A real-life situation
A small company runs a web server, a database, a mail server and a file server. Five years ago that meant four physical boxes, each about 10% busy, each needing power, cooling, rack space and its own switch port. Today the same four servers run as virtual machines on one physical server.
On the network side, the same router now serves two departments that must never see each other's traffic, and both were set up with 10.1.1.0/24 years ago. Instead of buying a second router, you split the one router into two virtual ones with VRFs. The CCNA expects you to explain both ideas.
What virtualization is
Virtualization means software pretends to be hardware, so one physical device can act as several independent ones. The CCNA covers three kinds:
- Server virtualization: one physical server runs many virtual machines.
- Containers: one operating system runs many isolated applications.
- Network virtualization with VRFs: one router keeps several separate routing tables.
Hypervisors and virtual machines
A virtual machine (VM) is a complete computer made of software: virtual CPUs, memory, disk and network cards. Each VM runs its own guest operating system, which doesn't know it is virtual.
The hypervisor is the software that creates the VMs and shares the real CPU, memory and network cards between them. There are two types:
- Type 1 (bare metal): the hypervisor is installed directly on the hardware, with no operating system underneath. Examples: VMware ESXi, Microsoft Hyper-V, KVM. This is what data centres and clouds use.
- Type 2 (hosted): the hypervisor is an application running on a normal operating system such as Windows or macOS. Examples: Oracle VirtualBox, VMware Workstation. Good for labs and testing on a laptop.
Why it works that way
Most physical servers spend most of their time idle. Putting many VMs on one server uses the hardware properly and saves power, space and cooling. Because a VM is just files, it can also be copied, backed up, or moved to another physical host while it is running (VMware calls this vMotion). That is how a host can be repaired without stopping the applications on it.
Containers go one step further. If every application runs on Linux anyway, a separate guest OS per application is wasted memory and boot time. A container packages just the application and its libraries and shares the host's kernel. It starts in about a second and can be very small. Tools like Docker build and run containers; Kubernetes is an orchestrator that starts, restarts and spreads containers across many hosts.
| Virtual machine | Container | |
|---|---|---|
| Contains | Full guest OS + apps | App + its libraries |
| Kernel | Its own | Shared with the host |
| Typical size | Gigabytes | Megabytes |
| Start time | Minutes | Seconds or less |
| Isolation | Strong (separate OS) | Lighter (separate processes) |
| Mixed OSes on one host | Yes (Windows and Linux VMs) | No (all use the host kernel) |
How VM networking works: the virtual switch
Each VM has one or more virtual NICs (vNICs) with their own MAC addresses. They plug into a virtual switch (vSwitch) inside the hypervisor. The vSwitch is a real Layer 2 switch in software: it learns MAC addresses, can place each VM in a VLAN, and tags frames with 802.1Q on its uplink. Its uplinks are the server's physical NICs, which connect to a physical switch port configured as a trunk.
- 1. VM to VM on the same host. The web VM talks to the database VM. The frame never leaves the server: the vSwitch forwards it in memory. The physical network never sees it.
- 2. VM to the outside. Traffic for another subnet goes to the gateway. The vSwitch tags the frame for VLAN 10 and sends it out the physical NIC to SW1's trunk port.
- 3. The reply comes back the same way. SW1 learned VM1's MAC on its port Gi1/0/10. Many MACs on one physical port is normal for a virtualization host.
Two consequences for network engineers: the switch port to a virtualization host is usually a trunk carrying every VLAN the VMs use, and port security limits such as "one MAC per port" break VM hosts. Network devices themselves can be virtual too: routers and firewalls run as VMs (Cisco's Catalyst 8000V is a virtual IOS XE router), which is how cloud networks are built (see Cloud networking).
VRFs: virtual routers inside one router
A VRF (Virtual Routing and Forwarding instance) is a separate routing table on a router. Each interface belongs to exactly one VRF, or to the normal global table if you assign none. A packet arriving on an interface is routed using only that interface's VRF table, so it can only leave through interfaces in the same VRF.
This gives two things that a single routing table can't:
- Isolation: customers or departments in different VRFs can't reach each other, even through the same router.
- Overlapping addresses: two VRFs can both use
10.1.1.0/24, because each address only has to be unique within its own table.
- 1. PC-A reaches its server. The packet arrives on Gi0/1, which is in CUST-A. R1 looks only in the CUST-A table, finds 172.16.10.0/24 on Gi0/3 and forwards it.
- 2. PC-B can't. The same packet from PC-B arrives on Gi0/2, in CUST-B. The CUST-B table has no route to 172.16.10.0/24, so R1 drops it.
- 3. Same subnet, no conflict. Gi0/1 and Gi0/2 both have 10.1.1.1/24. In one table that would be rejected as overlapping; in two VRFs it is fine.
How to configure a VRF on Cisco IOS
⚠️ Commands are based on Cisco IOS / IOS XE documentation and haven't been run on a lab device here. The CCNA asks you to explain VRFs, not to configure them, but seeing the commands makes the idea concrete.
vrf definition CUST-A
address-family ipv4
exit-address-family
!
vrf definition CUST-B
address-family ipv4
exit-address-familyCreate the VRFs. 'vrf definition' is the current multi-protocol syntax; older IOS also accepts 'ip vrf CUST-A'.
interface GigabitEthernet0/1
vrf forwarding CUST-A
ip address 10.1.1.1 255.255.255.0
no shutdown
!
interface GigabitEthernet0/2
vrf forwarding CUST-B
ip address 10.1.1.1 255.255.255.0
no shutdown
!
interface GigabitEthernet0/3
vrf forwarding CUST-A
ip address 172.16.10.1 255.255.255.0
no shutdownPut each interface in its VRF first, then add the IP address. Gi0/1 and Gi0/2 share an address, which only works because they're in different VRFs.
R1(config-if)#vrf forwarding CUST-A % Interface GigabitEthernet0/1 IPv4 disabled and address(es) removed due to enabling VRF CUST-A
vrf forwarding first, then ip address.ip route vrf CUST-A 0.0.0.0 0.0.0.0 172.16.10.254Routes are added per VRF too. Without the 'vrf' keyword the route goes into the global table.
How to verify it
R1#show ip vrf Name Default RD Interfaces CUST-A <not set> Gi0/1 Gi0/3 CUST-B <not set> Gi0/2
R1#show ip route vrf CUST-A Routing Table: CUST-A Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP ... Gateway of last resort is not set 10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks C 10.1.1.0/24 is directly connected, GigabitEthernet0/1 L 10.1.1.1/32 is directly connected, GigabitEthernet0/1 172.16.0.0/16 is variably subnetted, 2 subnets, 2 masks C 172.16.10.0/24 is directly connected, GigabitEthernet0/3 L 172.16.10.1/32 is directly connected, GigabitEthernet0/3
show ip route without vrf shows the global table, where none of these routes exist.R1#ping vrf CUST-A 172.16.10.10 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 172.16.10.10, timeout is 2 seconds: !!!!! Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
ping 172.16.10.10 would use the global table and fail. Every test from the router needs the vrf keyword.What goes wrong and how to troubleshoot it
- An interface lost its IP address. Someone added
vrf forwardingafter the address. Re-enterip address. - Ping from the router fails, but hosts work. The ping used the global table. Use
ping vrf NAME. - A static route has no effect. It was added to the global table. Use
ip route vrf NAME …. - Two VMs can't reach the outside but can reach each other. The vSwitch uplink or the physical switch port doesn't carry their VLAN. Check the trunk's allowed VLANs.
- A VM host's switch port goes err-disabled. Port security with a low MAC limit sees many VM MACs.
Common mistakes
- Calling a type 2 hypervisor "bare metal". Bare metal is type 1.
- Saying containers each run their own OS. They share the host kernel.
- Mixing up VLANs (Layer 2 separation) and VRFs (Layer 3 separation).
- Forgetting that a VRF needs its own routes; the global routes don't apply to it.
Exam tip: the CCNA 200-301 topic is "explain virtualization fundamentals (server virtualization, containers and VRFs)". Expect questions like: which hypervisor type runs directly on hardware (type 1), what a container shares with its host (the OS kernel), what connects VMs to each other inside a host (a virtual switch), and what a VRF allows (separate routing tables, so overlapping IP addresses and isolated traffic on one router).
Key takeaways
- A hypervisor runs VMs. Type 1 runs on the hardware; type 2 runs on a host OS.
- Each VM has its own OS; containers share the host kernel and are much lighter.
- VMs connect through a virtual switch, usually uplinked to a physical trunk.
- A VRF is a separate routing table; each interface belongs to one VRF.
- VRFs isolate traffic and allow overlapping addresses on one router.
Check yourself
A hypervisor is installed directly on a server with no operating system underneath. What type is it?
What does a container share with the other containers on the same host?
Two VMs on the same physical host and the same VLAN exchange traffic. Which device forwards their frames?
R1 has Gi0/1 in VRF RED and Gi0/2 in VRF BLUE, both with 10.1.1.1/24. What happens?
After configuring VRFs, ping 172.16.10.10 from R1 fails, although hosts in VRF CUST-A reach that server. Why?