Network functions virtualization (NFV) is the practice of running network functions such as routers, firewalls, SD-WAN edges, WAN optimizers and load balancers as software on standard servers, instead of as separate purpose-built appliances. Each function becomes a virtual network function (VNF) that can be installed, moved or scaled through software. Telecom carriers adopted NFV to run their own networks, and businesses meet it mostly through carrier-supplied universal CPE, cloud-hosted virtual appliances and network-as-a-service offerings.
At a glance
- NFV separates the network function, which becomes software, from the hardware it runs on, which becomes a general-purpose server or device.
- The main building blocks are the virtual network functions, the infrastructure that hosts them and the management and orchestration (MANO) software that deploys and runs them.
- For businesses, the most common form is a universal CPE box at a site running several functions, such as SD-WAN and a firewall, from one or more vendors.
- It can reduce appliances and shorten changes, but performance, licensing and operational skills need checking.
- It is often paired with software-defined networking (SDN) but is not the same thing.
What problem it solves
Traditional networks were built from single-purpose appliances: a router, a firewall, a WAN optimizer and sometimes more at every site, each from its own vendor with its own hardware lifecycle. Adding a service meant shipping and installing another box, and changing vendors meant replacing hardware at every location. For carriers, the same model made it slow and expensive to launch new services across thousands of sites.
NFV moves those functions into software. A new function can be installed on existing hardware remotely, capacity can be increased by allocating more compute, and the same hardware can host different vendors’ software over its life.
How it works
Virtual network functions. Each function runs as a virtual machine or, increasingly, as a container. Vendors sell virtual editions of their routers, firewalls and SD-WAN software alongside, or instead of, physical appliances.
NFV infrastructure. The VNFs run on standard servers with a hypervisor or container platform, either in a carrier’s data center, in a public cloud, or on a compact universal CPE device at the customer site.
Management and orchestration. Orchestration software deploys VNFs, links them in the right order (for example, traffic passes through the SD-WAN function and then the firewall), monitors them and scales them up or down. A reference framework for this architecture was developed by an industry group at ETSI, the European telecommunications standards body.
Service chaining with SDN. SDN controllers often steer traffic between VNFs, which is why the two terms appear together.
When it matters for buyers
- Branch refreshes. A universal CPE that hosts SD-WAN and security functions can replace several boxes; check whether you are locked into the provider’s choice of software.
- Cloud networking. Running a vendor’s virtual firewall or router in a public cloud is NFV in practice, and the same policies can then span cloud and branch.
- Managed and as-a-service networks. Network as a service and managed SD-WAN offerings often rely on NFV behind the scenes.
- High-throughput sites. Software on general-purpose hardware may not match a dedicated appliance at very high speeds or with every security feature enabled, so size carefully.
- Vendor flexibility. NFV can make changing vendors easier, but licensing, orchestration and support arrangements can create their own lock-in.
Questions to ask vendors
- Which network functions can run on this platform, and from which vendors?
- What throughput does each function achieve on this hardware with our features (encryption, inspection) turned on?
- Who supports the hardware, the hypervisor and each function, and who owns a problem that spans them?
- How are VNFs licensed, and can licenses move between hardware and cloud?
- How are software updates and security patches delivered and scheduled?
- What happens to the site if the host device fails, and is there a high-availability option?
- If we change providers, can we keep the hardware or the software licenses?
Our SD-WAN overview covers how virtualized edge devices fit into branch networks.
How it differs from SDN
The two are often mentioned together, which causes confusion. NFV is about where a network function runs: as software on general-purpose hardware rather than on a dedicated appliance. SDN is about how the network is controlled: decisions about forwarding traffic are made by central software and pushed to the devices, rather than worked out by each device on its own. You can virtualize a firewall without SDN, and you can run SDN on physical switches without NFV. In practice they complement each other, with SDN steering traffic through a chain of virtualized functions. Both underpin how carriers build modern networks, including 5G cores, which are designed as software functions.
