What is network virtualization?
Network Virtualization (NV) refers to abstracting network resources
that were traditionally delivered in hardware to software. NV can combine
multiple physical networks to one virtual, software-based network, or it
can divide one physical network into separate, independent virtual
networks.
Network virtualization software allows network administrators to move
virtual machines across different domains without reconfiguring the
network. The software creates a network overlay that can run separate
virtual network layers on top of the same physical network fabric.
Why network virtualization?
Network virtualization is rewriting the rules for the way services are
delivered, from the software-defined data center (SDDC), to the cloud, to
the edge. This approach moves networks from static, inflexible, and
inefficient to dynamic, agile, and optimized. Modern networks must keep
up with the demands for cloud-hosted, distributed apps, and the
increasing threats of cybercriminals while delivering the speed and agility
you need for faster time to market for your applications. With network
virtualization, you can forget about spending days or weeks provisioning
the infrastructure to support a new application. Apps
can be deployed or updated in minutes for rapid time to value.
How does network virtualization
work?
Network virtualization decouples network services from the underlying
hardware and allows virtual provisioning of an entire network. It makes it
possible to programmatically create, provision, and manage networks all
in software, while continuing to leverage the underlying physical network
as the packet-forwarding backplane. Physical network resources, such as
switching, routing, firewalling, load balancing, virtual private networks
(VPNs), and more, are pooled, delivered in software, and require only
Internet Protocol (IP) packet forwarding from the underlying physical
network.
Benefits of network virtualization
Network virtualization helps organizations achieve major advances in
speed, agility, and security by automating and simplifying many of the
processes that go into running a data center network and managing
networking and security in the cloud. Here are some of the key benefits of
network virtualization:
Reduce network provisioning time from weeks to minutes
Achieve greater operational efficiency by automating
manual processes
Place and move workloads independently of physical
topology
Improve network security within the data center
Network Virtualization Example
One example of network virtualization is virtual LAN (VLAN). A VLAN is a
subsection of a local area network (LAN) created with software that
combines network devices into one group, regardless of physical location.
VLANs can improve the speed and performance of busy networks and
simplify changes or additions to the network.
Another example is network overlays. There are various overlay
technologies. One industry-standard technology is called virtual extensible
local area network (VXLAN). VXLAN provides a framework for overlaying
virtualized layer 2 networks over layer 3 networks, defining both an
encapsulation mechanism and a control plane. Another is generic network
virtualization encapsulation (GENEVE), which takes the same concepts but
makes them more extensible by being flexible to multiple control plane
mechanisms.
VMware NSX Data Center – Network Virtualization Platform
VMware NSX Data Center is a network virtualization platform that delivers
networking and security components like firewalling, switching, and
routing that are defined and consumed in software. NSX takes an
architectural approach built on scale-out network virtualization that
delivers consistent, pervasive connectivity and security for apps and data
wherever they reside, independent of underlying physical infrastructure.
Network Virtualization in Cloud
Computing
Read
Discuss
Courses
Prerequisite – Virtualization and its Types in Cloud Computing
Network Virtualization is a process of logically grouping physical
networks and making them operate as single or multiple
independent networks called Virtual Networks.
General Architecture Of Network Virtualization
Tools for Network Virtualization :
1. Physical switch OS –
It is where the OS must have the functionality of network virtualization.
2. Hypervisor –
It is which uses third-party software or built-in networking and the
functionalities of network virtualization.
The basic functionality of the OS is to give the application or the executing
process with a simple set of instructions. System calls that are generated by
the OS and executed through the libc library are comparable to the service
primitives given at the interface between the application and the network
through the SAP (Service Access Point).
The hypervisor is used to create a virtual switch and configuring virtual
networks on it. The third-party software is installed onto the hypervisor and it
replaces the native networking functionality of the hypervisor. A hypervisor
allows us to have various VMs all working optimally on a single piece of
computer hardware.
Functions of Network Virtualization :
It enables the functional grouping of nodes in a virtual network.
It enables the virtual network to share network resources.
It allows communication between nodes in a virtual network without
routing of frames.
It restricts management traffic.
It enforces routing for communication between virtual networks.
Network Virtualization in Virtual Data Center :
1. Physical Network
Physical components: Network adapters, switches, bridges, repeaters,
routers and hubs.
Grants connectivity among physical servers running a hypervisor,
between physical servers and storage systems and between physical
servers and clients.
2. VM Network
Consists of virtual switches.
Provides connectivity to hypervisor kernel.
Connects to the physical network.
Resides inside the physical server.
Network Virtualization In VDC
Advantages of Network Virtualization :
Improves manageability –
Grouping and regrouping of nodes are eased.
Configuration of VM is allowed from a centralized management
workstation using management software.
Reduces CAPEX –
The requirement to set up separate physical networks for different node
groups is reduced.
Improves utilization –
Multiple VMs are enabled to share the same physical network which
enhances the utilization of network resource.
Enhances performance –
Network broadcast is restricted and VM performance is improved.
Enhances security –
Sensitive data is isolated from one VM to another VM.
Access to nodes is restricted in a VM from another VM.
Disadvantages of Network Virtualization :
It needs to manage IT in the abstract.
It needs to coexist with physical devices in a cloud-integrated hybrid
environment.
Increased complexity.
Upfront cost.
Possible learning curve.
Examples of Network Virtualization :
Virtual LAN (VLAN) –
The performance and speed of busy networks can be improved by VLAN.
VLAN can simplify additions or any changes to the network.
Network Overlays –
A framework is provided by an encapsulation protocol called VXLAN for
overlaying virtualized layer 2 networks over layer 3 networks.
The Generic Network Virtualization Encapsulation protocol (GENEVE)
provides a new way to encapsulation designed to provide control-plane
independence between the endpoints of the tunnel.
Network Virtualization Platform: VMware NSX –
VMware NSX Data Center transports the components of networking and
security such as switching, firewalling and routing that are defined and
consumed in software.
It transports the operational model of a virtual machine (VM) for the
network.
Applications of Network Virtualization :
Network virtualization may be used in the development of application
testing to mimic real-world hardware and system software.
It helps us to integrate several physical networks into a single network or
separate single physical networks into multiple analytical networks.
In the field of application performance engineering, network virtualization
allows the simulation of connections between applications, services,
dependencies, and end-users for software testing.
It helps us to deploy applications in a quicker time frame, thereby
supporting a faster go-to-market.
Network virtualization helps the software testing teams to derive actual
results with expected instances and congestion issues in a networked
environment.
VLAN (virtual LAN)
What is a VLAN (virtual LAN)?
A virtual LAN (VLAN) is a logical overlay network that groups
together a subset of devices that share a physical LAN, isolating the
traffic for each group.
A LAN is a group of computers or other devices in the same place -- e.g.,
the same building or campus -- that share the same physical network. A
LAN is usually associated with an Ethernet (Layer 2) broadcast domain,
which is the set of network devices an Ethernet broadcast packet can
reach.
Computers on the LAN connect to the same network switch, either directly
or through wireless access points (APs) connected to the same switch.
Computers can also connect to one of a set of interconnected switches,
such as a set of access switches that all connect up to a backbone switch.
Once traffic crosses a router and engages Layer 3 (IP-related) functions, it
is not considered to be on the same LAN, even if everything stays in the
same building or floor. As a result, a location could have many
interconnected LANs.
A VLAN, like the LAN it sits atop, operates at Layer 2 of the network, the
Ethernet level. VLANs partition a single switched network into a set of
overlaid virtual networks that can meet different functional and security
requirements. This partitioning avoids the need to have multiple, distinct
physical networks for different use cases.
The purpose of a VLAN
Network engineers use VLANs for multiple reasons, including the following:
to improve performance
to tighten security
to ease administration
Improve performance
VLANs can improve performance for devices on them by reducing the
amount of traffic a given endpoint sees and processes. VLANs break up
broadcast domains, reducing the number of other hosts from which any
given device sees broadcasts. For example, if all desktop voice over IP
phones are on one VLAN and all workstations are on another, phones
won't see any workstation-generated broadcast traffic and vice versa. Each
can devote its network resources to relevant traffic only.
Engineers can also define different traffic-handling rules per VLAN. For
example, they can set rules to prioritize video traffic on a VLAN that
connects conference room equipment to help guarantee the performance
of telepresence devices.
Tighten security
VLAN partitioning can also improve security by enabling a higher degree of
control over which devices have access to each other. For example,
network teams may restrict management access to network gear or IoT
devices to specific VLANs.
Ease administration
Using VLANs to group endpoints also enables administrators to group
devices for purely administrative, nontechnical purposes. For example, they
may put all accounting computers on one VLAN, all human resources
computers on another and so on.