logoalt Hacker News

q3kyesterday at 10:16 PM3 repliesview on HN

Drop the VXLAN. There's almost never a good reason to stretch L2 over a WAN. Just route stuff across.


Replies

dglyesterday at 10:38 PM

This.

Instead you can create multiple Wireguard interfaces and use policy routing / ECMP / BGP / all the layer 3 tricks, that way you can achieve similar things to what vxlan could give you but at layer 3.

There's a performance benefit to doing it this way too, in some testing I found the wireguard interface can be a bottleneck (there's various offload and multiple core support in Linux, but it still has some overhead).

iscoelhoyesterday at 11:03 PM

EVPN/VXLAN fabrics are becoming industry standard for new deployments. MACSEC/IPsec is industry standard for site-to-site.

You'd be surprised to know that this is especially popular in cloud! It's just abstracted away (:

show 1 reply
cjaackieyesterday at 10:31 PM

This is the correct answer, routing between subnets is how it’s suppose to work. I think there are some edge cases like DR where it seems like stretching L2 might sound like a good idea, but it practice it gets messy fast.

show 1 reply