Routelearn.net
Course menu

Course 14: VirtualizationLesson 1.1 (1 of 1 in this course)87 of 91 in the CCNA series

Virtual machines, containers and VRFs

Hypervisors, virtual machines and virtual switches, containers, and VRFs that split one router into several routing tables.

Intermediate · 12 min read

Virtualization is the use of software to divide one physical resource into several isolated logical ones. A hypervisor runs multiple virtual machines on one server, containers share the host’s operating system kernel while staying isolated from each other, and VRFs (Virtual Routing and Forwarding instances) give one router several separate routing tables.

In simple terms: Virtualization lets one physical box act like many separate ones. A server can run many virtual computers, and one router can act like several routers that don’t see each other’s routes.

A real-life situation

A small company runs a web server, a database, a mail server and a file server. Five years ago that meant four physical boxes, each about 10% busy, each needing power, cooling, rack space and its own switch port. Today the same four servers run as virtual machines on one physical server.

On the network side, the same router now serves two departments that must never see each other's traffic, and both were set up with 10.1.1.0/24 years ago. Instead of buying a second router, you split the one router into two virtual ones with VRFs. The CCNA expects you to explain both ideas.

What virtualization is

Virtualization means software pretends to be hardware, so one physical device can act as several independent ones. The CCNA covers three kinds:

  • Server virtualization: one physical server runs many virtual machines.
  • Containers: one operating system runs many isolated applications.
  • Network virtualization with VRFs: one router keeps several separate routing tables.

Hypervisors and virtual machines

A virtual machine (VM) is a complete computer made of software: virtual CPUs, memory, disk and network cards. Each VM runs its own guest operating system, which doesn't know it is virtual.

The hypervisor is the software that creates the VMs and shares the real CPU, memory and network cards between them. There are two types:

  • Type 1 (bare metal): the hypervisor is installed directly on the hardware, with no operating system underneath. Examples: VMware ESXi, Microsoft Hyper-V, KVM. This is what data centres and clouds use.
  • Type 2 (hosted): the hypervisor is an application running on a normal operating system such as Windows or macOS. Examples: Oracle VirtualBox, VMware Workstation. Good for labs and testing on a laptop.
Type 1 hypervisor
bare metal
App
App
App
Guest OS
Linux
Guest OS
Windows
Guest OS
Linux
Hypervisor
e.g. ESXi, Hyper-V, KVM
Physical server
CPU · RAM · disk · NICs
Type 2 hypervisor
hosted
App
App
Guest OS
Guest OS
Hypervisor app
e.g. VirtualBox
Host OS
Windows / macOS / Linux
PC or laptop
Containers
shared kernel
App + libs
App + libs
App + libs
App + libs
Container engine
e.g. Docker, containerd
Host OS + kernel
usually Linux
Server or VM
Read each stack from the bottom up. Containers have no guest OS; a type 2 hypervisor adds a host OS.

Why it works that way

Most physical servers spend most of their time idle. Putting many VMs on one server uses the hardware properly and saves power, space and cooling. Because a VM is just files, it can also be copied, backed up, or moved to another physical host while it is running (VMware calls this vMotion). That is how a host can be repaired without stopping the applications on it.

Containers go one step further. If every application runs on Linux anyway, a separate guest OS per application is wasted memory and boot time. A container packages just the application and its libraries and shares the host's kernel. It starts in about a second and can be very small. Tools like Docker build and run containers; Kubernetes is an orchestrator that starts, restarts and spreads containers across many hosts.

Virtual machineContainer
ContainsFull guest OS + appsApp + its libraries
KernelIts ownShared with the host
Typical sizeGigabytesMegabytes
Start timeMinutesSeconds or less
IsolationStrong (separate OS)Lighter (separate processes)
Mixed OSes on one hostYes (Windows and Linux VMs)No (all use the host kernel)

How VM networking works: the virtual switch

Each VM has one or more virtual NICs (vNICs) with their own MAC addresses. They plug into a virtual switch (vSwitch) inside the hypervisor. The vSwitch is a real Layer 2 switch in software: it learns MAC addresses, can place each VM in a VLAN, and tags frames with 802.1Q on its uplink. Its uplinks are the server's physical NICs, which connect to a physical switch port configured as a trunk.

vNICvNICphysical NIC · 802.1QGi0/0.10VM1 (web)VLAN 10 · 192.168.10.21VM2 (database)VLAN 10 · 192.168.10.22vSwitchinside the hypervisorSW1Gi1/0/10 trunkR1gateway 192.168.10.1
  1. 1. VM to VM on the same host. The web VM talks to the database VM. The frame never leaves the server: the vSwitch forwards it in memory. The physical network never sees it.
  2. 2. VM to the outside. Traffic for another subnet goes to the gateway. The vSwitch tags the frame for VLAN 10 and sends it out the physical NIC to SW1's trunk port.
  3. 3. The reply comes back the same way. SW1 learned VM1's MAC on its port Gi1/0/10. Many MACs on one physical port is normal for a virtualization host.

Two consequences for network engineers: the switch port to a virtualization host is usually a trunk carrying every VLAN the VMs use, and port security limits such as "one MAC per port" break VM hosts. Network devices themselves can be virtual too: routers and firewalls run as VMs (Cisco's Catalyst 8000V is a virtual IOS XE router), which is how cloud networks are built (see Cloud networking).

VRFs: virtual routers inside one router

A VRF (Virtual Routing and Forwarding instance) is a separate routing table on a router. Each interface belongs to exactly one VRF, or to the normal global table if you assign none. A packet arriving on an interface is routed using only that interface's VRF table, so it can only leave through interfaces in the same VRF.

This gives two things that a single routing table can't:

  • Isolation: customers or departments in different VRFs can't reach each other, even through the same router.
  • Overlapping addresses: two VRFs can both use 10.1.1.0/24, because each address only has to be unique within its own table.
Gi0/1 · 10.1.1.1 (CUST-A)Gi0/2 · 10.1.1.1 (CUST-B)Gi0/3 · 172.16.10.1 (CUST-A)CUST-APC-A10.1.1.10 · CUST-ACUST-BPC-B10.1.1.10 · CUST-BR1two routing tablesCUST-AServer A172.16.10.10 · CUST-A
  1. 1. PC-A reaches its server. The packet arrives on Gi0/1, which is in CUST-A. R1 looks only in the CUST-A table, finds 172.16.10.0/24 on Gi0/3 and forwards it.
  2. 2. PC-B can't. The same packet from PC-B arrives on Gi0/2, in CUST-B. The CUST-B table has no route to 172.16.10.0/24, so R1 drops it.
  3. 3. Same subnet, no conflict. Gi0/1 and Gi0/2 both have 10.1.1.1/24. In one table that would be rejected as overlapping; in two VRFs it is fine.

How to configure a VRF on Cisco IOS

⚠️ Commands are based on Cisco IOS / IOS XE documentation and haven't been run on a lab device here. The CCNA asks you to explain VRFs, not to configure them, but seeing the commands makes the idea concrete.

vrf definition CUST-A address-family ipv4 exit-address-family ! vrf definition CUST-B address-family ipv4 exit-address-family

Create the VRFs. 'vrf definition' is the current multi-protocol syntax; older IOS also accepts 'ip vrf CUST-A'.

interface GigabitEthernet0/1 vrf forwarding CUST-A ip address 10.1.1.1 255.255.255.0 no shutdown ! interface GigabitEthernet0/2 vrf forwarding CUST-B ip address 10.1.1.1 255.255.255.0 no shutdown ! interface GigabitEthernet0/3 vrf forwarding CUST-A ip address 172.16.10.1 255.255.255.0 no shutdown

Put each interface in its VRF first, then add the IP address. Gi0/1 and Gi0/2 share an address, which only works because they're in different VRFs.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1(config-if)#vrf forwarding CUST-A
% Interface GigabitEthernet0/1 IPv4 disabled and address(es) removed due to enabling VRF CUST-A
Moving an interface into a VRF removes its IP address. That is why the order matters: vrf forwarding first, then ip address.
ip route vrf CUST-A 0.0.0.0 0.0.0.0 172.16.10.254

Routes are added per VRF too. Without the 'vrf' keyword the route goes into the global table.

How to verify it

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip vrf
  Name                             Default RD            Interfaces
  CUST-A                           <not set>             Gi0/1
                                                         Gi0/3
  CUST-B                           <not set>             Gi0/2
Which interfaces are in which VRF. The RD (route distinguisher) is only needed for MPLS VPNs, so it isn't set here.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip route vrf CUST-A
Routing Table: CUST-A
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
       ...

Gateway of last resort is not set

      10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks
C        10.1.1.0/24 is directly connected, GigabitEthernet0/1
L        10.1.1.1/32 is directly connected, GigabitEthernet0/1
      172.16.0.0/16 is variably subnetted, 2 subnets, 2 masks
C        172.16.10.0/24 is directly connected, GigabitEthernet0/3
L        172.16.10.1/32 is directly connected, GigabitEthernet0/3
Only CUST-A's interfaces appear. show ip route without vrf shows the global table, where none of these routes exist.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#ping vrf CUST-A 172.16.10.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.16.10.10, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
A plain ping 172.16.10.10 would use the global table and fail. Every test from the router needs the vrf keyword.

What goes wrong and how to troubleshoot it

  • An interface lost its IP address. Someone added vrf forwarding after the address. Re-enter ip address.
  • Ping from the router fails, but hosts work. The ping used the global table. Use ping vrf NAME.
  • A static route has no effect. It was added to the global table. Use ip route vrf NAME ….
  • Two VMs can't reach the outside but can reach each other. The vSwitch uplink or the physical switch port doesn't carry their VLAN. Check the trunk's allowed VLANs.
  • A VM host's switch port goes err-disabled. Port security with a low MAC limit sees many VM MACs.

Common mistakes

  • Calling a type 2 hypervisor "bare metal". Bare metal is type 1.
  • Saying containers each run their own OS. They share the host kernel.
  • Mixing up VLANs (Layer 2 separation) and VRFs (Layer 3 separation).
  • Forgetting that a VRF needs its own routes; the global routes don't apply to it.

Exam tip: the CCNA 200-301 topic is "explain virtualization fundamentals (server virtualization, containers and VRFs)". Expect questions like: which hypervisor type runs directly on hardware (type 1), what a container shares with its host (the OS kernel), what connects VMs to each other inside a host (a virtual switch), and what a VRF allows (separate routing tables, so overlapping IP addresses and isolated traffic on one router).

Key takeaways

  • A hypervisor runs VMs. Type 1 runs on the hardware; type 2 runs on a host OS.
  • Each VM has its own OS; containers share the host kernel and are much lighter.
  • VMs connect through a virtual switch, usually uplinked to a physical trunk.
  • A VRF is a separate routing table; each interface belongs to one VRF.
  • VRFs isolate traffic and allow overlapping addresses on one router.

Check yourself

Predict · scenario 1

A hypervisor is installed directly on a server with no operating system underneath. What type is it?

Predict · scenario 2

What does a container share with the other containers on the same host?

Predict · scenario 3

Two VMs on the same physical host and the same VLAN exchange traffic. Which device forwards their frames?

Predict · scenario 4

R1 has Gi0/1 in VRF RED and Gi0/2 in VRF BLUE, both with 10.1.1.1/24. What happens?

Predict · scenario 5

After configuring VRFs, ping 172.16.10.10 from R1 fails, although hosts in VRF CUST-A reach that server. Why?

FAQ

Is a container just a lighter virtual machine?
Not exactly. A virtual machine pretends to be a whole computer and runs its own operating system. A container is an isolated group of processes that shares the host's operating system kernel. That makes containers much smaller and faster to start, but every container on a host must suit the same kernel type, for example Linux.
What is the difference between a VLAN and a VRF?
A VLAN splits a switch into separate Layer 2 broadcast domains. A VRF splits a router into separate Layer 3 routing tables. They are often used together: each VLAN's interface or SVI is placed into the VRF for that customer or department.
What is VRF-lite?
VRF-lite is using VRFs on a router or Layer 3 switch without MPLS. Each VRF has its own interfaces and routes on that device. Service providers extend VRFs across their networks with MPLS VPNs, which add route distinguishers and route targets; that is beyond the CCNA.
Can traffic move between two VRFs?
Not by default, which is the point. To allow it you must leak routes between VRFs on purpose, or send traffic through a device such as a firewall that connects to both. Both are beyond the CCNA exam.