Replacing a legacy switching architecture with a VXLAN/EVPN fabric, migrating live top-of-rack switches with zero service interruption.
A full datacenter network redesign and migration for an Internet Service Provider, replacing a legacy switching architecture with a modern spine/leaf fabric based on VXLAN/EVPN. Scope covered architectural design, hardware deployment, and live migration of existing top-of-rack switches into the new fabric with zero service interruption.
The ISP was running a legacy datacenter switching architecture that could no longer scale to meet rapid traffic growth and increasing operational demands.
A flat, legacy Layer 2 topology offered poor fault isolation and constrained network growth.
Customer traffic separation depended entirely on traditional VLANs, creating a sprawling and difficult-to-manage domain.
No clear demarcation existed between customer Layer 3 traffic and internal fabric traffic.
Transit provider connectivity was tightly integrated into the core network, leaving no dedicated edge layer.
Existing top-of-rack switches sat outside any structured or cohesive fabric design.
A comprehensive spine/leaf architecture using Juniper QFX series switches, with a VXLAN/EVPN overlay fabric and a dedicated border leaf tier for customer Layer 3 traffic.
Juniper QFX10000 series switches form a pure Layer 3 spine carrying no customer traffic and no VLANs. All inter-leaf traffic routes through the spine via ECMP, optimized for maximum bandwidth and minimal latency.
Juniper QFX5000 series switches serve as top-of-rack nodes. VXLAN tunnels are established between all leaf pairs, with EVPN as the control plane for MAC and IP distribution. Each leaf operates as a VXLAN Tunnel Endpoint.
Dedicated border leaf switches exclusively handle customer Layer 3 traffic, creating clear separation between fabric-internal switching and customer routing. A VRF-per-customer model ensures traffic never bleeds into the underlay or into other customer domains.
Cisco ASR routers manage transit provider connectivity. BGP sessions with upstream providers terminate on the ASRs, which peer with the border leafs to exchange routes into the internal fabric.
An IGP runs across spine and leaf layers for underlay reachability, with all spine-to-leaf links configured as Layer 3 point-to-point, eliminating Spanning Tree within the underlay. The VXLAN overlay provides Layer 2 extension across Layer 3 boundaries, with EVPN handling ARP suppression, MAC/IP advertisement, and multi-homing.
Legacy ToR switches were re-homed to new leaf nodes as access-layer devices, with legacy VLANs mapped directly to corresponding VNIs in the overlay. Migration ran incrementally, one rack at a time, keeping legacy uplinks active until each switch was confirmed operational in the new fabric.
Thirty minutes with a senior engineer, covering your current environment and the gaps worth addressing first. No obligation, no sales handoff.