cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
509
Views
2
Helpful
3
Replies

C3650 VXLAN EVPN

mikhailov.ivan
Level 1
Level 1

Hello colleagues! Have a question that I couldn't sort by myself. There is a WS-C3650-48TS  with IOS-XE 16.12.08 , and I would like to know if it supports VXLAN\EVPN ? Wanted to connect it as a leaf switch for migration process temporary. I see that there are all VXLAN\EVPN commands in the OS , except that it doesn't support both L2 and L3 vni on the same NVE interface, but ok. I could configure the BGP\EVPN afi , and got control plane working , I can see all routes type2 and 5, but the data plane doesn't work and I can't ping other C9k leafs from a Looopback interface in a VRF, it should be over the L3VNI. I started googling and there is no official doc about the c3650 models that proves if it supports or not VXLAN , some docs say that it supports in SDA mode only, some say that it works partially , so absolutely unclear. So can someone from the vendor share an official claim about this ?  And another one: I wanted to captire the VXLAN traffic for checking if it even sends from interfaces, but in the pcap file I don't see any UDP at all , even from the C9k, looks strange. Does enyone know how to capture VXLAN from a catalyst ?

Thanks!

 
 

 

 

1 Accepted Solution

Accepted Solutions

vishalbhandari
Spotlight
Spotlight

@mikhailov.ivan The Cisco Catalyst 3650 with IOS-XE 16.12.08 does not officially support VXLAN/EVPN as a fully functional leaf switch in a VXLAN/EVPN fabric. While the CLI may show some VXLAN/EVPN commands, the 3650 is primarily designed for SDA mode, where VXLAN is limited to specific use cases and lacks comprehensive functionality, such as full L2 and L3 VNI support on the same NVE interface. The issues you’re facing with the data plane and the inability to ping through L3VNI confirm that the hardware and software lack full VXLAN/EVPN capabilities.

As for capturing VXLAN traffic, Catalyst switches like the 3650 and even the 9Ks might not show encapsulated VXLAN traffic easily via standard packet capture methods due to hardware offloading. You may need to use an external device for inline captures or specific hardware tools designed for deep inspection of VXLAN encapsulated packets. For official confirmation, I recommend contacting Cisco TAC or referring to the Catalyst 3650 product documentation.

View solution in original post

3 Replies 3

@mikhailov.ivan 

Based on datasheet, It does not support. Considering that datasheet shows what the device support only. We Will not find any mention to what It does not.

Indeed this device can be onboard on DNAC from version 16.12.x and as fabric node It must support vxlan. 

 If you can open a TAC I believe that would be the right place. The documentation is really not helping about this. 

vishalbhandari
Spotlight
Spotlight

@mikhailov.ivan The Cisco Catalyst 3650 with IOS-XE 16.12.08 does not officially support VXLAN/EVPN as a fully functional leaf switch in a VXLAN/EVPN fabric. While the CLI may show some VXLAN/EVPN commands, the 3650 is primarily designed for SDA mode, where VXLAN is limited to specific use cases and lacks comprehensive functionality, such as full L2 and L3 VNI support on the same NVE interface. The issues you’re facing with the data plane and the inability to ping through L3VNI confirm that the hardware and software lack full VXLAN/EVPN capabilities.

As for capturing VXLAN traffic, Catalyst switches like the 3650 and even the 9Ks might not show encapsulated VXLAN traffic easily via standard packet capture methods due to hardware offloading. You may need to use an external device for inline captures or specific hardware tools designed for deep inspection of VXLAN encapsulated packets. For official confirmation, I recommend contacting Cisco TAC or referring to the Catalyst 3650 product documentation.

Thanks mates! I suppose that for now we can use these claims as a proof that it doesn't support vxlan. GPT said the same Ok , I just hoped that I would be able to use vxlan for a transparent migration to vxlan fabric with a brand new c9k, but seems sadly I will have to deploy the vrf-lite.  Unfortunately I can't open a TAC case due to this is a legaci switch doesn't have a smartnet and will be deprecated soon.  It's strange that the CLI doesn't show any errors when you try to configure vxlan. I also found several topics on reddit where people have the same issue and can't get a clear answer. 

Thanks,  I hope this tred will be cashed in search engines for a future.