EVPN VXLAN: Architecture, Design, Configuration & Training GuideCisco · General EVPN/VXLAN design · Overlay fundamentals

This EVPN VXLAN training hub helps you choose the right course for your starting point: overlay fundamentals, EVPN route-type theory, Cisco Nexus CLI deployment, Nexus Dashboard operations, advanced Multi-Site engineering, or migration from a classical Ethernet data center.

All 6 courses, about 43 hours of video, are included in one membership. You can compare the paths below and start with the course that matches your current fabric, lab access, and design responsibility through membership access.




EVPN-VXLAN is a modern network architecture commonly used in data centers. It combines VXLAN as the data planewith BGP EVPN as the control plane.

VXLAN creates scalable Layer 2 and Layer 3 overlay networks across an IP-based underlay. It uses VTEPs (VXLAN Tunnel Endpoints) to encapsulate traffic and transport it across the network.

BGP EVPN distributes MAC and IP reachability information between VTEPs. Instead of relying only on traditional flood-and-learn behavior, EVPN provides a more scalable and efficient control plane.

6 EVPN VXLAN: Architecture, Design, Configuration courses 43+ hours of content Expert instructors

What EVPN VXLAN actually changes

VXLAN separates the tenant Layer 2 or Layer 3 service from the physical IP fabric. Instead of stretching VLANs across a large Spanning Tree domain, you build a routed spine-leaf underlay and use VTEPs to encapsulate tenant traffic into VXLAN packets. The underlay only needs IP reachability between VTEP loopbacks; the overlay carries tenant segmentation through VNIs.

EVPN changes the learning model. Traditional Ethernet learns MAC addresses reactively in the data plane by flooding unknown traffic. BGP EVPN advertises MAC, IP, Ethernet segment, inclusive multicast, and prefix information in the control plane, so the fabric can reduce flooding, support multihoming, and make forwarding decisions before traffic arrives.

The operational model also changes. You troubleshoot two networks at the same time: the underlay that must provide stable reachability and ECMP, and the overlay that must import the correct Route Targets, install L2RIB and L3RIB entries, build NVE adjacencies, and map VLANs to VNIs correctly. Many production failures are not caused by VXLAN encapsulation itself; they come from inconsistent VNIs, wrong RD/RT policy, MTU mismatch, underlay multicast or ingress replication design, external routing leaks, vPC or ESI multihoming behavior, and migration boundaries.

EVPN route types matter because each one solves a different fabric problem. Route Type 1 supports Ethernet Auto-Discovery and mass withdrawal for multihomed segments. Route Type 2 advertises MAC and MAC/IP reachability. Route Type 3 builds the inclusive multicast tree used for BUM replication. Route Type 4 discovers Ethernet Segment members and supports Designated Forwarder election. Route Type 5 advertises IP prefixes for routed connectivity, firewall insertion, and external networks.

Design areaClassical Ethernet / 3-tier data centerVXLAN EVPN fabric
Layer 2 scaleVLANs are tied to local switching domains and often constrained by STP, vPC, and aggregation boundaries.Layer 2 segments are mapped to VNIs and can exist as overlay services across routed leaf-spine paths.
Learning modelMAC learning is reactive and data-plane driven; unknown unicast and ARP create flooding pressure.BGP EVPN distributes MAC, MAC/IP, multicast, Ethernet Segment, and prefix reachability through route types.
Underlay forwardingRedundancy often depends on blocked links, chassis virtualization, or carefully constrained Layer 2 domains.The underlay is routed and can use ECMP across spines with OSPF, IS-IS, or BGP depending on design.
Default gatewayFirst-hop routing often uses HSRP/VRRP at aggregation or core layers.Distributed anycast gateway places the default gateway on each leaf for local routing and symmetric IRB.
MultitenancySegmentation is commonly VLAN and VRF based but harder to stretch consistently at scale.L2 VNIs, L3 VNIs, VRFs, RD/RT policy, and BGP EVPN imports define tenant reachability.
External connectivityRouting usually exits through core or aggregation devices with fewer overlay considerations.Border leafs, L3Out-style models, route-maps, prefix-lists, Route Type 5, and VRF route control become design points.
Migration riskExisting HSRP, vPC, STP, and VLAN numbering are already operational but may block scale.Cutover requires gateway strategy, L2/L3 interconnects, loop prevention, VLAN-to-VNI mapping, and coexistence planning.

EVPN is also used outside VXLAN, including MPLS VPN-style provider designs, but the data center use case is different. MPLS VPN normally builds routed VPN services across an MPLS transport; VXLAN EVPN usually builds tenant Layer 2 and Layer 3 overlays across an IP fabric. If your work is data center fabric design, focus on VTEPs, VNIs, anycast gateways, symmetric IRB, BUM handling, and the EVPN route types used by Nexus and similar switching platforms.

Study our EVPN-VXLAN courses in this order

Pick the path that matches your current responsibility: learning the model, building a Cisco fabric, operating it with Nexus Dashboard, or migrating a live data center.

Foundation

Overlay and tunnel theory before EVPN VXLAN

Start here if you need a clean mental model for what an overlay is, how a tunnel differs from a service abstraction, and why MTU, scale, resiliency, and visibility become design issues before you touch VXLAN.

Start with this course

General EVPN/VXLAN design

EVPN route types, BUM handling, multihoming, and external connectivity

Use this path if you are a network engineer, designer, or solution architect who wants the protocol and design view: EVPN proactive learning, underlay and overlay models, Route Types 1 through 5, vPC, ESI multihoming, firewall insertion, and exit leaf options.

Start with this course

Cisco Nexus CLI

Build a VXLAN BGP EVPN fabric by hand

Choose this path if you want a beginner-friendly Cisco Nexus sequence that maps CCNA-level routing and switching knowledge to underlay, MP-BGP EVPN, VNIs, anycast gateway, vPC, border leafs, route control, and Multi-Site.

Start with this course

Cisco Nexus Dashboard

Move from CLI fabric to controller-driven operations

Take this after you can read and build a VXLAN EVPN fabric on NX-OS. It covers Nexus Dashboard 4.2 cluster deployment, Fabric Builder, POAP onboarding, L3Out, brownfield import, Multi-Site parent fabrics, and endpoint tracing.

Start with this course

Advanced engineering

Underlay, symmetric IRB, IPv6 fabric, VRF leaking, and Multi-Site

Use this track when the basics are clear and you need deeper engineering practice across underlay protocols, Flood and Learn to EVPN migration, vPC integration, ARP suppression, VXLANv6, VRF leaking, default route advertisement, TRM, and Multi-Site.

Start with this course

Migration

Move a classical Ethernet data center to VXLAN EVPN

Choose this path if the hard problem is not greenfield deployment but cutover. It focuses on HSRP/vPC brownfield environments, L2 and L3 interconnects, STP control, gateway migration, VLAN-to-VNI mapping, workload moves, and NX-OS 10.2(3)+ coexistence mechanics.

Start with this course

Compare all EVPN VXLAN courses

Use the course cards below to compare level, duration, instructor, lab focus, and whether the course is stronger for theory, Cisco CLI deployment, Nexus Dashboard operations, advanced engineering, or migration.

Building VXLAN EVPN Fabrics Course
CiscoBeginner·Burak Atasal

Building VXLAN EVPN Fabrics Course

Best first full VXLAN EVPN course for engineers with CCNA-level routing and switching. You build a Cisco Nexus fabric with underlay, MP-BGP EVPN, VNIs, vPC, border leaf routing, route control, and Multi-Site.

5.0 (7) 13 Hours 37 lessons
EVPN - VXLAN Training by Toni Pasanen
General designIntermediate·Orhan Ergun, Toni Pasanen

EVPN - VXLAN Training by Toni Pasanen

For engineers, designers, and solution architects who need EVPN/VXLAN theory in depth. Strongest course for route types, BUM behavior, underlay and overlay options, vPC, ESI multihoming, firewall insertion, and exit designs.

4.7 (27) 8 Hours 41 lessons
Deploying VXLAN EVPN Fabrics with Cisco Nexus Dashboard 4.2
CiscoIntermediate·Burak Atasal

Deploying VXLAN EVPN Fabrics with Cisco Nexus Dashboard 4.2

For engineers who already understand VXLAN EVPN on NX-OS and need Nexus Dashboard 4.2 operations. You deploy ND, build greenfield fabrics, import brownfield fabrics, configure L3Out, and validate Multi-Site.

5.0 (2) 8 Hours 26 lessons
Design and Migrate Modern Data Centers with VXLAN EVPN
Cisco migrationAdvanced·Mohammad Imani

Design and Migrate Modern Data Centers with VXLAN EVPN

For senior engineers and consultants migrating HSRP/vPC 3-tier data centers to VXLAN EVPN. It focuses on cutover planning, L2/L3 interconnects, STP control, gateway migration, VLAN-to-VNI mapping, and workload mobility.

5.0 (1) 4 Hours 16 lessons
VXLAN EVPN Engineering: From Core Underlay to Multi-Site Fabric
Cisco engineeringAdvanced·Mohammad Imani

VXLAN EVPN Engineering: From Core Underlay to Multi-Site Fabric

For engineers who know the basics and need deeper deployment practice. It covers underlay options, Flood and Learn to EVPN, symmetric IRB, vPC, ARP suppression, VXLANv6, VRF leaking, default routes, Multi-Site, and TRM.

7 Hours 23 lessons
Understanding Overlays and Tunnels
Overlay fundamentalsFoundation·Russ White

Understanding Overlays and Tunnels

For learners who want the overlay and tunnel model before VXLAN EVPN. It explains overlay versus tunnel, control-plane and data-plane considerations, MTU and fragmentation, resiliency, scale, and visibility trade-offs.

5.0 (4) 51 Min 3 lessons

EVPN Route Types 1–5

BGP EVPN uses different route types to exchange Layer 2 and Layer 3 reachability information across an EVPN-VXLAN fabric. These routes allow VTEPs to advertise MAC addresses, IP addresses, Ethernet segments, and IP prefixes through the BGP EVPN control plane.

EVPN Route Type 1 – Ethernet Auto-Discovery (A-D)
Route Type 1 is mainly used for EVPN multihoming. It helps advertise Ethernet Segment information and supports functions such as aliasing, fast convergence, and mass withdrawal when a link or PE/VTEP fails.

EVPN Route Type 2 – MAC/IP Advertisement
Route Type 2 advertises MAC addresses and, optionally, their associated IP addresses between VTEPs. It is one of the most important EVPN route types because it enables control-plane MAC/IP learning and helps reduce traditional data-plane flooding. It also supports features such as ARP and Neighbor Discovery suppression.

EVPN Route Type 3 – Inclusive Multicast Ethernet Tag (IMET)
Route Type 3 is used to build the distribution mechanism for BUM traffic: Broadcast, Unknown Unicast, and Multicast. VTEPs advertise their participation in a VNI so that BUM traffic can be delivered to the required remote VTEPs.

EVPN Route Type 4 – Ethernet Segment
Route Type 4 is used in EVPN multihoming environments. It advertises Ethernet Segment information between EVPN devices and plays an important role in Designated Forwarder (DF) election and multihoming operations.

EVPN Route Type 5 – IP Prefix
Route Type 5 advertises IP prefixes through the EVPN control plane. It is primarily used for Layer 3 connectivity and allows IP networks to be exchanged between VTEPs without advertising every destination as a MAC/IP route.

Together, these EVPN route types provide the control-plane information required for scalable MAC learning, IP routing, multihoming, BUM traffic handling, and Layer 2/Layer 3 services in an EVPN-VXLAN network.

EVPN Route Types 1–5

EVPN Route Types 1–5

One membership includes the full EVPN VXLAN training path

You do not need to buy separate VXLAN, EVPN, migration, and Nexus Dashboard courses. Use one membership to move from overlay theory to fabric deployment and operations.

  • 6 EVPN VXLAN and overlay courses included
  • About 43 hours of video training
  • Cisco Nexus CLI, Nexus Dashboard 4.2, Multi-Site, migration, and design-focused courses in one library
  • Labs and workbooks where the course data includes them, including Nexus Dashboard and migration lab materials
  • A practical order: overlay theory → EVPN/VXLAN fundamentals → Cisco fabric build → operations, advanced engineering, or migration

EVPN-VXLAN Learning Path

Learning EVPN-VXLAN is easier when the technologies are studied in the correct order. Network engineers should first understand traditional IP networking and BGP before moving into VXLAN encapsulation and the BGP EVPN control plane.

A practical EVPN-VXLAN learning path can follow these steps:

1. Networking Fundamentals
Start with IP addressing, routing, switching, VLANs, and trunking. These concepts provide the foundation for understanding data center fabrics.

2. BGP Fundamentals
Learn BGP neighbors, route advertisements, route policies, iBGP versus eBGP, route reflectors, and BGP attributes. BGP becomes especially important because MP-BGP EVPN provides the control plane for EVPN-VXLAN.

3. Data Center Underlay
Understand spine-leaf architecture and how OSPF, IS-IS, or eBGP can provide IP reachability between VTEPs. The underlay must provide reliable and scalable connectivity before the VXLAN overlay can operate.

4. VXLAN Fundamentals
Learn VXLAN encapsulation, VTEPs, VNIs, UDP-based tunneling, and how Layer 2 and Layer 3 networks can be transported across an IP fabric.

5. BGP EVPN Control Plane
Study EVPN route types, MAC/IP advertisement, Route Distinguishers, Route Targets, and control-plane learning. This explains how VTEPs discover remote endpoints and exchange reachability information.

6. L2VNI, L3VNI and IRB
Understand the difference between Layer 2 VNIs and Layer 3 VNIs, tenant VRFs, Anycast Gateway, inter-subnet routing, and symmetric versus asymmetric IRB.

7. EVPN Multihoming, Design and Troubleshooting
Finally, study Ethernet Segments, ESI, Designated Forwarder election, all-active multihoming, redundancy, scalability, failure scenarios, and EVPN-VXLAN troubleshooting.

Hands-on labs should be used throughout the learning path. Engineers should be able to build an EVPN-VXLAN fabric, verify BGP EVPN routes, examine VXLAN tunnels and VNIs, configure L2/L3 services, and troubleshoot both the underlay and overlay networks.

EVPN-VXLAN Learning Path

EVPN-VXLAN Learning Path

Which EVPN VXLAN course should you take first?

Use these recommendations when two courses look similar. The right first course depends on whether you need theory, configuration, controller operations, advanced design, or migration planning.

EVPN VXLAN instructors in this training path

The instructors are listed only where they appear in the supplied course data. Each card reflects the courses they teach in this hub.

Teaches the Cisco Nexus VXLAN EVPN build course and the Nexus Dashboard 4.2 operations course. His courses focus on underlay and overlay deployment, vPC, border leaf routing, Multi-Site, brownfield import, and verification with production-style show commands.

View main course

Teaches the EVPN - VXLAN design course with Orhan Ergun. The course focuses on EVPN/VXLAN theory, underlay and overlay design options, BUM handling, route types, vPC, ESI multihoming, firewall implementation, and external connectivity.

View main course

Appears in the EVPN - VXLAN Training by Toni Pasanen course and goes through the course agenda with Toni. The course is aimed at engineers, designers, and solution architects who need detailed EVPN/VXLAN design understanding.

View main course

Teaches the advanced VXLAN EVPN engineering course and the migration course. His topics include underlay construction, Flood and Learn to EVPN, symmetric IRB, vPC, IPv6 VXLAN, VRF leaking, Multi-Site, HSRP/vPC migration, and gateway cutover strategy.

View main course

Teaches the overlay and tunnel fundamentals course. His course focuses on overlay theory, the distinction between overlays and tunnels, and design challenges such as scale, resiliency, MTU, fragmentation, and operational visibility.

View main course

Frequently asked questions

Where should I start if I am new to EVPN VXLAN?

If you are not comfortable with overlays and tunnels, start with Understanding Overlays and Tunnels. It gives you the terminology and design problems behind encapsulation, MTU, scale, and visibility.

If you already understand basic routing, switching, VLANs, OSPF, and BGP, start with Building VXLAN EVPN Fabrics Course. It is the best first full VXLAN BGP EVPN build course in this hub.

What is the difference between the Burak Atasal VXLAN EVPN course and Toni Pasanen’s EVPN - VXLAN Training?

Building VXLAN EVPN Fabrics Course is the better starting point if you want to build and verify a Cisco Nexus fabric end to end. It maps existing routing and switching knowledge to underlay, MP-BGP EVPN, VNIs, vPC, border leaf routing, route control, and Multi-Site.

EVPN - VXLAN Training by Toni Pasanen is stronger for theory and design depth. It spends more time on EVPN route types, underlay and overlay design models, BUM handling, L2RIB and L3RIB behavior, vPC, ESI multihoming, firewall implementation, and external connectivity design.

Do these courses include hands-on labs?

Several courses are explicitly lab-focused. The Cisco fabric build course includes single-site and Multi-Site labs, the Nexus Dashboard course includes a lab workbook and lab setup guidance, the migration course includes a workbook and PNETLab files, and the advanced engineering course lists hands-on lab exercises across underlay, overlay, vPC, VXLANv6, VRF leaking, and Multi-Site topics.

The Toni Pasanen EVPN - VXLAN course is different: the catalogue states that it does not come with lab configurations or lab workbooks. Treat it as a theory and design deep-dive rather than the main hands-on lab course.

What prerequisites do I need for EVPN VXLAN training?

For the beginner Cisco VXLAN EVPN course, you should have CCNA-level networking: IP addressing, VLANs, trunking, basic routing, OSPF and BGP fundamentals, and the ability to read Cisco CLI configurations. You do not need prior VXLAN, EVPN, or NX-OS experience for that course.

For Nexus Dashboard, you should already understand VXLAN EVPN on NX-OS through the CLI, including underlay routing, MP-BGP EVPN, VNIs, VRFs, symmetric IRB, and anycast gateway. For the migration and advanced engineering courses, experience with OSPF, BGP, traditional data center architectures, vPC, HSRP, VLANs, STP, and NX-OS operations is useful.

Which course covers EVPN route types 1 through 5?

Building VXLAN EVPN Fabrics Course explicitly lists EVPN Route Types 1 through 5 as an outcome and explains what each route type carries and when it is used. It is the most direct route if you want route types tied to a Cisco Nexus fabric build.

EVPN - VXLAN Training by Toni Pasanen also goes deep on route types, including Route Type 2 for MAC advertisement, Route Type 3 for inclusive multicast, Route Type 4 for Ethernet Segment discovery, Route Type 1 for Ethernet AD, and Route Type 5 for prefix advertisement.

Which course should I take for Cisco Nexus Dashboard?

Take Deploying VXLAN EVPN Fabrics with Cisco Nexus Dashboard 4.2 if you already understand a VXLAN EVPN fabric built on NX-OS. It is not the best first VXLAN course because it assumes you can read outputs such as show ip route and show bgp l2vpn evpn.

The course covers Nexus Dashboard cluster deployment, Fabric Builder, POAP switch onboarding, device roles, vPC domains, VRFs and networks, overlay verification, L3Out external connectivity, route control, brownfield import, and Multi-Site fabric groups.

Which course is best for migrating from a classical Ethernet data center to VXLAN EVPN?

Use Design and Migrate Modern Data Centers with VXLAN EVPN. It is built around the hard production problem: moving from legacy 3-tier designs with HSRP, vPC, STP, and VLAN boundaries into a Cisco Nexus VXLAN BGP EVPN fabric.

The course covers discovery, L2 and L3 interconnects, gateway movement, STP control, VLAN selection, 12-bit VLAN to 24-bit VNI mapping, MAC table stability, workload mobility, and NX-OS 10.2(3)+ coexistence mechanics.

Do I need to learn VXLAN Flood and Learn before BGP EVPN?

You do not need to deploy Flood and Learn in production before learning BGP EVPN, but it is useful to understand what EVPN improves. Flood and Learn shows the limitation of data-plane learning and BUM replication without a stronger control plane.

VXLAN EVPN Engineering: From Core Underlay to Multi-Site Fabric explicitly walks from VXLAN Flood and Learn to EVPN. The migration course also treats Flood and Learn as a possible beginning state before moving to BGP EVPN.

Which course covers Multi-Site EVPN VXLAN?

Several courses cover Multi-Site, but with different angles. Building VXLAN EVPN Fabrics Course introduces VXLAN EVPN Multi-Site with Border Gateways and includes a Multi-Site deployment lab.

Deploying VXLAN EVPN Fabrics with Cisco Nexus Dashboard 4.2 covers Multi-Site through Nexus Dashboard, including a parent fabric, child fabrics, Inter-Site Network modeling, stretched VRFs, and endpoint tracing. VXLAN EVPN Engineering includes Multi-Site as part of its advanced deployment topics.

What is included with membership for this EVPN VXLAN path?

Membership gives you access to the 6 courses in this EVPN VXLAN hub, totaling about 43 hours of video training. The path includes overlay fundamentals, EVPN/VXLAN design, Cisco Nexus CLI fabric deployment, Nexus Dashboard 4.2 operations, advanced engineering, and migration-focused content.

You can start with one course and continue into the others without choosing a separate purchase path. See the current membership options at /pricing.

Start your EVPN VXLAN training path

Choose the course that matches your starting point, then work forward into Cisco Nexus deployment, Nexus Dashboard operations, advanced engineering, or migration. One membership gives you access to the full EVPN VXLAN path in this hub.

Start your membership