That makes sense. I was thinking they could use something like DTLS [1] and tunnel just the one UDP port needed for their VXLAN connections, rather than use full-blown VPN software. I have never actually tried this myself though.
[1] https://en.wikipedia.org/wiki/Datagram_Transport_Layer_Secur...