Courseiva
Infrastructure →mediumMultiple Select

CCNP Infrastructure Practice Question

A network engineer is configuring a Cisco IOS XE router to support a site-to-site VXLAN tunnel over an existing IP underlay. The engineer must configure the NVE interface and ensure that the underlay provides the necessary transport. Which two statements are true about this configuration? (Choose two.)

⚠ Common exam trap

The trap here is assuming VXLAN needs MPLS or Layer 2 adjacency in the underlay, when it actually runs over a plain IP underlay using UDP 4789 and a sourced NVE interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VXLAN uses UDP port 4789 as the destination port for encapsulated traffic by default.

VXLAN on Cisco IOS XE uses an NVE interface that references a source interface for the tunnel source IP, and it encapsulates frames in UDP with default destination port 4789. The underlay only needs IP reachability between VTEPs; MPLS LDP, shared subnets, and Layer 2 adjacency are not required. These two statements correctly describe the configuration and transport behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The NVE interface must be assigned an IP address from the same subnet as the remote VTEP.

    Why it's wrong here

    The NVE interface is a logical interface that does not take an IP address for tunnel endpoint addressing; instead, it references a source interface. The source interface address must be routable to remote VTEP addresses, but they do not need to be in the same subnet. Requiring the same subnet would unnecessarily limit the design and is not how VXLAN VTEPs are addressed.

  • ✗

    VXLAN requires that the underlay provide Layer 2 adjacency between all VTEPs.

    Why it's wrong here

    VXLAN is designed to work over a Layer 3 underlay, which is one of its main advantages over traditional Layer 2 extensions. VTEPs only need IP reachability to each other, not Layer 2 adjacency. Requiring Layer 2 adjacency would defeat the purpose of using VXLAN to stretch Layer 2 segments across a routed network and is not a valid requirement.

  • ✗

    The underlay must run MPLS LDP to carry VXLAN traffic between VTEPs.

    Why it's wrong here

    VXLAN is an overlay technology that runs over a standard IP underlay; it does not require MPLS LDP. The underlay simply needs IP reachability between VTEP source addresses. While MPLS can be used in some designs, it is not a requirement for VXLAN, and stating that LDP is mandatory is incorrect. The overlay encapsulates traffic in UDP/IP, independent of MPLS.

  • ✓

    VXLAN uses UDP port 4789 as the destination port for encapsulated traffic by default.

    Why this is correct

    VXLAN encapsulates Layer 2 frames in UDP, and the IANA-assigned default destination port is 4789. Cisco platforms use this port by default when sending VXLAN-encapsulated traffic. If a firewall or ACL is in the path, it must permit UDP 4789 so that the tunnel traffic is not dropped. Changing the port is possible but uncommon and must match on all VTEPs.

  • ✓

    The NVE interface is configured with a source interface that provides the tunnel source IP address.

    Why this is correct

    The NVE interface requires a source interface, typically a loopback, whose IP address is used as the source of the VXLAN tunnel. This address must be reachable in the underlay so that remote VTEPs can establish the tunnel. Without a properly configured source interface, the NVE interface cannot come up and VXLAN traffic cannot be encapsulated or decapsulated correctly.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.