3.1 Device Virtualization: Type 1/2 Hypervisors, Virtual Machines, and Virtual Switching

Key Takeaways

  • Type 1 hypervisors execute directly on physical server hardware with bare-metal efficiency, whereas Type 2 hypervisors run as software applications on top of a host operating system.

  • Virtual switches (vSwitch and Distributed Virtual Switch) replicate Layer 2 bridge forwarding without Spanning Tree Protocol, relying instead on split-horizon loop prevention rules.

  • Virtual switch VLAN tagging modes dictate the frame handling boundary: EST offloads tagging to physical switches, VST tags and untags at the hypervisor port group, and VGT passes 802.1Q tagged frames straight into guest VMs.

  • Single Root I/O Virtualization (SR-IOV) partitions a physical PCIe network adapter into Virtual Functions (VFs), allowing guest VMs direct hardware access to bypass hypervisor virtual switch latency.

  • Network Functions Virtualization (NFV) transitions proprietary hardware appliances into software instances, illustrated by enterprise virtual routers such as the Cisco Catalyst 8000v and CSR 1000v.

Last updated: October 2026

Device Virtualization: Type 1/2 Hypervisors, Virtual Machines, and Virtual Switching

Virtualization abstracts physical computing, storage, and networking hardware into logical software instances. By decoupling operating systems and network functions from underlying hardware, enterprise architectures achieve higher hardware utilization, agile provisioning, and simplified disaster recovery.

Hypervisor Architecture: Type 1 vs. Type 2

A hypervisor, or Virtual Machine Monitor (VMM), abstracts server hardware and allocates compute resources across isolated virtual machines. Hypervisors fall into two primary categories:

  • Type 1 Hypervisors (Bare-Metal): Install directly onto physical server hardware without an underlying general-purpose operating system. The hypervisor kernel directly controls CPU scheduling, memory management, and physical I/O devices. Type 1 hypervisors provide near-native execution speed, low latency, and small memory footprints. They are the enterprise standard for data centers, private clouds, and Network Functions Virtualization (NFV). Examples include VMware ESXi, Linux KVM, and Microsoft Hyper-V.
  • Type 2 Hypervisors (Hosted): Execute as user-space applications on top of an existing host operating system (e.g., Windows, macOS, or Linux). Guest VM requests must traverse the hypervisor application, host operating system kernel, and host drivers before reaching hardware. This dual-layer architecture introduces latency and scheduling overhead, making Type 2 hypervisors best suited for engineering labs, testing, and client desktop virtualization. Examples include VMware Workstation, Oracle VirtualBox, and VMware Fusion.

Hypervisor Comparison

Architectural DimensionType 1 Hypervisor (Bare-Metal)Type 2 Hypervisor (Hosted)
Execution LayerDirectly on bare-metal server hardwareOn top of a pre-existing host operating system
Kernel OverheadMinimal; dedicated, streamlined hypervisor kernelHigh; burdened by host OS background services
I/O LatencyLow and deterministic; near bare-metal performanceHigher; subject to host OS scheduling and drivers
Hardware AccessDirect access to hardware virtualization (VT-x, AMD-V)Mediated through host OS system calls and API layers
Enterprise RoleProduction data centers, private clouds, carrier NFVEngineering labs, software development, client testing
Common PlatformsVMware ESXi, Linux KVM, Microsoft Hyper-VVMware Workstation, Oracle VirtualBox, Parallels

Virtual Machine Components

A Virtual Machine (VM) represents an isolated software container running an independent guest operating system. The hypervisor provides virtualized hardware representations:

  • vCPU (Virtual CPU): Represents an assignable thread of execution mapped to physical CPU cores or hyper-threads. Modern hypervisors utilize Non-Uniform Memory Access (NUMA) node pinning to keep vCPU execution and memory access within the same physical processor socket.
  • vRAM (Virtual RAM): Hypervisors allocate physical host memory to guest VMs using dynamic reclamation techniques such as memory ballooning, transparent page sharing, and compression to permit safe memory overcommitment.
  • vNIC (Virtual NIC): Emulated adapters (e.g., Intel e1000) or paravirtualized network drivers (e.g., VMware VMXNET3, Linux virtio-net) assigned to a VM. Paravirtualized drivers bypass legacy hardware register emulation, interacting directly with the virtual switch for higher packet throughput.
  • Virtual Storage: Virtual disks (VMDK, QCOW2) attach via virtual SCSI or NVMe controllers, backed by SAN, NAS, or distributed software-defined storage solutions (such as VMware vSAN or Ceph).

Virtual Switching Architecture and Port Groups

Virtual switches replicate Layer 2 Ethernet bridging in software, interconnecting virtual machines and bridging them to physical network adapters.

  • Virtual Standard Switch (vSwitch): Managed locally on an individual hypervisor host. Configuration must be manually replicated across each host in a server cluster.
  • Distributed Virtual Switch (vDS / DVS): Centrally managed across an entire server cluster by a management controller (such as VMware vCenter). The DVS enforces consistent port profiles, QoS policies, Private VLANs, NetFlow, and port mirroring (ERSPAN) across all hosts, simplifying VM live migration.
  • Port Groups: Logical groupings of virtual ports sharing common configuration parameters, such as VLAN tagging and security rules:
    • Promiscuous Mode: When enabled, permits a VM vNIC to capture all traffic transiting the port group (useful for intrusion detection appliances).
    • MAC Address Changes: Permits or denies VMs changing their effective MAC address away from their assigned address.
    • Forged Transmits: When set to Reject, drops outgoing frames whose source MAC address does not match the VM adapter's assigned address.
  • Loop Prevention Without STP: Virtual switches do not run Spanning Tree Protocol (STP). To prevent Layer 2 forwarding loops between redundant physical uplinks, virtual switches enforce a strict split-horizon rule: a frame received on an external physical uplink is never forwarded back out another physical uplink.

Virtual Switch VLAN Tagging Modes

Virtual switches implement IEEE 802.1Q tagging across three standardized operational modes:

  1. External Switch Tagging (EST): The upstream physical switch port operates in access mode. All frames leaving the hypervisor physical uplink are untagged, and tagging occurs entirely on the physical switch. The virtual switch and guest VMs operate without VLAN awareness.
  2. Virtual Switch Tagging (VST): The upstream physical switch port is an 802.1Q trunk. The hypervisor port group is assigned a specific VLAN ID (1–4094). The virtual switch inserts the 802.1Q tag on egress traffic and strips tags before delivering frames to guest VMs. This is the standard enterprise design.
  3. Virtual Guest Tagging (VGT): The upstream physical switch port is an 802.1Q trunk, and the virtual port group is configured with VLAN 4095 (in VMware) to pass all tagged frames unmodified. The guest VM operating system must maintain an 802.1Q trunk driver to process and insert VLAN tags. VGT is commonly used for virtual routers and multi-tenant firewalls that need many VLANs on one vNIC.

VLAN Tagging Mode Comparison

ModeTagging EntityPort Group SettingPhysical Switch PortTypical Use Case
ESTPhysical switchVLAN 0 / NoneAccess modeLegacy single-VLAN servers, dedicated physical NICs
VSTHypervisor vSwitchVLAN 1–4094802.1Q TrunkStandard enterprise VMs; offloads tagging from guest OS
VGTGuest VM operating systemVLAN 4095 (All)802.1Q TrunkVirtual routers (C8000v), multi-tenant virtual firewalls

High-Performance I/O: SR-IOV

Standard virtual switching incurs CPU processing overhead for every packet processed by the hypervisor network stack. Single Root I/O Virtualization (SR-IOV) is a PCI-SIG hardware standard that enables a single physical PCIe network adapter to partition itself into multiple distinct virtual PCIe devices:

  • Physical Function (PF): The primary PCIe function representing the physical NIC, managed by the hypervisor host driver.
  • Virtual Function (VF): Lightweight PCIe functions associated with a PF, presenting dedicated transmit/receive queues and DMA channels.

By assigning a Virtual Function directly to a guest VM via PCIe passthrough, network traffic travels straight between the physical adapter and VM memory. This bypasses the hypervisor kernel and vSwitch, achieving near-native throughput and latency. However, SR-IOV prevents hypervisor-level features such as vMotion live migration and software traffic inspection.

Network Functions Virtualization (NFV) and Virtual Routers

Network Functions Virtualization (NFV) replaces proprietary hardware appliances with software-based Virtual Network Functions (VNFs) running on standard commercial off-the-shelf (COTS) x86 servers:

  • NFV Framework: Comprises the NFV Infrastructure (NFVI compute, storage, and virtualization layer), VNFs (routing, security, and load-balancing applications), and Management and Orchestration (MANO).
  • Cisco Cloud Services Router 1000v (CSR 1000v): Pioneer enterprise virtual router running IOS-XE across VMware ESXi, KVM, AWS, Azure, and Google Cloud, supporting BGP, OSPF, VRF-Lite, and DMVPN.
  • Cisco Catalyst 8000v (C8000v): The modern virtual routing platform succeeding the CSR 1000v. Designed for multi-cloud enterprise routing and SD-WAN fabrics, the C8000v uses a DPDK-based data plane for high packet throughput, zero-touch provisioning, and complete support for Catalyst SD-WAN, IPsec VPNs, and telemetry APIs.
Test Your Knowledge

Which virtual switch VLAN tagging mode requires the guest virtual machine operating system to maintain an 802.1Q trunk driver to tag and untag its own network frames?

A

External Switch Tagging (EST)

B

Virtual Switch Tagging (VST)

C

Virtual Guest Tagging (VGT)

D

Distributed Virtual Tagging (DVT)

Test Your Knowledge

In Single Root I/O Virtualization (SR-IOV), what is the architectural role of a Virtual Function (VF)?

A

It acts as a lightweight PCIe function assigned directly to a guest VM to enable direct hardware I/O passthrough

B

It manages global PCIe physical link negotiation and firmware updates across the hypervisor host

C

It inspects Layer 2 frames within the hypervisor software kernel to enforce distributed firewall rules

D

It emulates legacy IDE and SCSI disk controllers for virtual hard drive storage attachment

Test Your Knowledge

How do standard hypervisor virtual switches prevent Layer 2 bridging loops when connected via multiple redundant uplinks to external physical switches?

A

They participate actively in Spanning Tree Protocol elections by transmitting and receiving periodic BPDUs

B

They use split horizon: a frame received on one physical uplink is never sent out another physical uplink

C

They automatically shut down secondary uplinks using Unidirectional Link Detection (UDLD)

D

They dynamically convert redundant physical uplinks into Layer 3 routed point-to-point subinterfaces

Sections you finish are checked off in the contents.