Application of Zero-Trust Security Principles in VXLAN Environments
Hetti Kankanamge, Dhanushka Sampath (2026)
Hetti Kankanamge, Dhanushka Sampath
2026
Master's Programme in Computing Sciences and Electrical Engineering
Informaatioteknologian ja viestinnän tiedekunta - Faculty of Information Technology and Communication Sciences
This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.
Hyväksymispäivämäärä
2026-06-01
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi:tuni-202605316639
https://urn.fi/URN:NBN:fi:tuni-202605316639
Tiivistelmä
This thesis examines the application of Zero Trust architecture within Virtual Extensible LAN (VXLAN) environments. As modern data centers increasingly rely on overlay networks to achieve massive multi-tenant scalability, traditional perimeter defenses have become ineffective. Consequently, the primary objective of this research is to analyze the architectural challenges of securing highly distributed infrastructures and to evaluate methodologies for mitigating lateral movement vulnerabilities.
Rather than relying on a physical proof-of-concept, this study systematically evaluated existing industry frameworks, academic literature, and validated engineering designs. The analysis focused on the integration of Zero Trust Policy Engines with distributed VXLAN data planes. Specifically, it compared centralized Software-Defined Networking (SDN) models against distributed Border Gateway Protocol Ethernet Virtual Private Network (BGP EVPN) control planes, alongside an examination of hypervisor-level micro-segmentation strategies.
The findings indicate that while integrating Zero Trust into VXLAN structurally resolves internal threat propagation, it introduces a severe performance overhead, commonly referred to in the industry as the "Zero Trust Tax." The heavy IPsec cryptography and packet encapsulation required for continuous verification cause substantial latency and bandwidth degradation, ultimately necessitating physical underlay modifications such as Maximum Transmission Unit (MTU) adjustments.
Ultimately, the research concludes that purely software-based enforcement is unsustainable at scale. To achieve high-speed, secure overlay networks, the industry must transition toward hybrid control plane architectures supported by hardware acceleration, specifically utilizing Data Processing Units (DPUs) to offload cryptographic processing. By outlining these limitations and hardware requirements, this thesis offers architectural recommendations for network engineers and researchers tasked with designing resilient, high-throughput data centers that do not compromise on security.
Rather than relying on a physical proof-of-concept, this study systematically evaluated existing industry frameworks, academic literature, and validated engineering designs. The analysis focused on the integration of Zero Trust Policy Engines with distributed VXLAN data planes. Specifically, it compared centralized Software-Defined Networking (SDN) models against distributed Border Gateway Protocol Ethernet Virtual Private Network (BGP EVPN) control planes, alongside an examination of hypervisor-level micro-segmentation strategies.
The findings indicate that while integrating Zero Trust into VXLAN structurally resolves internal threat propagation, it introduces a severe performance overhead, commonly referred to in the industry as the "Zero Trust Tax." The heavy IPsec cryptography and packet encapsulation required for continuous verification cause substantial latency and bandwidth degradation, ultimately necessitating physical underlay modifications such as Maximum Transmission Unit (MTU) adjustments.
Ultimately, the research concludes that purely software-based enforcement is unsustainable at scale. To achieve high-speed, secure overlay networks, the industry must transition toward hybrid control plane architectures supported by hardware acceleration, specifically utilizing Data Processing Units (DPUs) to offload cryptographic processing. By outlining these limitations and hardware requirements, this thesis offers architectural recommendations for network engineers and researchers tasked with designing resilient, high-throughput data centers that do not compromise on security.
