Comparison
Asymmetric versus symmetric IRB
Asymmetric IRB bridges on the egress VTEP using the destination MAC. Symmetric IRB routes on a routed VNI at both ends. The packet walk and the MAC-VRF tables are not interchangeable.
Side-by-side walkthrough
One shared step index advances both scenarios. Share the URL — ?step= is part of the link.
VXLAN
Host A sends an ARP request. On a real Ethernet segment it reaches everyone; on a routed fabric there is nobody to send it to. Leaf 1 · ingress: Needs flood to every VNI 10010 peer. Leaf 2. Leaf 3. Leaf 4 · no VNI 10010. EVPN route reflector.
- Link
- Blocking
- Packet in flight
- Discarded
- Emphasis
Text equivalent of this diagram
| Element | Kind | State |
|---|---|---|
| Leaf 1 · ingress | switch | Needs: flood to every VNI 10010 peer |
| Leaf 2 | switch | — |
| Leaf 3 | switch | — |
| Leaf 4 · no VNI 10010 | switch | — |
| EVPN route reflector | router | — |
| Leaf 1 · ingress — Leaf 2 | link | up |
| Leaf 1 · ingress — Leaf 3 | link | up |
| Leaf 1 · ingress — Leaf 4 · no VNI 10010 | link | standby |
| Leaf 1 · ingress — EVPN route reflector | link | up |
Host A sends an ARP request. On a real Ethernet segment it reaches everyone; on a routed fabric there is nobody to send it to.
What changed
- Leaf 1 · ingress: Needs → flood to every VNI 10010 peer
- Emphasis on Leaf 1 · ingress
EVPN
Host A sends its first frame — usually a gratuitous ARP. Leaf 1 learns the MAC on the access port exactly as any switch would. Host A. Leaf 1: Local MAC A on Eth1/1. Route reflector. Leaf 2. Host B.
- Link
- Blocking
- Packet in flight
- Discarded
- Emphasis
Text equivalent of this diagram
| Element | Kind | State |
|---|---|---|
| Host A | host | — |
| Leaf 1 | switch | Local: MAC A on Eth1/1 |
| Route reflector | router | — |
| Leaf 2 | switch | — |
| Host B | host | — |
| Host A — Leaf 1 | link | up |
| Leaf 1 — Route reflector | link | up |
| Route reflector — Leaf 2 | link | up |
| Leaf 2 — Host B | link | up |
Host A sends its first frame — usually a gratuitous ARP. Leaf 1 learns the MAC on the access port exactly as any switch would.
What changed
- Leaf 1: Local → MAC A on Eth1/1
- Emphasis on Host A ↔ Leaf 1
Side by side
| Mechanism | VXLAN | EVPN |
|---|---|---|
| Where the IP lookup happens | Asymmetric: the ingress PE routes into the destination MAC-VRF and the egress PE only bridges. The inner destination MAC is the real host MAC. Symmetric and Asymmetric IRBRFC 9135 · PROPOSED STANDARD · October 2021 | Symmetric: both PEs route. The inner destination MAC is the egress PE’s IRB MAC, and the routed VNI is in the label/VNI stack. Symmetric IRB ProceduresRFC 9135 · PROPOSED STANDARD · October 2021 |
| What the egress table must hold | The destination host MAC in the MAC-VRF, learned from an EVPN type-2 or from local bridging. No IP lookup on egress. Asymmetric IRB ProceduresRFC 9135 · PROPOSED STANDARD · October 2021 | An IP route in the IP-VRF (host /32 or a prefix via type 5) plus the routed VNI. The host MAC is not required on the egress MAC-VRF for that hop. The BGP EVPN IP Prefix RouteRFC 9136 · PROPOSED STANDARD · October 2021 |
| Type-2 advertisement | Needs the MAC and, to suppress ARP, the host IP. One VNI, the bridged one. Asymmetric IRB ProceduresRFC 9135 · PROPOSED STANDARD · October 2021 | Needs MAC+IP with two labels/VNIs: the L2 VNI and the L3 (routed) VNI. Missing the L3 VNI is how a “symmetric” fabric becomes asymmetric in practice. Symmetric IRB ProceduresRFC 9135 · PROPOSED STANDARD · October 2021 |
| Failure that looks like VXLAN | Egress has no MAC: unknown-unicast flood or a blackhole if ARP suppression hid the miss. The underlay is fine. Asymmetric IRB ProceduresRFC 9135 · PROPOSED STANDARD · October 2021 | Egress has no IP route for the inner destination: TTL-expired or silent drop on the IRB. Operators then capture VXLAN and miss that the inner lookup is IPv4. Symmetric IRB ProceduresRFC 9135 · PROPOSED STANDARD · October 2021 |
What does not carry over
The names describe the lookup, not a vendor knob. Symmetric means the same kind of lookup (IP) on both PEs. Asymmetric means the ingress routes and the egress bridges.
RFC 9135 §4 is the definition. RFC 9136 type-5 prefixes are how a symmetric fabric advertises a subnet rather than every host MAC.
Mixing one PE configured for two-VNI (symmetric) type-2s with a peer that only installs the L2 VNI produces a blackhole that is not a VXLAN underlay problem.