Network overlay
A virtual network built on top of an existing physical network by encapsulating its traffic, so separate segments can share one underlying network.
A network overlay is a logical network that runs on top of another network, called the underlay. Traffic belonging to the overlay is wrapped inside packets that the underlay knows how to deliver, a technique known as encapsulation, and unwrapped at the far end. The underlay sees only the outer headers, so several overlays can share the same physical network while each keeps its own addressing. NIST SP 800-215 gives VXLAN as an example of overlay encapsulation used in data centres and clouds.
Overlays are one of the building blocks of micro-segmentation: they let segments be defined in software without rewiring. The distinction candidates commonly blur is between the transport and the policy. Encapsulation keeps one segment’s traffic apart from another’s, but encapsulation on its own does not encrypt, so it gives no confidentiality by itself. What decides which workloads may talk to which is a separate policy layer, such as a distributed firewall. Where confidentiality is needed across the underlay, a protocol such as IPsec has to supply it.
Exam relevance: a scenario may describe segments carried over a shared network by encapsulation and then ask what protects the data. Candidates are expected to see that the overlay separates traffic but does not protect it, and that treating the overlay itself as the security control is the trap.