With Junos 19.4R2 onward, EX3400 and EX4300 can serve as a fully functional EVPN-VXLAN leaf — IRB anycast on every leaf, full Type-2 MAC-IP learning and interop with QFX5120/QFX5220 spines.

1. Why Use EX As A Leaf

EX3400/EX4300 at price points QFX cannot match. Same functional fabric, one third of the price.

If you are about to spend 70k on a QFX5120 stack for an eight-leaf campus fabric, try the EX3400/EX4300 leaves first.

2. Topology — Two-Site Campus EVPN-VXLAN

  • Spines: 2 × QFX5120-48Y per site. ASN 65000.
  • Leaves: 4 × EX4300-48T per site.
  • Underlay eBGP with BFD for sub-50ms failure.
  • Overlay iBGP EVPN on lo0.0 to both spines.

3. Underlay

3.1 EX4300

set interfaces lo0 unit 0 family inet address 10.255.10.1/32
set interfaces xe-0/2/0 unit 0 family inet address 10.20.0.1/31
set interfaces xe-0/2/1 unit 0 family inet address 10.20.0.3/31
set policy-options policy-statement UPLINK-LO0 term 1 from route-filter 10.255.10.0/24 orlonger
set policy-options policy-statement UPLINK-LO0 term 1 then accept
set protocols bgp group UPLINK type external export UPLINK-LO0
set protocols bgp group UPLINK neighbor 10.20.0.0 peer-as 65000
set protocols bgp group UPLINK neighbor 10.20.0.2 peer-as 65000
set protocols bgp group UPLINK bfd-liveness-detection minimum-interval 50 multiplier 3

4. Overlay — EVPN iBGP on EX Leaves

set routing-instances EVPN-VOICE instance-type mac-vrf
set routing-instances EVPN-VOICE protocols evpn encapsulation vxlan
set routing-instances EVPN-VOICE protocols evpn vni 11100
set routing-instances EVPN-VOICE protocols evpn default-gateway advertise
set routing-instances EVPN-VOICE service-type vlan-aware-vlan-bundle
set routing-instances EVPN-VOICE vtep-source-interface lo0.0
set routing-instances EVPN-VOICE route-distinguisher 10.255.10.1:11100
set routing-instances EVPN-VOICE vrf-target target:65041:11100
set routing-instances EVPN-VOICE vlans VOICE-VLAN vlan-id 100 l3-interface irb.100
set interfaces irb unit 100 family inet address 10.100.0.1/24
set interfaces irb unit 100 mac 00:23:9c:00:01:01
set protocols evpn encapsulation vxlan
set protocols evpn default-bridge-loopback 10.255.10.1
VRRP is not supported on IRB in any VxLAN routing-instance on EX3400/4300 — you must rely on EVPN anycast-gateway. You need Junos 19.4R2 or later for Vlan-Aware VLAN Bundle.

5. Layer 2 Forwarding

set vlans VOICE-VLAN vlan-id 100
set vlans VOICE-VLAN vxlan vni 11100
set vlans DATA-VLAN vlan-id 200
set vlans DATA-VLAN vxlan vni 11200
set vlans GUEST-VLAN vlan-id 300
set vlans GUEST-VLAN vxlan vni 11300

6. Verification

show evpn instance
show vxlan address-table
show bgp evpn summary
show bgp evpn route-type 2
show bgp evpn route-type 3

7. Pitfalls

7.1 VNI not visible

Set routing-instance type to mac-vrf, not evpn.

7.2 IRB U (down) but peering up

MTU mismatch. Set set interfaces irb unit X family inet mtu 1400.

8. Closing

EX3400 and EX4300 as VXLAN leaves are the most under-used capability in the Juniper switch portfolio. For deeper context, see EVPN three-vendor guide. For QoS on the trunks, see MX CoS deep dive.