skip to content

On a VXLAN VTEP, how is a local VLAN mapped to a VNI, and why may two VTEPs use different VLAN IDs for one segment?

level: middleimportance: should knowfreq 30%

answer

  1. two identifiers, two scopes
  2. what happens to the 802.1Q tag
  3. only one number crosses the fabric
  4. RFC 7348 section 6.1

basics

~20 s

The VTEP holds a configured VLAN-to-VNI table; it strips the 802.1Q tag before encapsulating and maps the arriving VNI back to its own local VLAN, so with the usual domain-wide VNIs only the VNI must agree and VLAN IDs stay locally significant.

solid answer

~40 s

Each VTEP is configured with a mapping from a local VLAN, or a port and VLAN, to a VNI. RFC 7348 says frames arriving on the non-VXLAN side are mapped to a VXLAN segment based on their VLAN ID, and that the encapsulating VTEP SHOULD strip the tag unless configured otherwise; on the way out, decapsulated frames that still carry an inner tag SHOULD be discarded unless configured otherwise. So the VLAN number never crosses the fabric: leaf A can put VLAN 10 into VNI 10010 while leaf B puts VLAN 210 into the same VNI, and the hosts share one segment. The VNI is what must match; RFC 8365 treats VNIs as normally unique across a domain, with locally significant VNIs an exception for data-centre interconnect through a translating gateway.

go deeper

for a junior

Recall that the VTEP turns a local VLAN into a VNI and that only the VNI travels across the fabric.

for a middle

Walk the tag's life: matched to a VNI on ingress, stripped per RFC 7348 section 6.1, re-applied from the egress VTEP's own mapping. Show why two leaves may use different VLAN numbers.

for a senior

Diagnose silent splits from mismatched VNIs and isolation breaks from a VLAN mapped into the wrong tenant's VNI; know that inner tags are dropped by default.

for a principal

Own the numbering plan: fabric-wide VNI allocation, local VLAN freedom per leaf, and where VNI translation is acceptable at domain borders.

## Two identifiers, two scopes A VXLAN fabric deals with two different segment identifiers: - **The VLAN ID** (12 bits, IEEE 802.1Q) is what a server or appliance puts on the frames it sends to its leaf switch, or what the leaf assigns to an untagged access port. - **The VNI** (24 bits, RFC 7348) is what the **VTEP** (VXLAN Tunnel End Point) writes into the VXLAN header for the trip across the routed fabric. The VTEP sits at the border between the two and holds a **VLAN-to-VNI mapping**. The key fact is that the two identifiers have different **scope**: the VLAN ID is meaningful only on the links between one VTEP and its attached hosts, while the VNI is meaningful across the whole overlay. ## What the VTEP does on the way in 1. A tagged frame arrives on a server-facing port with VLAN 10. 2. The VTEP looks up its mapping and finds VLAN 10 -> VNI 10010. RFC 7348 describes exactly this: frames for the non-VXLAN interfaces "are mapped to a specific VXLAN overlay network based on the VLAN ID in the frame". 3. It **strips the 802.1Q tag**. RFC 7348 section 6.1: the encapsulating VTEP SHOULD strip the VLAN tag, and SHOULD NOT include an inner tag, unless configured otherwise. 4. It encapsulates the untagged frame with VNI 10010 and sends it to the remote VTEP over the underlay. ## On the way out 1. The remote VTEP decapsulates and reads VNI 10010. 2. If the inner frame still carries a VLAN tag, RFC 7348 says it SHOULD be discarded unless the VTEP is configured to accept it. 3. The VTEP looks up its own mapping in reverse, VNI 10010 -> its local VLAN, and forwards the frame toward the destination host, tagging it with that local VLAN if the port is a trunk. ## A worked mapping | VTEP | Local VLAN | VNI | Segment | |---|---|---|---| | Leaf A | 10 | 10010 | Tenant A, web tier | | Leaf B | 210 | 10010 | Tenant A, web tier | | Leaf A | 20 | 20010 | Tenant B, web tier | | Leaf C | 10 | 20010 | Tenant B, web tier | Leaf A's VLAN 10 and leaf B's VLAN 210 are the **same layer 2 segment**, because both map to VNI 10010. Leaf A's VLAN 10 and leaf C's VLAN 10 are **different segments** despite the identical number. The numbering habit "VNI = 10000 + VLAN" is only a convention for readability, not a rule. ## Why local significance matters - **More segments than VLAN IDs.** Any one 802.1Q link still carries at most 4,094 VLAN IDs, but different leaves can reuse the same VLAN numbers for different VNIs, so the fabric as a whole carries far more segments than 4,094. - **Tenants keep their own numbering.** A tenant's appliance hard-wired to VLAN 100 can sit on any leaf; the leaf maps it into that tenant's VNI. - **Moves are easy.** A rack can be renumbered locally without touching any other VTEP, as long as its mapping keeps the VNI. ## How the mapping relates to service models RFC 8365 says the usual case, one VNI per tenant VLAN with no inner tag, corresponds to EVPN's **VLAN-based service** (one broadcast domain per EVPN instance). VXLAN's optional mode that keeps the inner tag maps to the **VLAN bundle service**, where several VLANs share one bridge table. The details of how an EVPN control plane advertises these belong to the control-plane discussion; at the VTEP the essential job is the mapping itself. ## When the VNI is translated The VNI normally is the one identifier everybody agrees on. RFC 8365 section 5.1.1 notes that although VNIs are defined as globally unique 24-bit values, locally significant VNIs are sometimes wanted, especially for **data-centre interconnect**, where a gateway at each data centre's edge translates VNIs between the values used inside each data centre and those used across the WAN. RFC 8365 also lets an EVPN control plane carry locally assigned VNIs that each egress VTEP advertises, but the common single-fabric design keeps VNIs domain-wide. ## What goes wrong - **Mismatched VNI.** Leaf A maps VLAN 10 to VNI 10010 and leaf B maps its VLAN to 10011: two separate segments, no error, and hosts simply cannot reach each other at layer 2. - **A VLAN in the wrong VNI.** Mapping a tenant's VLAN to another tenant's VNI joins their broadcast domains, which is the most direct way to break tenant isolation. - **Unexpected inner tags.** A host that sends double-tagged traffic loses it at the far end when the default discard rule applies.

  • Leaf A maps VLAN 10 to VNI 10010, but leaf B maps its VLAN 10 to VNI 10011. What do you see?
    Two separate segments. Each VTEP only delivers within the VNI it received, so ARP requests from leaf A's hosts never reach leaf B's hosts and nothing raises an error. You find it by comparing VLAN-to-VNI tables, or by noticing that the control plane shows no remote hosts in the VNI on one side.
  • When would a VNI itself be translated rather than kept fabric-wide?
    RFC 8365 section 5.1.1: when separately run domains are joined, typically for data-centre interconnect. A gateway at each data centre's edge translates between the VNIs used inside that data centre and those used across the WAN, so each operator keeps its own numbering.

saying these in an interview costs you the question

  • VXLAN always carries the original VLAN tag so the far VTEP reuses it.
  • Every leaf must use the same VLAN number for a given segment.
  • The VNI is just the VLAN ID padded to 24 bits.
  • Mapping VLANs to VNIs lifts the 4,094-VLAN limit on each individual switch port.
  • A mismatched VLAN-to-VNI mapping makes the VTEP report an error.