skip to content

In a VXLAN fabric that routes for its tenants, what is the difference between an L2 VNI and an L3 VNI?

level: middleimportance: should knowfreq 24%

answer

  1. bridge table versus routing table
  2. one per subnet, one per tenant
  3. what the egress VTEP looks up
  4. router MACs in the inner header

basics

~20 s

An L2 VNI names one bridged subnet, so the receiving VTEP looks up the destination MAC in that bridge table; an L3 VNI names a tenant's VRF, so the receiving VTEP looks up the destination IP in that tenant's routing table.

solid answer

~40 s

"L2 VNI" and "L3 VNI" are industry shorthand; RFC 9135 speaks of a VNI that identifies a MAC-VRF bridge table and a VNI "corresponding to the tenant's IP-VRF". A tenant has one L2 VNI per subnet and one L3 VNI for its VRF, shared by all its subnets. Bridged traffic travels in the subnet's L2 VNI with the hosts' own MACs. Routed traffic under symmetric routing travels in the L3 VNI, and RFC 9135 has the egress VTEP use that VNI to pick the IP-VRF, do an IP lookup, then rewrite to the host's MAC. The inner frame carries the two VTEPs' router MACs. The L3 VNI is what stitches the tenant's VRF on every VTEP into one routing domain.

go deeper

for a junior

Recall the split: an L2 VNI is one bridged subnet, an L3 VNI is one tenant's routing instance.

for a middle

Explain what the egress VTEP does with each: MAC lookup in a bridge table versus IP lookup in the tenant VRF, and why the inner frame then carries router MACs.

for a senior

Diagnose the failures: an L3 VNI mismatch in global mode drops routes while bridging still works, and a missing router MAC prevents encapsulation.

for a principal

Weigh global against downstream VNI assignment and plan VNI allocation per tenant so VRFs stay consistent across leaves and domains.

## Two kinds of segment identifier The VXLAN header has exactly one 24-bit **VNI** field. What the number *means* is decided by the configuration of the receiving **VTEP** (VXLAN Tunnel End Point). Two meanings matter once the fabric routes as well as bridges: - **L2 VNI**: the VNI is bound to a **bridge table**, one layer 2 broadcast domain, typically one tenant subnet. RFC 9135 calls the containing table a **MAC-VRF** (from RFC 7432). - **L3 VNI**: the VNI is bound to a tenant's **IP-VRF**, its Virtual Routing and Forwarding table for IP routes (the RFC 4364 concept). "L2 VNI" and "L3 VNI" are widely used shorthand rather than RFC terms. RFC 9135 describes the same thing as the MPLS Label2 field "set to either an MPLS label or a VNI corresponding to the tenant's IP-VRF". ## What the receiver does with each | | L2 VNI | L3 VNI | |---|---|---| | Bound to | One bridge table (one subnet) | One tenant IP-VRF | | Count per tenant | One per subnet | One per VRF, shared by all its subnets | | Inner destination MAC | The destination host's MAC | The egress VTEP's router MAC | | Egress lookup | MAC lookup in that bridge table | IP lookup in that VRF, then MAC rewrite | | Used for | Bridging, and asymmetric routing | Symmetric routing | RFC 9135 section 5.5 states the rule directly: the egress VTEP uses the VNI "to identify the IP-VRF in which IP lookup needs to be performed", and if the VNI identifies a MAC-VRF instead, the asymmetric procedures apply. ## A worked tenant Tenant A has two subnets and one VRF: | Object | Identifier | |---|---| | Subnet 10.0.0.0/24 | L2 VNI 10010 | | Subnet 10.0.1.0/24 | L2 VNI 10011 | | VRF of tenant A | L3 VNI 50001 | 1. Host 10.0.0.5 on leaf A sends to 10.0.1.7 on leaf B, addressing the frame to its gateway's MAC. 2. Leaf A sees the gateway MAC, routes in tenant A's VRF and finds 10.0.1.7 behind leaf B with VNI 50001. 3. Leaf A decrements the TTL, builds an inner Ethernet header from its own router MAC to leaf B's router MAC, and encapsulates with VNI 50001. 4. Leaf B maps 50001 to tenant A's VRF, does an IP lookup, decrements the TTL again, rewrites the frame to the host's MAC and delivers it in subnet 10.0.1.0/24. Leaf B's router MAC reaches leaf A in the **EVPN Router's MAC Extended Community** carried with the host's route. ## Why one VNI per VRF stitches the tenant together - **Each VTEP holds its own copy** of tenant A's VRF. The L3 VNI is the label that says "this packet belongs to tenant A's routing domain", so the copies behave as one distributed router. - **No subnet has to exist everywhere.** A leaf can route to 10.0.1.0/24 without carrying that subnet's L2 VNI, because routed packets arrive in the L3 VNI. - **Tenants stay apart.** Tenant B's VRF has a different L3 VNI, so a correctly mapped VTEP delivers tenant A's routed packets into tenant A's table only. ## Global and downstream assignment RFC 9135 section 5.4 allows two ways of choosing the L3 VNI: - **Global mode**: one domain-wide value per IP-VRF. All VTEPs MUST be configured with the same IP-VRF VNI, and a received route whose value differs from the local one MUST NOT be used. - **Downstream mode**: each egress VTEP assigns the value and advertises it, and the ingress uses whatever was advertised. ## Operational traps - **A mismatched L3 VNI in global mode** silently drops routes: bridging inside each subnet keeps working while routing to hosts behind that leaf fails. - **Expecting an L3 VNI under asymmetric routing**: asymmetric routing bridges the routed packet into the destination subnet's L2 VNI and uses no L3 VNI at all. - **Forgetting the router MAC**: routed traffic in the L3 VNI is addressed to the egress VTEP's router MAC, so a VTEP that does not know it cannot build the inner frame.

  • Does a packet sent in an L3 VNI still carry an Ethernet header inside the VXLAN packet?
    Yes. VXLAN is an Ethernet overlay, so RFC 9135 adds an inner Ethernet header whose source is the ingress VTEP's router MAC and whose destination is the egress VTEP's router MAC, learned from the EVPN Router's MAC Extended Community. The egress VTEP replaces it with the destination host's MAC after its IP lookup.
  • In RFC 9135 global mode, what happens if two VTEPs configure different L3 VNIs for the same tenant VRF?
    A received route whose VNI does not match the locally configured IP-VRF VNI MUST NOT be used, and an error SHOULD be logged. Bridging inside each subnet keeps working, but routed traffic to hosts behind the mismatched VTEP fails.

An L2 VNI is like an internal mail slot for one department: whatever lands there goes straight to the named person. An L3 VNI is the building's front desk for the whole company: the clerk reads the full address and only then decides which department's slot it goes into.

saying these in an interview costs you the question

  • Each tenant subnet needs its own L3 VNI.
  • Routed traffic in an L3 VNI keeps the destination host's MAC in the inner frame.
  • Asymmetric routing needs an L3 VNI for every tenant.
  • The VXLAN header has separate fields for the L2 VNI and the L3 VNI.
  • An L3 VNI forwards every routed packet to one central gateway VTEP.