EVPN/VXLAN outside the datacenter

How to create scalable campus and wan solutions with evpn/vxlan

Posted by     nmodena on Tuesday, May 20, 2025

Every year, the Itnog appointment is special. It is an opportunity to share something practical and engage in new challenges for those who want to collect them. This year, I decided to talk about the EVPN VXLAN combination in a campus and geographic context.

The growing support of this technology by many vendors in different products, such as switches, routers, and now firewalls, has made this possibility real. It is now possible to create uniform solutions from the data center until access leveraging this technology. Adopting a control plane and an overlay over IP networks enables multitenant and multivendor solutions that scale both in the infrastructure and services. My presentation covers EVPN/VXLAN services from layer-2 to layer-3, comparing asymmetric and symmetric VXLAN routing, anycast gateway with optimal routing distribution, and different scalability results. A simple remote site architecture is presented to consolidate the topic covered during the presentation, consolidating a strong separation between layer-2 and Layer-3 services on the WAN. As always, I try to focus on the use of layer 2 and the pitfalls it can present.

The talk and the slides are full of ideas to deepen the technology in many aspects since the vastness of the topic and the time given to me did not allow me to go further.

Presentation

This is the ITNOG9 Presentation from my github repository.