A cloud provider is offering private cloud services to multiple enterprises, each requiring their own isolated network infrastructure, including dedicated IP address spaces, routing policies, and security controls, all running on a shared physical data center. Which data path virtualization technology provides the necessary isolation and multi-tenancy at a large scale?
- AVXLAN
- BGRE Tunnels
- CVRF-Lite
- DVLANs with Trunking
Show answer & explanationAnswer & explanation
Correct answer: A. VXLAN
VXLAN (Virtual eXtensible LAN) is designed for large-scale multi-tenancy in data centers, providing Layer 2 overlay networks over a Layer 3 underlay. It allows for a vast number of isolated network segments (up to 16 million VNIs) and can stretch Layer 2 domains across physically disparate locations, meeting the demands for dedicated IP spaces and routing policies on a shared infrastructure.
Why the other options are wrong
- B. GRE tunnels can encapsulate traffic but lack the control plane, scalability, and integration with virtual networking components that VXLAN offers for multi-tenancy.
- C. VRF-Lite provides Layer 3 routing isolation but operates on a per-router basis and doesn't inherently offer the large-scale Layer 2 extension needed for dynamic VM placement across a data center fabric.
- D. VLANs are limited to 4094 segments and provide only Layer 2 isolation, insufficient for large-scale multi-tenancy with dedicated IP spaces and routing policies.
VXLAN
VXLAN (Virtual eXtensible LAN) is a network virtualization encapsulation protocol that creates Layer 2 overlay networks on top of a Layer 3 infrastructure. It extends VLAN capabilities, supporting up to 16 million logical network segments (VNIs) and enabling large-scale multi-tenancy and mobility in data centers.
- Layer 2 overlay over Layer 3.
- Scales to 16 million logical networks (VNIs).
- Enables large-scale multi-tenancy and VM mobility.
Memory trick: VXLAN: Vast X-tended LAN, Virtualized for X-tra tenants.