the packet along a multicast tree. The source sends one packet. 2. **Ingress replication** (also called head-end replication). The source VTEP holds a list of peer VTEPs for the VNI and sends a separate unicast copy to each. The underlay needs no multicast at all; the source pays in bandwidth. Either way, the receiving VTEPs deliver the frame to their local hosts in that segment — and **learn** from it, because the flooded packet carries the sender's VTEP address as its outer source. ## How the two halves feed each other Consider the very first exchange between two hosts that have never spoken: 1. Host A broadcasts an ARP request for host B's IP address. 2. A's VTEP floods it; every VTEP in the segment learns that A lives behind A's VTEP. 3. B answers with a unicast ARP reply. B's VTEP already knows where A is, so the reply crosses the underlay as one unicast packet. 4. A's VTEP decapsulates the reply and learns where B is. From now on, both directions are known unicast. That is the whole design: **flooding is the discovery mechanism**, and learning makes the flood unnecessary for the rest of the conversation. ## Where the model stops Flood-and-learn needs no protocol between the VTEPs beyond the encapsulation itself; only the VNI-to-group mapping comes from the management layer. The price is that every VTEP in a segment carries every broadcast and every unknown-unicast frame, mappings exist only after traffic has flowed, and a host that moves is relearned only when it next sends. Those costs are why large fabrics replace the learning with a control plane while keeping the same VXLAN encapsulation — RFC 8365 contrasts the two, noting that data-plane learning requires flooding unknown unicast and ARP frames while control-plane learning does not.
- Why does a flood-and-learn VTEP flood unknown unicast instead of dropping it?A unicast MAC the VTEP has not learned may still belong to a valid host in the segment — one that has been silent, or whose entry aged out. A layer 2 segment promises delivery within the broadcast domain, so the VTEP floods the frame the way a bridge would. The host's reply then teaches the VTEP where it lives, and later frames go unicast to that one VTEP.
- Does a VTEP learn from a flooded frame even when none of its local hosts is the target?In the RFC 7348 model, yes: learning happens on decapsulation. A VTEP that hosts the VNI decapsulates the flood, delivers the broadcast to its local hosts in that segment, and records the sender's MAC against the outer source IP whether or not any local host answers. So every VTEP in a segment tends to hold entries for hosts its own hosts never talk to.
A mailroom network with no staff directory: a letter for an unknown name is copied to every building's mailroom, and each mailroom notes the return address on everything it receives, so the reply goes straight to the right building.
saying these in an interview costs you the question
- BUM means broadcast, unicast and multicast, so all unicast traffic is flooded.
- The B in BUM stands for spanning-tree BPDUs carried across the overlay.
- Flood-and-learn VTEPs exchange their MAC tables over a BGP session.
- Once a host's MAC is learned, ARP broadcasts for it stop being flooded.
- A VTEP learns a remote host's location from the destination of the frames it sends.