Networking · 18 Jun 2026 · 5 min read
VXLAN overlay for isolation without losing uptime
We deployed a VXLAN overlay across company infrastructure to isolate traffic and keep uptime guarantees at scale. What worked, and what we refused to over-engineer.
VXLAN is often sold as a data-center fashion. We used it as an operational contract: isolate traffic classes on a shared underlay without giving up the uptime number the business already quotes.
The constraint was not "can we stretch L2." The constraint was 150+ multi-vendor core devices, live national traffic, and a team that still has to troubleshoot at 2 a.m.
Design rules we kept
- Underlay remains simple, well-documented IGP plus MPLS where it already existed
- Overlay is for isolation and controlled stretch, not a second internet
- Every VNI has an owner, a change window, and a rollback
- Monitoring stays on the underlay first — overlay pretty dashboards do not page the NOC
The result that mattered
Uptime stayed at 99.9% while we gained traffic isolation we could actually explain to downstream teams. That is the only metric I will put on a case study.
If you are considering VXLAN on an ISP backbone, start from the incident you want to survive — not from the overlay white paper.
