Introduction to Network Function Virtualization

This is a guide on network function virtualization.

Check out Audible on Amazon and listen to the newest books!

 

Network function virtualization, commonly referred to as NFV, represents a significant evolution in how organizations approach network infrastructure and service delivery. While it is important to note that network function virtualization is not synonymous with software-defined networking, the two topics are closely related and frequently discussed together in modern networking conversations. Before examining the specifics of NFV, it is helpful to understand the broader context of virtualization in general.

Virtualization itself is not a new concept. It has been established for several years and has become increasingly prevalent across various aspects of information technology. Most individuals working in technology have likely encountered virtualized software, software-as-a-service offerings, or virtualized servers at some point in their careers. The practice of virtualizing servers has become extremely common in server farms and data centers, allowing organizations to maximize their hardware investments and improve operational flexibility. Network function virtualization simply takes this established virtualization process to the next logical step in the evolution of network infrastructure management.

The fundamental concept behind NFV involves taking the physical devices that would normally be deployed as dedicated hardware appliances and running them inside software as virtualized devices. To understand why this approach makes sense, consider the essential nature of common network devices. A switch or a router, for example, serves the primary purpose of directing traffic across a network. A switch uses MAC addresses and is only effective within a local network segment, while a router uses IP addresses and can be used across the Internet. Regardless of these differences, the core functionality of both devices revolves around routing and directing traffic across the network. The physical box that contains this functionality is not fundamentally important to the task being performed.

Switches and routers contain their own programming, their own software, and in many cases, their own operating systems. This raises an important question: why not take that software portion and place it in a virtual environment, completely doing away with the physical device? This same approach can be applied to intrusion detection systems, intrusion prevention systems, firewalls, load balancers, or virtually any other network function. The software within the device that actually performs the work can be extracted and placed in a virtualized environment, eliminating the need for the physical hardware altogether.

Once the concept and possibility of NFV are understood, the real question becomes whether organizations should actually implement it. Just because something can be done does not mean it should be done. Therefore, it is essential to examine the advantages that NFV offers.

Advantages of Network Function Virtualization

The benefits of implementing network function virtualization can be categorized into several areas, each offering distinct advantages to organizations of varying sizes and requirements.

Capital Expenditure Benefits

One of the most immediately apparent advantages of NFV relates to capital expenditure. Physical network appliances represent significant financial investments. Purchasing numerous physical boxes for switches, routers, firewalls, and other network functions requires substantial upfront capital. By consolidating these functions into a fewer number of virtual machine hosts—perhaps one or a few powerful servers—organizations can achieve substantial cost savings. The reduced hardware footprint translates directly into lower capital costs.

Furthermore, when an organization needs to upgrade a particular network function, the process becomes much easier, simpler, faster, and consequently cheaper. Consider a scenario where an organization needs to update fifty switches across its network. In a traditional physical environment, this would require individually updating each device, a time-consuming and labor-intensive process. With NFV, all fifty virtual switches can be updated in one fell swoop from a single location. This centralized approach to updates and upgrades significantly reduces the administrative burden and associated costs.

Operational Expenditure Benefits

Beyond capital expenditure, network function virtualization offers substantial operational expenditure benefits. Maintaining one, two, or even three servers that host virtualized devices consumes significantly less power than operating several dozen routers, dozens of switches, and all other devices as separate hardware units. Each physical device consumes power independently, so reducing the number of physical devices directly reduces overall power consumption.

For organizations accustomed to administering small-to-medium networks, the cost of power consumption may not seem particularly significant. However, for large-scale networks, this represents a very real savings that seriously and significantly impacts the budget. The cumulative effect of reduced power consumption across hundreds or thousands of devices can be substantial.

Additionally, when network functionality is virtualized, a smaller skill set is required from administrative staff. Administrators do not need to be masters of all the different vendors' hardware platforms. Instead, they only need to be able to administer the virtualized functionality, which provides a more consistent and unified management experience. This reduces training requirements, simplifies staffing decisions, and allows organizations to more effectively utilize their human resources.

Additional Operational Benefits

Several other benefits contribute to the overall value proposition of NFV. Because all devices are condensed into one or a few boxes, there is significantly less space required for network infrastructure. Data center floor space is expensive, and reducing the physical footprint of network equipment frees up valuable space for other purposes. Additionally, fewer boxes producing heat means less cooling is required, which further reduces operational costs and environmental impact. These factors allow organizations to better utilize their resources and improve overall efficiency.

In general, there are numerous benefits—operational, capital, and convenience-related—to using network function virtualization. The cumulative effect of these advantages makes NFV an increasingly attractive option for organizations seeking to modernize their network infrastructure.

Use Cases and Distinctions from Software-Defined Networking

Network function virtualization and software-defined networking are related topics, but there are key differences that must be understood to appreciate how these technologies complement each other.

Primary Purposes

The primary purpose of a software-defined network is managing and automating the administration of the network. SDN does not particularly concern itself with whether the network functionality resides on physical boxes or virtualized environments. SDN is fundamentally a management approach that provides centralized control and programmability for network resources.

Network function virtualization, by contrast, is primarily about improving provisioning. By virtualizing network functionality, it becomes much easier to provision resources, manage bandwidth, and perform similar tasks. These two technologies have different purposes, yet they frequently work together effectively.

Management Requirements

Another key difference is that network function virtualization is, by definition, managed by virtualization tools. It must be managed this way. Software-defined networking, however, can be managed by virtualized tools but does not have to be. SDN can be managed through a simple web interface or GUI interface on a standard machine, allowing organizations to implement software-defined networking without requiring a fully virtualized environment.

It is possible to have network function virtualization without SDN. In this scenario, an organization may have already virtualized other things, such as servers, and then chooses to virtualize network functionality as well. This approach is much easier if the organization has previous virtualization experience. Getting management buy-in becomes simpler when there is existing familiarity with virtualization concepts and practices. Additionally, if other functions have already been virtualized, the infrastructure is already in place to support NFV, making the transition much smoother.

Operational Benefits of NFV

What does NFV do for operations? Organizations often want to showcase the benefits in a training environment. The ability to quickly reset, reconfigure, or align equipment becomes much simpler, faster, and cheaper with NFV. Configuration is easier to control because network function virtualization allows administrators to handle all configuration issues from a centralized location through the virtualized host.

While it would be desirable for NFV implementations to provide complete awareness of the entire wide area network—what might be called WAN omniscience—this is not actually required. However, it is more likely to be achieved because devices are not so dispersed. They reside on virtualized hosts, making it easier to be aware of what is happening across the network. This also means more efficient use of bandwidth because all components are in a single location, making management easier and reducing bandwidth utilization.

Combined SDN and NFV Use Cases

Even though network function virtualization and software-defined networking are separate technologies, they are frequently used together because they work exceptionally well in combination. Network function virtualization provides an easy way to provision network functionality because all functions are contained in a virtual environment instead of physical boxes. It seems logical to manage that environment via software-defined networking, and the SDN controller provides an interface to the virtualized network functions, creating a very scalable network that is easy to expand or contract as needed and highly dynamic.

Large Complex Environments

Consider a use case where SDN and NFV are used together in a very large, complex environment. In such networks, there are numerous devices, so virtualization provides the most significant benefits. In a large network, NFV immediately demonstrates cost savings. However, because the network is large, planning traffic, managing bandwidth, and managing congestion become very significant issues. These tasks are considered to have a high cognitive load, meaning administrators must spend considerable time thinking deeply about these challenges and sometimes rethinking decisions. Adding SDN eases the management of this complex environment by providing centralized control and automation.

Dispersed IP Subnets

Another compelling use case involves dispersed IP subnets across multiple locations. An organization might have a campus with multiple buildings or locations spread throughout a metropolitan area. Placing virtual machines in multiple locations can make them appear to be local. From the virtual environment, these dispersed IP subnets might as well be next door. In fact, they could be placed on the same subnet even though they are in different physical locations. This is a significant advantage of virtualization. Combining virtualization with SDN makes it much easier to manage this distributed environment.

High-Control Environments

Environments that require a high degree of control present another strong use case for combined SDN and NFV. For example, organizations with very strict change management requirements will find that SDN excels in this area. With software-defined networking, managing the change management process becomes much easier. It is even possible to automate things like patching and rollbacks, making change management much more effective.

Regulated Industries

Consider networks used in industries with tight regulatory controls, such as credit card processing or healthcare. These industries have serious regulatory requirements and require auditing. Organizations should ask themselves whether it is easier to audit many diverse equipment spread all over the place or to have a few boxes containing all virtualized network functionality. The latter is obviously preferable. It is also easier to audit and maintain regulatory requirements from a centralized common management interface as provided with SDN rather than managing and auditing each component independently.

By combining SDN and NFV, organizations with a need for a high degree of control, dispersed IP subnets, or highly complex environments will see the most improvement. These technologies can certainly be combined in less complex environments with less need for control and completely localized operations, but the greatest benefits and savings will be realized in the three environments described.

NFV Overlay Protocols

An overlay is literally one network overlaid upon another. This concept may seem odd at first glance, but consider the Internet in its early days. The Internet was one network overlaid upon another via the public telephone telecommunications network. In that case, there was a great deal of abstraction. When connecting to a website in those days, the intervening telecommunications infrastructure meant nothing to the user. It was transparent and irrelevant to the task at hand. A similar situation occurs today with VPNs. When connecting from a remote laptop to a company's network via VPN, the intervening Internet infrastructure—which may be vast depending on distance—is totally irrelevant and abstracted away. This is essentially what an overlay is: putting one network on top of another.

Benefits of Overlays

Why use overlays? First, they are fantastic for scalability. Consider the VPN example: expanding either end of the connection is perfectly fine. In very large-scale deployments, particularly in the cloud, the overlay process is even more efficient when it comes to scaling up.

Overlays are also important because different locations can appear to be adjacent. In the VPN example, although a user might be sitting in a hotel room in Pittsburgh while the office is in Los Angeles, communication behaves as if there were no thousands of miles of intervening distance and a vast Internet network between them. It is as if the user were sitting in the office. End systems do not need to know about the connecting infrastructure. In the VPN example, the user does not need to know about all the network hops across the Internet between the source and destination. End systems can even be moved in an overlay. If a user leaves Pittsburgh, goes to Manhattan, and logs on again, nothing has changed. Overlapping address bases can also be used because one network is on top of another, allowing one to use an overlapping address space. This is particularly important for disaster recovery sites, where the ability to move end systems is highly likely.

How Overlays Work

How do these overlays work? A Layer 2 address, such as a MAC address, is encapsulated in a Layer 3 packet, an IP packet. Why? Local network segments depend on MAC addresses. Once traffic reaches the switch level, it is sent where it needs to go based on MAC address. Beyond that level, IP addresses must be used. Since the goal is to emulate a local network across nodes that could be geographically spread out, those Layer 2 addresses must be placed into Layer 3 packets. Jumbo-sized frames are often used from the entire network.

Overlay Protocols

Several protocols can accomplish this. Network virtualization using GRE (Generic Routing Encapsulation) is one option. GRE is a protocol that allows one packet to be placed inside virtual links and sent across the Internet. It is very widely supported and is a Microsoft technology.

Another option is VXLAN (Virtual eXtensible LAN). This takes MAC addresses or Layer 2 addresses used for local network segments and encapsulates them in a Layer 4 packet, specifically UDP (User Datagram Protocol). This is used for multicast, broadcast, and unknown destination traffic. It is supported on Open vSwitches and was created by a consortium of VMware, Cisco, and Arista.

DOVE (Distributed Overlay Virtual Ethernet) is another possibility. It is basically used to take Ethernet traffic, MAC-based traffic, and spread it out over a larger network by putting it on an overlaid network. There are no multicast dependencies, and it is not dependent on MAC addresses because it overlays those. It was invented by IBM and is proprietary, but there is an open-source alternative called Open DOVE.

Overlay Transport Virtualization (OTV) is another approach where each switch manages all the machines' MAC addresses across all sites. This is essentially a Cisco technology that takes Layer 2 addresses and puts them in a Layer 3 packet.

NFV Switches, Routers, and Firewalls

When considering network function virtualization, it is necessary to think about virtualized versions of all the major components.

Virtual Switches

Virtual switches are among the simpler networking components. They route traffic on the local network based on MAC address. These are available with most hypervisors. A hypervisor is the part of the virtual machine or virtual system that spawns virtual machines. VMs are connected by default to some sort of switch. In fact, many VMs, even on desktop computers, have a virtual switch automatically included. Virtual switches perform all the same functions as physical switches, not just directing traffic based on MAC addresses but also including capabilities such as creating virtual LANs (VLANs).

Virtual Routers

Virtual routers are not as commonly available in most hypervisors as switches are. Routing is often handled by the actual physical network. Network function virtualization routers route traffic between networks that are on the same hosts or even between hosts. In other words, an NFV router routes traffic wherever it needs to go.

Virtual Firewalls

Virtual firewalls are very common NFV devices. They can implement all the functions expected of a firewall, including network address translation, different rules for inbound and outbound traffic, dynamic host configuration protocol for dynamically assigning IP addresses, and basic routing functions.

There are many uses for virtual firewalls. They can segregate layers within a multi-layer application. For example, in a three-tiered application, a firewall can be placed between each layer for a robust layered security approach. On a virtual machine, various trust zones can be created even within the same virtual host or across different hosts, each separated by a virtual firewall. Virtual firewalls can also be linked with other NFV devices. Virtual firewalls are so common because they are so useful.

Other NFV Devices

Intrusion Detection Systems

Intrusion detection systems should be part of any modern approach to security. An IDS analyzes traffic looking for anomalies that could indicate an attack. For example, if a web server experiences a sudden surge in traffic—tenfold beyond normal—that could indicate a denial of service attack. An IDS will detect these anomalies. If it judges them to be likely malicious activity or attacks, it will log them. Later, the administrator will review the log and become aware that an attack occurred or likely occurred. This means the information is received after the attack is over. Some more robust IDS systems actually notify the administrator when a suspected attack is ongoing.

Network function virtualization is all about centralizing command and control of the network. An IDS, to be effective, needs a complete view of the entire network to detect any anomalous traffic. Therefore, IDSs are excellent candidates for network function virtualization.

Intrusion Prevention Systems

Intrusion prevention systems take this to another level. When they detect anomalous traffic, they block that traffic. On initially hearing this, many people conclude that this is the absolute best system. The problem is that there will be some false positives. Organizations need to examine their business needs and security posture to determine if they can withstand those false positives or if an IDS would be a better solution. If an IPS is chosen, it works through real-time analysis of network traffic to detect and prevent likely attacks. Again, this involves real-time analysis of the entire network, which is well-suited for network function virtualization, particularly if servers, switches, and routers have already been virtualized. If it is possible to buy either an IDS or an IPS with a firewall and antivirus, a more complete defense posture will result. Using any one of these products alone is only a partial solution to security.

Load Balancers

Load balancers are common network function virtualization devices. A load balancer spreads the load across several nodes in a cluster. For example, a major e-commerce site might have its website duplicated across ten members of a cluster of web servers. As a new connection comes in, the load balancer routes it to whichever member of the cluster currently has the least workload. Load balancing is very easy to do with NFV. If the servers and the switches connecting them have also been virtualized, it is common sense to virtualize the load balancer as well. It is even possible to have a virtualized load balancer that spins up new virtual machines when scaling up is necessary. For example, if traffic has been steadily increasing over six hours to the point that the cluster is approaching 80% or 90% utilization, additional virtual servers can be spun up before reaching 100% to handle the workload.

Antivirus

Network function virtualization for antivirus is also important. Antivirus can be deployed on the VM host and on a central controller. The appliance then scans all the virtual machines. Since virtual machines reside on a limited number of physical machines, the scanning is very efficient. The central controller allows centralization of all command and control of antivirus activities, whether updating antivirus files, conducting scans of all VMs simultaneously, or performing other processes. Having this centralized through NFV is a much better solution than having it on separate devices. Scans can also be coordinated with workload so that they have minimal impact on resources. Scanning all virtual machines in the middle of the workday is not advisable. These activities should be coordinated, and scans can even be paused automatically if bandwidth utilization exceeds a certain level so that network utility is not negatively impacted.

Conclusion

Network function virtualization represents a significant advancement in how organizations design, deploy, and manage their network infrastructure. By extracting network functionality from dedicated physical appliances and placing it in virtualized environments, organizations can achieve substantial capital and operational expenditure savings, improve operational flexibility, simplify management, and better utilize their resources. When combined with software-defined networking, NFV enables highly scalable, dynamic, and manageable networks that can adapt to changing requirements. From virtual switches and routers to firewalls, intrusion detection and prevention systems, load balancers, and antivirus solutions, the range of network functions that can be virtualized continues to expand. As organizations increasingly adopt cloud computing and seek to modernize their network infrastructure, network function virtualization will continue to play a central role in enabling efficient, cost-effective, and agile network operations.