What is VXLAN?

VXLAN (Virtual Extensible LAN) creates virtual network segments across an IP network, so servers, virtual machines and applications in different locations can operate as though they share the same local network. It is widely used in large, virtualised and multi-tenant data centre environments.

1

Simplifies network changes

Logical networks can be moved, added or reorganised without repeatedly redesigning the underlying switching infrastructure.

2

Supports large-scale segmentation

VXLAN supports around 16 million segments, making it suitable for cloud platforms, distributed applications and securely separated tenants or departments.

3

Check fabric and control-plane support

Suitability depends on whether the switching fabric and EVPN design can correctly learn, scale and share routes across the environment.

The Role of VXLAN in Modern Data Centre Environments

VXLAN creates scalable virtual network segments across a shared physical data centre network, keeping applications, workloads, departments, customers, or security zones logically separated as they move between racks, buildings, or sites.

The architecture you choose determines how easily you can expand services, maintain segmentation at scale, and support workload mobility without repeatedly reconfiguring the underlying switching fabric.

As a partner to vendors including Cisco, HPE Aruba, Juniper, and Arista, we specify VXLAN against your requirements, so you're not overbuilding fabric capacity you will not use or introducing segmentation, addressing, and traffic design choices that increase operational complexity.

How VXLAN Works

VXLAN carries Ethernet traffic across an IP network by wrapping each frame inside UDP and IP headers. VXLAN tunnel endpoints add and remove this information at each end.

For IT teams

This simplifies network expansion across racks or sites. It supports stronger segmentation, easier workload moves, and new virtual networks without redesigning the physical underlay.

The diagram below shows how vxlan works

Why Organisations Choose VXLAN

VXLAN helps organisations extend, segment and scale logical networks across IP infrastructure for more flexible virtualised and data centre environments.


Extending Layer 2 Networks

VXLAN supports application mobility by connecting workloads logically across an IP network, without keeping every system in one location.

Simplifying Multi-Tenant Networking

Separate virtual segments support customers, departments, applications or security zones across shared infrastructure with clearly defined logical boundaries.

Supporting Cloud-Scale Infrastructure

VXLAN provides segmentation capacity for large private cloud and virtualised environments where traditional VLAN limits can restrict expansion.

Improving Network Flexibility

Logical networks can be created, moved or expanded without repeatedly redesigning physical infrastructure for changing workload requirements.

Enabling Modern Data Centre Fabrics

VXLAN works across scalable spine-leaf networks and is commonly paired with EVPN for connectivity, route distribution and segmentation.

Scaling Virtual Networks

Millions of potential network segments support expansion beyond the approximately 4,000-segment ceiling of traditional VLANs.

Common Enterprise Use Cases

VXLAN supports scalable network segmentation, workload mobility and logical isolation across shared enterprise, data centre and cloud-connected infrastructure.


Extending Layer 2 Networks

Encapsulates Layer 2 traffic across IP networks, keeping workloads in different racks or sites within the same logical segment.

Enabling Multi-Tenant Networking

Creates isolated logical segments for customers, departments or applications operating securely across the same shared physical network infrastructure.

Supporting Hybrid Cloud Connectivity

Extends consistent network segmentation between compatible private, hosted and cloud environments, simplifying connectivity for distributed applications and services.

Building Software-Defined Networks

Allows software-defined platforms to provision and modify logical networks independently of the physical fabric, accelerating deployment and policy consistency.

Scaling Enterprise Networks

Provides far greater segmentation capacity than traditional VLANs, supporting growth across large data centres with many isolated environments.

Supporting Virtualised Infrastructure

Maintains logical connectivity and segmentation when virtual machines move between compatible hosts, reducing physical network reconfiguration during migrations.

Key Considerations When Deploying VXLAN

These controls prevent unstable overlays, fragmented traffic, inconsistent gateways and tenant leakage across expanding virtualised data-centre fabrics.


01

Overlay Network Design

Define VXLAN network identifiers, endpoint placement and traffic flows so logical segments align with application, security and tenancy requirements.

02

Underlay Network Readiness

Verify IP reachability, routing convergence, equal-cost paths and multicast or ingress-replication support so VXLAN tunnel endpoints communicate reliably.

03

MTU Configuration

Calculate encapsulation overhead and configure a consistent underlay MTU so VXLAN packets are not fragmented or silently dropped between tunnel endpoints.

04

Gateway Integration

Confirm where supported Layer 2 and Layer 3 gateways will reside so workloads can reach external networks without asymmetric or inefficient paths.

05

Network Automation

Validate controller, API and template support for creating, changing and removing VXLAN segments so overlay state remains consistent across the fabric.

06

Multi-Tenant Design

Map tenants to isolated network and routing instances with controlled shared services so overlapping addresses or policy errors do not expose traffic.

Technology Comparison: VXLAN vs Traditional VLANs

VXLAN and VLANs create network segments differently, affecting scale, workload mobility, troubleshooting and the supporting network design.

VXLAN Traditional VLANs
Overlay and underlay design VXLAN encapsulates Layer 2 frames across a routed IP underlay, creating logical overlay segments between compatible tunnel endpoints. Traditional VLANs use 802.1Q tags to separate Layer 2 broadcast domains directly across the switched network.
Best-fit virtualised environments Multi-tenant, virtualised and cloud-style data centres that need logical segments across racks while retaining a scalable routed underlay. Campus networks, smaller data centres and local segments where straightforward Layer 2 separation provides sufficient reach and scale.
Segmentation and network scale Supports a much larger segment space and can extend workload connectivity across Layer 3 boundaries without expanding the physical broadcast domain. Provides simpler segmentation but has a smaller identifier space and can become operationally difficult when Layer 2 domains span widely.
Gateway, control-plane and operations Requires VTEPs, consistent MTU, a resilient IP underlay and usually EVPN or another supported control method for endpoint distribution. Uses mature switch configuration and monitoring, with MAC learning, spanning tree and gateway placement managed directly in the physical network.
What it is not built for Simple local segmentation where an overlay, routed underlay and additional control-plane operations would add unnecessary complexity. Large multi-tenant fabrics requiring extensive segment scale or workload mobility across routed data centre boundaries.

Enterprise Platforms We Recommend

Arista, HPE Aruba, Juniper, and Cisco VXLAN platforms each suit different data centre fabrics, operating models, and automation requirements. Here's where each one fits best.


Arista Data Centre Switching product

Arista Data Centre Switching

Best for: Large cloud, AI, or financial-services estates with experienced automation teams needing scalable overlay segmentation across a routed fabric.

Strengths
  • Supported models terminate VXLAN overlays across a routed underlay fabric
  • VXLAN identifiers scale segmentation well beyond conventional VLAN limits
  • EOS supports distributed gateways and EVPN-based workload mobility
  • CloudVision streamlines high-volume fabric change through programmable workflows
HPE Aruba Data Centre Switching product

HPE Aruba Data Centre Switching

Best for: Mid-sized private-cloud estates with lean teams extending familiar Aruba operations into the data centre for scalable overlay segmentation.

Strengths
  • Supported models terminate VXLAN overlays across a routed underlay fabric
  • VXLAN identifiers isolate applications, tenants, and zones at scale
  • AOS-CX supports distributed gateways and EVPN-based workload mobility
  • Aruba tooling preserves operational familiarity across campus and data centre
Juniper Data Centre Switching product

Juniper Data Centre Switching

Best for: Mid-sized and large data centres with automation-led teams prioritising intent-based fabric assurance and scalable overlay segmentation.

Strengths
  • Supported models terminate VXLAN overlays across a routed underlay fabric
  • VXLAN identifiers isolate applications, tenants, and zones at scale
  • Junos OS supports distributed gateways and EVPN-based workload mobility
  • Apstra validates live fabric state against intended design
Cisco Data Centre Switching product

Cisco Data Centre Switching

Best for: Large Cisco-integrated data centres with dedicated fabric teams needing formal policy control and scalable overlay segmentation.

Strengths
  • Supported models terminate VXLAN overlays across a routed underlay fabric
  • VXLAN identifiers scale segmentation well beyond conventional VLAN limits
  • NX-OS or ACI supports distributed gateways and EVPN control
  • Nexus Dashboard centralises policy, telemetry, and fabric automation
Steel City Consulting logo

Get a clear recommendation for your network

Unsure which platform is the right fit for your requirements? Our specialists can assess your workloads, existing estate, growth plans, and operational requirements, then recommend the right approach.

Related Technology Guides

VXLAN operates within a wider routed fabric; these guides cover the control plane, topology and routing technologies commonly used alongside it.

EVPN

Understand how EVPN replaces traffic-based endpoint discovery with a scalable control plane for VXLAN overlays.

Read the guide

Spine-Leaf Architecture

See how spine-leaf routing provides the consistent underlay paths used to carry VXLAN-encapsulated traffic.

Read the guide

Border Gateway Protocol (BGP)

Explore how BGP-based control planes distribute routes and endpoint information across modern data centre overlays.

Read the guide

Segment Routing

Learn how programmable routed paths can steer underlay traffic beneath virtual network overlays.

Read the guide

Related Technology Platforms

Explore the physical switching platforms that carry VXLAN overlays across data centre, AI and wider enterprise network environments.

Data Centre Switching

Transport VXLAN overlays between tunnel endpoints across scalable routed data centre switching fabrics.

View Data Centre Switching

AI Networking

Keep accelerated workloads and services logically while using shared high-performance physical infrastructure.

View AI Networking Platforms

Core Switching

Bring together VXLAN-enabled fabrics to wider campus, WAN and service networks through resilient core routing.

View Core Switching Platforms

Network Switches

Examine switching platforms used for VXLAN underlays, tunnel endpoints and connections to external networks.

View Network Switching Platforms
Steel City Consulting logo
Need help implementing this technology?

Our specialists can recommend the right platform for your environment.

FAQ

What is VXLAN and how does it work?

VXLAN carries a logical Ethernet network across routed IP infrastructure, allowing workloads in different racks or locations to remain within the same network segment.

At each end, a VXLAN tunnel endpoint wraps the original Ethernet frame inside UDP and IP information, then removes it on arrival. This separates the logical network from the physical switching layout, making expansion and workload placement easier to manage.

Why is VXLAN used instead of traditional VLANs?

VXLAN is used when VLANs cannot provide enough segments, flexibility or reach for large virtualised, multi-tenant or distributed data centre environments.

VLANs remain suitable for simpler networks but offer approximately 4,000 usable identifiers and are closely tied to the physical topology. VXLAN supports millions of logical segments across routed infrastructure, giving stronger separation and workload mobility without extending one Layer 2 network across the estate.

What is the relationship between VXLAN and EVPN?

VXLAN carries workload traffic across the routed network, while EVPN commonly tells participating switches where workloads and logical network segments are located.

Used together, VXLAN provides the virtual network and EVPN distributes the reachability information needed to find connected endpoints efficiently. This reduces reliance on widespread traffic discovery and helps larger fabrics scale with better operational control, although simpler VXLAN deployments may use another control method.

What infrastructure is required to deploy VXLAN?

VXLAN requires compatible switches or virtual network devices, a reliable routed underlay and sufficient capacity to carry encapsulated traffic between tunnel endpoints.

Addressing, gateways, segmentation, packet size, routing and monitoring also affect whether the overlay operates reliably. Steel City Consulting can validate platform support and design these dependencies together, helping avoid fragmentation, unreachable workloads or an overlay that exceeds underlay capabilities.

Does VXLAN provide security between workloads?

VXLAN separates workloads into logical network segments, but firewalls, identity controls and security policies are still needed to govern communication between them.

The segmentation can isolate applications, departments, tenants or security zones across shared infrastructure. However, gateway placement and inter-segment policies determine what can communicate, so the design must align each VXLAN segment with the organisation’s actual access and security requirements.

When might VXLAN be unnecessary for an organisation?

VXLAN may be unnecessary when existing VLANs already provide sufficient segmentation, scale and workload connectivity within a relatively simple physical network.

Overlay networking adds routing, monitoring and troubleshooting considerations that some environments do not need. Steel City Consulting can compare the current architecture with expected growth and mobility requirements, establishing whether VXLAN addresses a real limitation or whether conventional VLANs remain more manageable.

Get expert advice, with no obligation.

From new deployments to hardware refreshes and network reviews, we can help you identify what needs to change and how to move forward with confidence.
A group discussing IT solutions