The resulting forwarding action can be one of the following:
action forward
The packet is forwarded as usual to its original destination.
action forward sf-ip sf-ip [esi esi] service-id svc-id
The packet is tunneled toward the sf-ip over EVPN/VXLAN overlay.
If the sf-ip cannot be resolved (see EVPN route updates and tracking), the fail-action is used. This can be either forward or drop. The default is forward. Optionally, an NSH header can be inserted.