StudyToCert

All certifications / CCNA / Lessons

Cisco CCNA 200-301 v2.0 · Domain 1: Network infrastructure & connectivity

Hypervisors (type 1 vs type 2), virtual machines and containers

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Modern data centers rarely run one operating system per physical server. Instead, a hypervisor lets one physical host run many isolated virtual machines (VMs), each believing it has its own CPU, memory, disk and network card. This matters to network engineers because those VMs still need VLANs (virtual LANs), IP addresses and security policy, and a lot of switching now happens inside the server in software. Understanding the layers helps you configure the physical switch port a host plugs into and explain where a packet actually travels.

A hypervisor is the software layer that creates and runs VMs and shares the physical hardware among them. A type 1 hypervisor, also called bare-metal, installs directly on the server hardware with no general-purpose operating system underneath. Examples include VMware ESXi, Microsoft Hyper-V and KVM (Kernel-based Virtual Machine). Type 1 is what you find in data centers and public clouds because it is efficient and stable. A type 2 hypervisor, also called hosted, runs as an application on top of a normal operating system such as Windows, macOS or Linux desktop. Oracle VirtualBox and VMware Workstation are examples. Type 2 is convenient for labs, training and desktop testing, but it adds overhead because hardware access passes through the host OS.

Each VM contains a full guest operating system with its own kernel, libraries and applications. It connects to the network through a virtual NIC (vNIC) that plugs into a virtual switch (vSwitch) inside the hypervisor. The vSwitch forwards frames between VMs on the same host without them ever touching a physical cable, and it uplinks through the server's physical NICs to the real network. Those uplinks are usually 802.1Q trunks so different VMs can sit in different VLANs. That is why a server-facing switch port is frequently configured as a trunk rather than an access port, often with two NICs to two switches for redundancy.

Containers take a lighter approach. Instead of virtualizing hardware, a container engine such as Docker shares the host's operating system kernel and packages only the application and its libraries. Containers start in seconds, use far less memory and disk than VMs, and many more can run on one host. The trade-off is weaker isolation: every container on a host shares one kernel, and a container must be built for that kernel type, so Linux containers need a Linux kernel. Orchestration platforms such as Kubernetes schedule, scale and connect large numbers of containers across many hosts.

Keep the layers straight, because the exam often asks you to place them. Physical hardware sits at the bottom. With type 1, the hypervisor runs directly on it and each VM runs its own guest OS. With type 2, a host OS runs on the hardware, the hypervisor runs as an application on that OS, and VMs run above it. With containers, a single host OS runs a container engine and isolated application packages share its kernel. Virtualization brings benefits the exam likes: better hardware utilization, faster provisioning from templates, snapshots before risky changes, and live migration of running VMs between hosts for maintenance.

Consider a worked example. A company replaces twelve lightly used physical servers with two hosts running a type 1 hypervisor. Each host has two physical NICs, one to each of two access switches. Those switch ports are configured with switchport mode trunk and switchport trunk allowed vlan 10,20,30, and the vSwitch places each VM's vNIC in VLAN 10, 20 or 30. Two VMs in VLAN 20 on the same host talk through the vSwitch without leaving the server. Meanwhile, a developer tests the web application on her laptop in containers, and later the operations team runs those same container images on Linux hosts in the data center.

Common mistakes: calling Hyper-V or ESXi type 2 because you see a management console on a desktop (the hypervisor itself is bare-metal); thinking containers each carry their own kernel; assuming a Windows container runs natively on a Linux kernel; configuring a server-facing port as an access port and then wondering why only one VLAN of VMs works; and forgetting that VM-to-VM traffic on one host may never appear on the physical switch, which matters for monitoring and security policy.

Exam questions use clear clue words. 'Bare metal', 'installed directly on hardware' or 'data center' point to type 1. 'Runs on top of an existing operating system' or 'desktop lab software' points to type 2. 'Shares the host kernel', 'lightweight', 'starts in seconds' or 'packages the app and its dependencies' points to containers. 'Each instance has its own operating system' points to VMs. 'Software switch inside the host' is a vSwitch, and 'the host uplink carries several VLANs' means an 802.1Q trunk.

Key terms

Type 1 hypervisor
A bare-metal hypervisor installed directly on server hardware, such as ESXi, Hyper-V or KVM.
Type 2 hypervisor
A hosted hypervisor that runs as an application on a desktop operating system, such as VirtualBox or VMware Workstation.
Virtual machine (VM)
A software-defined computer with its own guest operating system and kernel, running on a hypervisor.
Container
An isolated application package that shares the host operating system kernel instead of running its own OS.
Virtual switch (vSwitch)
Software inside a hypervisor that switches traffic between VM virtual NICs and the host's physical NICs.
Guest OS
The operating system installed inside a virtual machine.
Orchestration
Automated scheduling, scaling and networking of many containers across hosts, as Kubernetes does.
Real-world example

A hospital's server team consolidates its file, print and directory servers onto a pair of type 1 hypervisor hosts. The network team configures each host-facing switch port as an 802.1Q trunk carrying the server, management and backup VLANs. Before patching a VM, the server team takes a snapshot, and during hardware maintenance they migrate running VMs to the other host so users notice nothing.

Exam tip: 'Bare metal' means type 1; 'runs on top of an existing OS' means type 2. If a question stresses sharing the host kernel and fast, lightweight startup, the answer is containers, not VMs.

Check yourself

Which hypervisor type would you expect on a production data-center server, and why?

Type 1 (bare-metal), because it runs directly on the hardware with less overhead and fewer layers that can fail than a hosted type 2 hypervisor.

What is the key architectural difference between a VM and a container?

A VM includes its own full guest operating system and kernel; a container shares the host operating system's kernel and packages only the app and its dependencies.

Why is a switch port connected to a virtualization host often configured as a trunk?

Because VMs on that host belong to different VLANs, so the vSwitch uplink must carry tagged traffic for several VLANs.

Two VMs in the same VLAN on the same host exchange traffic. Does it cross the physical switch?

Usually not; the hypervisor's vSwitch forwards it internally, so it never appears on the physical network.

Study CCNA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CCNA study plan