Abstract

This work compares two approaches to multi-tenant isolation and load balancing on a single-site, IPv6-only testbed: (1) F5 BIG-IP LTM with routing domains and administrative partitions and (2) HAProxy Community with Keepalived and Linux VRF. They are assessed across data plane isolation, management plane isolation, high availability, and operational characteristics; load-balancer takeover was measurable only for the open-source stack. Both approaches blocked all tested cross-tenant traffic through separate routing contexts and showed similar behaviour after pool-member failure. Their main difference is the management plane: F5 provides native partition-scoped administration, whereas the tested open-source stack requires additional controls.

Recommended Citation

Niedziela, A., Pokrywczyński, J., Grodzki, M. & Zwierzykowski, P.(2026). Multi-Tenant Environment Isolation in Data Centre Information Systems: A Comparative Study of Commercial and Open-Source Load Balancers. In M. Valenta, B. Mannová, R. Pergl, A. Przybylek, M. Lang, H. Linger, C. Schneider, N. Iivari, & E. Insfran (Eds.), Making ISD Sustainable: Reloaded with AI and Automation (ISD2026 Proceedings). Prague, Czech Republic: Czech Technical University in Prague. ISBN: 978-80-01-07585-2. https://doi.org/10.62036/ISD.2026.7

Paper Type

Poster

DOI

10.62036/ISD.2026.7

Share

COinS
 

Multi-Tenant Environment Isolation in Data Centre Information Systems: A Comparative Study of Commercial and Open-Source Load Balancers

This work compares two approaches to multi-tenant isolation and load balancing on a single-site, IPv6-only testbed: (1) F5 BIG-IP LTM with routing domains and administrative partitions and (2) HAProxy Community with Keepalived and Linux VRF. They are assessed across data plane isolation, management plane isolation, high availability, and operational characteristics; load-balancer takeover was measurable only for the open-source stack. Both approaches blocked all tested cross-tenant traffic through separate routing contexts and showed similar behaviour after pool-member failure. Their main difference is the management plane: F5 provides native partition-scoped administration, whereas the tested open-source stack requires additional controls.