Md. Mahabubur Rahman
VXLAN overlay for isolation without losing uptime

Networking · 18 Jun 2026 · 5 min read

VXLAN overlay for isolation without losing uptime

We deployed a VXLAN overlay across company infrastructure to isolate traffic and keep uptime guarantees at scale. What worked, and what we refused to over-engineer.

VXLAN is often sold as a data-center fashion. We used it as an operational contract: isolate traffic classes on a shared underlay without giving up the uptime number the business already quotes.

The constraint was not "can we stretch L2." The constraint was 150+ multi-vendor core devices, live national traffic, and a team that still has to troubleshoot at 2 a.m.

Design rules we kept

  • Underlay remains simple, well-documented IGP plus MPLS where it already existed
  • Overlay is for isolation and controlled stretch, not a second internet
  • Every VNI has an owner, a change window, and a rollback
  • Monitoring stays on the underlay first — overlay pretty dashboards do not page the NOC

The result that mattered

Uptime stayed at 99.9% while we gained traffic isolation we could actually explain to downstream teams. That is the only metric I will put on a case study.

If you are considering VXLAN on an ISP backbone, start from the incident you want to survive — not from the overlay white paper.