VXLAN (Virtual Extensible LAN)

An overlay protocol (RFC 7348) that wraps layer-2 Ethernet frames in UDP packets so isolated segments can stretch across a layer-3 network; it separates traffic but does not encrypt it.

VXLAN, Virtual Extensible LAN, is a network overlay protocol defined in RFC 7348. It takes a complete layer-2 Ethernet frame, adds a VXLAN header, and carries the result inside a UDP packet across an ordinary routed IP network. The devices that wrap and unwrap frames, VXLAN tunnel endpoints, are commonly hypervisor virtual switches or physical switches. Each segment is named by a 24-bit VXLAN Network Identifier, which allows around 16 million segments against the 4,094 usable IDs of a VLAN. That scale suits large virtualised and multi-tenant environments.

NIST SP 800-215 names VXLAN as an example overlay in its discussion of micro-segmentation, and the point to hold is that encapsulation separates traffic without protecting it. The VXLAN header gives no confidentiality and no integrity, so anyone with access to the underlying network can read or inject frames unless the underlay is itself protected, for example with IPsec. The overlay is the transport; the security policy that decides which workloads may talk is enforced separately, by distributed firewalls or the virtual switch.

Exam relevance: a scenario is likely to describe segments stretched across a data centre or a very large number of tenant networks. Candidates are expected to recognise VXLAN as an overlay that provides separation and scale, and to avoid treating the encapsulation itself as a confidentiality control.