Network Functions Virtualization (NFV)

Running network functions such as firewalls, routers and load balancers as software on general-purpose servers instead of on dedicated hardware appliances.

Network Functions Virtualization moves network functions off purpose-built appliances and runs them as software, called virtual network functions, on standard servers under a hypervisor or container platform. The idea was set out by a group of telecommunications operators in a 2012 white paper and is developed by the ETSI NFV Industry Specification Group. A firewall, router or load balancer becomes something that can be deployed, scaled or moved in software rather than shipped and racked.

NFV is often named alongside Software-Defined Networking, and the two are easy to merge. SDN separates the control plane from the data plane and logically centralises control in a controller; NFV changes what the network function runs on. Each can be used without the other, although they are commonly combined. The security consequences follow from the shift to software: the virtual functions share hardware with other workloads, so the hypervisor and the orchestration layer that deploys them become part of the attack surface and need the same hardening, authentication and change control as any management system.

Exam relevance: a scenario describing a firewall or router delivered as a virtual instance on commodity hardware is likely to point to NFV. Questions in this area tend to test whether a candidate can separate NFV (virtualising the function) from SDN (separating control from forwarding).