Migrating to VXLAN EVPN with VRRP Gateway

Answer Correct answer: B — Shut down legacy Layer 3 SVIs and activate new preconfigured Layer 3 SVIs on VXLAN.

A customer migrates from a traditional Layer 2 data center network into a new SDN-based, spine-and-leaf VXLAN EVPN data center within the same location. The networks are joined to enable host migration at Layer 2. What is the final migration step, after hosts have physically migrated, to have traffic flowing through the new network without changing any host configuration?

  1. Increase VRRP priorities on new infrastructure over legacy VRRP values, then shut down legacy SVIs.
  2. Shut down legacy Layer 3 SVIs and activate new preconfigured Layer 3 SVIs on VXLAN. Correct Answer
  3. Shut down legacy infrastructure to allow VXLAN gateways to become active.
  4. Shut down legacy Layer 3 SVIs, clear ARP caches on all hosts being migrated, and then configure the legacy VRRP address onto new VXLAN core switches.

Community Votes

B
71%
D
29%

71% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests knowledge of Cisco's official limitation regarding VRRP/HSRP in VXLAN EVPN migrations, specifically that the virtual MAC address cannot be shared across the legacy and new fabrics without disruption.

This question addresses the specific constraints of migrating from a traditional Layer 2 data center to an SDN-based spine-and-leaf VXLAN EVPN fabric when using VRRP. It establishes that non-disruptive migration is impossible in this scenario due to FHRP limitations.

Many candidates choose Option D because it attempts to maintain the same IP gateway (VRRP address), but they fail to realize that the associated MAC address changes between the legacy and VXLAN gateways, causing ARP resolution failures for endpoints.

Community Discussion (5 comments)

ba7a09d 👍 1 Selected: B
https://www.cisco.com/c/en/us/td/docs/dcn/whitepapers/migrating-classic-ethernet-to-vxlan-bgp-evpn-white-paper.html
i9t6 👍 1 Selected: D
I think it is better to set the right expectation, "non disruptive migration is not supported". then the customer will be ready to engage the host's admin to support if needed.
cisco_guy 👍 2 Selected: B
Considering the VRRP issue noted by others, and having done this several times with both HSRP and VRRP, the customer already knows there will be a potential ARP issue at the endpoint level, so they take that into consideration before changing where the actual SVI will sit. Shutting it down on the old and enabling it on the new will cause short term issues. Knowing it will be an issue to me makes it part of the verification process and the right folks are available and on the call when the change occurs, therefore, there's no outage, you're in a maintenance window and end systems are being verified, you troubleshoot the ones that are having issues.
famov66542 👍 1 Selected: D
the same paper as blurain mentions reads: "The practice of changing the FHRP virtual MAC followed by a state change (active-standby) results in the highest probability that connected endpoints relearn the first-hop gateway’s new virtual MAC address. Nonetheless, a possibility remains that some endpoints will not honor the signalization through GARP or have a static MAC entry for the first-hop gateway. These endpoints require manual intervention to flush their ARP cache and hence, we recommend performing this action during a Maintenance Window."
blurain 👍 2 Selected: B
https://www.cisco.com/c/en/us/td/docs/dcn/whitepapers/migrating-classic-ethernet-to-vxlan-bgp-evpn-white-paper.html "Note: Non-disruptive migration is not supported if the existing Classic LAN fabric is using VRRP/VRRPv3 as FHRP protocol. In this case, you must schedule a maintenance window for migrating the default gateway between the legacy network and the greenfield VXLAN EVPN fabric." Considering the above, the next best answer would be B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is B because Cisco documentation explicitly states that non-disruptive migration is not supported if the existing Classic LAN fabric uses VRRP or HSRP as the First Hop Redundancy Protocol (FHRP). Since the legacy network relies on VRRP, you cannot seamlessly hand off the gateway state to the new VXLAN EVPN fabric without breaking connectivity for endpoints that have cached the old VRRP MAC address. Therefore, a maintenance window is required to shut down the legacy SVIs and activate the new ones.

Why the Other Options Are Wrong

Option A is incorrect because simply increasing priority does not solve the underlying issue of different virtual MAC addresses being used by the legacy vs. VXLAN gateways; hosts will still send traffic to the wrong MAC. Option C is too vague and doesn't address the Layer 3 gateway configuration. Option D suggests clearing ARP caches, which is impractical for a large-scale customer migration and contradicts the goal of minimal host configuration changes; furthermore, even with cleared caches, the transition involves a period where the gateway moves, which constitutes a disruption requiring a scheduled window.

Community Comment Notes

Community feedback strongly supports the necessity of a maintenance window. As one user noted, "Non-disruptive migration is not supported if the existing Classic LAN fabric is using VRRP... In this case, you must schedule a maintenance window." Another commenter highlighted that changing the FHRP virtual MAC results in the highest probability of endpoint issues, confirming why a clean break (shutting down legacy) is the standard procedure.

Official Reference

Exam Strategy

Always check for specific protocol limitations in migration scenarios. If the question mentions VRRP or HSRP in a VXLAN migration context, assume that a disruptive maintenance window is required unless the question specifies a specific technology like BGP EVPN route leaking that might allow otherwise (though VRRP itself is the blocker here).

Frequently Asked Questions

Why can't we just clear ARP caches on hosts?

Clearing ARP caches is not scalable or practical for a large customer environment. More importantly, the transition involves moving the active gateway, which inherently causes a brief outage regardless of cache state.

Does VXLAN EVPN support seamless VRRP handoff?

No. Cisco explicitly states that non-disruptive migration is not supported when VRRP or HSRP are used as the FHRP protocol due to virtual MAC address differences.

Related Analysis

← Back to 400-007 Study Guide