Configuration restrictions and guidelines

When you configure VXLAN IP gateways, follow these restrictions and guidelines:

Device role

Configuration

Restrictions and guidelines

VXLAN IP gateway

Ethernet service instance and access mode

  • Use the Ethernet access mode if an Ethernet service instance uses the encapsulation untagged criterion.

  • Use the VLAN access mode if an Ethernet service instance uses the encapsulation s-vid { vlan-id [ only-tagged ] | vlan-id-list } criterion.

Priority trust mode

A VXLAN IP gateway processes the DSCP precedence in frames received from an AC as follows:

  • For Layer 3 forwarding, the gateway always uses the DSCP precedence for priority mapping, regardless of whether you configure the qos trust dscp command on the incoming interface.

  • For Layer 2 forwarding, the gateway uses the DSCP precedence for priority mapping only when the qos trust dscp command is configured on the incoming interface.

PBR

A PBR policy cannot match VXLAN packets by the source and destination IP addresses in the outer IP header on a Layer 3 interface (VSI interfaces not included). To match VXLAN packets by the source and destination IP addresses in the outer IP header, apply a PBR policy to a VSI interface.

VTEP

PBR

On a Layer 3 interface, a PBR policy cannot match VXLAN packets by the source and destination IP addresses in the outer IP header.

Border gateway

ACL

An ACL applied to a Layer 3 Ethernet interface or Layer 3 aggregate interface matches packets on both the interface and its subinterfaces. For more information about ACLs, see ACL and QoS Configuration Guide.

QoS

  • A QoS policy applied to a Layer 3 Ethernet interface also takes effect on its subinterfaces if the QoS policy does not contain inner and outer VLAN ID match criteria. For more information about QoS policies, see ACL and QoS Configuration Guide.

  • If a QoS policy is applied to an interface other than a Layer 3 Ethernet interface, the inner and outer VLAN ID match criteria in the QoS policy cannot match untagged packets that are forwarded at Layer 3.

PBR

A PBR policy applied to a Layer 3 Ethernet interface or Layer 3 aggregate interface takes effect on both the interface and its subinterfaces. For more information about PBR, see Layer 3—IP Routing Configuration Guide.

Storm suppression

Broadcast, multicast, or unknown unicast storm suppression configured on a Layer 3 Ethernet interface takes effect on both the interface and its subinterfaces. For more information about storm suppression, see Layer 2LAN Switching Configuration Guide.

MAC address assignment

Do not use the mac-address command to assign MAC addresses to the following interfaces:

  • Layer 3 Ethernet interfaces.

  • Layer 3 Ethernet subinterfaces.

  • Layer 3 aggregate interfaces.

  • Layer 3 aggregate subinterfaces.

ARP

You cannot execute the arp mode uni command on interfaces of a Layer 3 border gateway. For more information about this command, see ARP commands in Layer 3IP Services Command Reference.