Under RFC 9135, how do symmetric and asymmetric integrated routing and bridging differ in a VXLAN fabric, and what does each demand of every leaf?
answer
- where the routing happens
- count the lookups on each side
- which VNI the packet travels in
- TTL tells the story
- scale versus control-plane simplicity
basics
~20 sAsymmetric IRB routes only at the ingress VTEP and bridges into the destination subnet's L2 VNI, so every leaf carries every subnet; symmetric IRB routes at both VTEPs over the tenant's L3 VNI, so each leaf carries only its local subnets.
solid answer
~40 s**Integrated routing and bridging (IRB)** lets each VTEP route between a tenant's subnets as well as bridge within them. In **asymmetric** IRB the ingress VTEP does a MAC lookup, an IP lookup and another MAC lookup, then sends the packet in the destination subnet's L2 VNI; the egress does only a MAC lookup. RFC 9135 says each VTEP then MUST keep ARP entries for remote hosts and bridge tables and gateway interfaces for ALL the tenant's subnets, and the TTL drops once. In **symmetric** IRB both VTEPs route: the packet crosses in the tenant's L3 VNI between router MACs, each VTEP keeps only local subnets and local ARP entries, and the TTL drops twice. RFC 9135 frames the choice as scale (symmetric) versus control-plane simplicity (asymmetric).
go deeper
Recall that IRB lets a leaf both bridge and route, and that the two models differ in where the routing lookup happens.
List the lookups on each side for both models and which VNI the packet travels in, L2 VNI for asymmetric and L3 VNI for symmetric.
Tie the model to table scale: asymmetric needs every subnet and remote ARP entry on every leaf, symmetric needs subnet routes advertised. Expect the extra TTL hop under symmetric.
Choose per fabric from subnet placement: stretched-everywhere subnets favour asymmetric simplicity, sparse placement favours symmetric scale, and mixing them follows RFC 9135's signalling.
## What IRB means **Integrated Routing and Bridging (IRB)** is the ability of one device, here a VXLAN VTEP on a leaf switch, both to **bridge** frames within a subnet and to **route** packets between subnets of the same tenant. RFC 9135 defines an **IRB interface** as the layer 3 interface that connects a tenant's **IP-VRF** (routing table) to one **bridge table** (one subnet). Every leaf can act as the default gateway for its local hosts. RFC 9135 defines two ways the leaves can share the routing work, and the names describe where the lookups happen. ## Asymmetric IRB: route at ingress, bridge across RFC 9135 section 4 describes the ingress VTEP doing three lookups and the egress one: 1. **Ingress MAC lookup**: the frame is addressed to the gateway MAC, so it must be routed. 2. **Ingress IP lookup** in the tenant's IP-VRF finds the destination subnet, reached through the local gateway interface of that subnet. 3. **Ingress MAC lookup** in the destination subnet's bridge table finds the host's MAC and the remote VTEP. The ingress rewrites the inner frame to the destination host's MAC and sends it in the **destination subnet's L2 VNI**. 4. **Egress MAC lookup**: the remote VTEP simply bridges the frame to the host. Consequences stated in RFC 9135: the tunnel MUST be of type Ethernet; each VTEP MUST maintain ARP entries for remote hosts and MUST maintain bridge tables and gateway interfaces for **all** subnets of the IP-VRF, including subnets with no local host; and the TTL or hop limit is decremented **once**, at the ingress. ## Symmetric IRB: route at both ends 1. **Ingress MAC lookup**, then **ingress IP lookup** in the tenant's IP-VRF, which yields the egress VTEP and a VNI for the IP-VRF (the "L3 VNI"). The ingress decrements the TTL. 2. The ingress adds an inner Ethernet header from its own router MAC to the egress VTEP's router MAC, learned from the **EVPN Router's MAC Extended Community**, and encapsulates with the **L3 VNI**. 3. **Egress IP lookup**: the egress maps the VNI to the IP-VRF, looks up the host, decrements the TTL again. 4. **Egress MAC lookup**: it rewrites to the host's MAC and bridges it out. Each VTEP then keeps ARP entries only for locally connected hosts and bridge tables only for locally configured subnets. The price is a control-plane duty: because not every subnet is on every leaf, RFC 9135 section 5.3 says the VTEPs MUST advertise their local subnets as IP prefix routes, so an ingress can reach a subnet it does not carry and trigger discovery of a host it has not yet learned. ## Side by side | | Asymmetric IRB | Symmetric IRB | |---|---|---| | Ingress lookups | MAC, IP, MAC | MAC, IP | | Egress lookups | MAC | IP, MAC | | VNI on the wire | Destination subnet's L2 VNI | Tenant's L3 VNI | | Inner destination MAC | Destination host | Egress VTEP's router MAC | | TTL decrements | 1 | 2 | | Subnets each leaf must carry | All of the tenant's subnets | Only its local subnets | | ARP entries | Local and remote hosts | Local hosts only | ## Choosing between them RFC 9135 section 4.2 frames the choice as **scale versus control-plane simplicity**: - **Asymmetric fits** when every subnet already has hosts on (nearly) every leaf. The ARP and MAC entries must be learned everywhere anyway, and no host routes are installed in the VRF route table. - **Symmetric fits** when subnets are not stretched everywhere but routing between them is needed. It saves ARP and bridge-table space on every leaf, because a leaf carries only what is attached to it. - **Provisioning differs.** Asymmetric means configuring every subnet on every leaf; symmetric means configuring one L3 VNI per tenant VRF on every leaf that serves the tenant. ## Mixed fabrics and traps - **They can coexist.** RFC 9135 lets an ingress that supports both modes follow what the egress signals: a non-zero Label2 and an IP-VRF route target mean symmetric, a zero Label2 and no IP-VRF target mean asymmetric. - **Traceroute hop counts differ** by one between the modes because of the extra TTL decrement. - **Global-mode L3 VNI mismatch.** When the L3 VNI is assigned domain-wide, every VTEP must use the same value; a route carrying a different value MUST NOT be used, so routing to that leaf fails while bridging works. - **The name misleads.** "Asymmetric" describes the lookups, not traffic taking different paths in each direction.
- Why does a traceroute through symmetric IRB show one more routed hop than through asymmetric IRB?RFC 9135 has both the ingress and the egress VTEP decrement the TTL under symmetric IRB, because both do an IP lookup. Under asymmetric IRB only the ingress routes, so the TTL drops once. Underlay hops do not touch the inner TTL in either mode.
- Under symmetric IRB, how does a leaf route to a subnet it does not carry when the destination host has not been learned yet?RFC 9135 section 5.3 requires VTEPs to advertise their local subnets as IP prefix routes. The ingress routes the packet to a VTEP that has the subnet; that VTEP ARPs for the host, learns it, and advertises the host route, after which traffic goes directly to the right leaf.
saying these in an interview costs you the question
- Asymmetric IRB means traffic takes a different path in each direction.
- Symmetric IRB requires every subnet to be configured on every leaf.
- Asymmetric IRB needs an L3 VNI for each tenant.
- Both IRB models decrement the TTL exactly once.
- A fabric must run one IRB model everywhere because the two cannot interwork.