What Is NFV (Network Functions Virtualization)?

Also called: Network function virtualization

Related problems: Too many separate boxes at every branch to buy, power and maintain; Waiting weeks for new hardware to add a network or security service; Want to change firewall or SD-WAN vendor without swapping hardware at every site; Need network and security appliances that run in the cloud

Network functions virtualization (NFV) is the practice of running network functions such as routers, firewalls, SD-WAN edges, WAN optimizers and load balancers as software on standard servers, instead of as separate purpose-built appliances. Each function becomes a virtual network function (VNF) that can be installed, moved or scaled through software. Telecom carriers adopted NFV to run their own networks, and businesses meet it mostly through carrier-supplied universal CPE, cloud-hosted virtual appliances and network-as-a-service offerings.

At a glance

  • NFV separates the network function, which becomes software, from the hardware it runs on, which becomes a general-purpose server or device.
  • The main building blocks are the virtual network functions, the infrastructure that hosts them and the management and orchestration (MANO) software that deploys and runs them.
  • For businesses, the most common form is a universal CPE box at a site running several functions, such as SD-WAN and a firewall, from one or more vendors.
  • It can reduce appliances and shorten changes, but performance, licensing and operational skills need checking.
  • It is often paired with software-defined networking (SDN) but is not the same thing.

What problem it solves

Traditional networks were built from single-purpose appliances: a router, a firewall, a WAN optimizer and sometimes more at every site, each from its own vendor with its own hardware lifecycle. Adding a service meant shipping and installing another box, and changing vendors meant replacing hardware at every location. For carriers, the same model made it slow and expensive to launch new services across thousands of sites.

NFV moves those functions into software. A new function can be installed on existing hardware remotely, capacity can be increased by allocating more compute, and the same hardware can host different vendors’ software over its life.

How it works

Virtual network functions. Each function runs as a virtual machine or, increasingly, as a container. Vendors sell virtual editions of their routers, firewalls and SD-WAN software alongside, or instead of, physical appliances.

NFV infrastructure. The VNFs run on standard servers with a hypervisor or container platform, either in a carrier’s data center, in a public cloud, or on a compact universal CPE device at the customer site.

Management and orchestration. Orchestration software deploys VNFs, links them in the right order (for example, traffic passes through the SD-WAN function and then the firewall), monitors them and scales them up or down. A reference framework for this architecture was developed by an industry group at ETSI, the European telecommunications standards body.

Service chaining with SDN. SDN controllers often steer traffic between VNFs, which is why the two terms appear together.

When it matters for buyers

  • Branch refreshes. A universal CPE that hosts SD-WAN and security functions can replace several boxes; check whether you are locked into the provider’s choice of software.
  • Cloud networking. Running a vendor’s virtual firewall or router in a public cloud is NFV in practice, and the same policies can then span cloud and branch.
  • Managed and as-a-service networks. Network as a service and managed SD-WAN offerings often rely on NFV behind the scenes.
  • High-throughput sites. Software on general-purpose hardware may not match a dedicated appliance at very high speeds or with every security feature enabled, so size carefully.
  • Vendor flexibility. NFV can make changing vendors easier, but licensing, orchestration and support arrangements can create their own lock-in.

Questions to ask vendors

  • Which network functions can run on this platform, and from which vendors?
  • What throughput does each function achieve on this hardware with our features (encryption, inspection) turned on?
  • Who supports the hardware, the hypervisor and each function, and who owns a problem that spans them?
  • How are VNFs licensed, and can licenses move between hardware and cloud?
  • How are software updates and security patches delivered and scheduled?
  • What happens to the site if the host device fails, and is there a high-availability option?
  • If we change providers, can we keep the hardware or the software licenses?

Our SD-WAN overview covers how virtualized edge devices fit into branch networks.

How it differs from SDN

The two are often mentioned together, which causes confusion. NFV is about where a network function runs: as software on general-purpose hardware rather than on a dedicated appliance. SDN is about how the network is controlled: decisions about forwarding traffic are made by central software and pushed to the devices, rather than worked out by each device on its own. You can virtualize a firewall without SDN, and you can run SDN on physical switches without NFV. In practice they complement each other, with SDN steering traffic through a chain of virtualized functions. Both underpin how carriers build modern networks, including 5G cores, which are designed as software functions.

Frequently Asked Questions

What is the difference between NFV and SDN?
NFV turns network functions such as firewalls and routers into software that runs on standard servers. Software-defined networking (SDN) separates the control of how traffic is forwarded from the switches and routers that forward it, so the network can be programmed centrally. They are often used together but solve different problems.
What is a VNF?
A virtual network function (VNF) is one network function, such as a router, firewall, load balancer or SD-WAN edge, packaged as software that runs on a virtualization platform. Newer designs often package functions as containers, sometimes called cloud-native network functions (CNFs).
Does NFV save money?
It can, by reducing the number of appliances and site visits, but not automatically. Software licenses, the server or universal CPE that hosts the functions, orchestration tools and the skills to run it all add cost. Compare total cost against the appliances it replaces.
Do mid-sized companies use NFV?
Usually indirectly. Most encounter it as a universal CPE device from a carrier or managed provider that hosts SD-WAN and firewall software, as virtual appliances in a public cloud, or inside a network-as-a-service offering, rather than building their own NFV platform.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.