FIREWALLS IN LOGICAL NETWORKS
    11.
    发明公开
    FIREWALLS IN LOGICAL NETWORKS 审中-公开
    防火墙在逻辑网络

    公开(公告)号:EP2748750A1

    公开(公告)日:2014-07-02

    申请号:EP12849295.6

    申请日:2012-11-15

    申请人: Nicira Inc.

    IPC分类号: G06F21/00

    摘要: Some embodiments provide a non-transitory machine readable medium of a controller of a network control system for configuring a wide area network (WAN) optimizer instance to implement a WAN optimizer for a logical network. The controller receives a configuration for the WAN optimizer to optimize network data from the logical network for transmission to another WAN optimizer. The controller identifies several other controllers in the network control system on which to implement the logical network. The controller distributes the configuration for implementation on the WAN optimizer.

    DYNAMIC DATAPATH AT EDGE GATEWAY
    13.
    发明公开

    公开(公告)号:EP3700144A1

    公开(公告)日:2020-08-26

    申请号:EP20170078.8

    申请日:2016-10-29

    申请人: Nicira, Inc.

    摘要: A gateway is provided that handles traffic in and out of a network by using a datapath pipeline. The datapath pipeline includes multiple stages for performing various data-plane packet-processing operations at the edge of the network. The processing stages include centralized routing stages and distributed routing stages. The processing stages can include service-providing stages such as NAT and firewall. The gateway caches the result previous packet operations and reapplies the result to subsequent packets that meet certain criteria. For packets that do not have applicable or valid result from previous packet processing operations, the gateway datapath daemon executes the pipelined packet processing stages and records a set of data from each stage of the pipeline and synthesizes those data into a cache entry for subsequent packets.

    DYNAMIC DATAPATH AT EDGE GATEWAY
    15.
    发明公开

    公开(公告)号:EP3366012A1

    公开(公告)日:2018-08-29

    申请号:EP16794482.6

    申请日:2016-10-29

    申请人: Nicira, Inc.

    IPC分类号: H04L12/713 H04L12/715

    摘要: A novel design of a gateway that handles traffic in and out of a network by using a datapath pipeline is provided. The datapath pipeline includes multiple stages for performing various data-plane packet-processing operations at the edge of the network. The processing stages include centralized routing stages and distributed routing stages. The processing stages can include service-providing stages such as NAT and firewall. The gateway caches the result previous packet operations and reapplies the result to subsequent packets that meet certain criteria. For packets that do not have applicable or valid result from previous packet processing operations, the gateway datapath daemon executes the pipelined packet processing stages and records a set of data from each stage of the pipeline and synthesizes those data into a cache entry for subsequent packets.

    HIERARCHICAL CONTROLLER CLUSTERS FOR INTERCONNECTING DIFFERENT LOGICAL DOMAINS
    18.
    发明公开
    HIERARCHICAL CONTROLLER CLUSTERS FOR INTERCONNECTING DIFFERENT LOGICAL DOMAINS 有权
    维多利亚VERSCHIEDENER LOGISCHERDOMÄNENHIERARCHISCHE STEUERUNGSCLUSTER

    公开(公告)号:EP2745473A1

    公开(公告)日:2014-06-25

    申请号:EP12823387.1

    申请日:2012-08-17

    申请人: Nicira Inc.

    IPC分类号: H04L12/54

    摘要: Some embodiments provide a novel network control system for managing a set of switching elements in a network. The network control system includes a first set of network controllers for managing a first set of switching elements that enable communication between a first set of machines. The network control system includes a second set of network controllers for managing a second set of switching elements that enable communication between a second set of machines. The second set of switching elements is separate from the first set of switching elements and the second set of machines is separate from the first set of machines. The network control system includes a third set of network controllers for managing the first and second sets of network controllers in order to enable communication between machines in the first set of machines and machines in the second set of machines.

    摘要翻译: 一种网络控制器,用于管理将分段网络连接到共享物理互连网络的一组互连交换元件。 网络控制器包括:i)用于接收在不同分段网络处耦合到一组网络段的逻辑交换元件的逻辑控制平面定义的接口; ii)用于将逻辑交换元件的逻辑控制平面定义翻译成逻辑转发平面中的第一组流条目的控制应用; 以及iii)用于将所述第一组流条目转换为物理控制平面中的第二组流条目的虚拟化应用。 物理控制平面中的流条目用于随后由被管理的互连交换元件转换成物理转发平面中的第三组流条目,该物理转发平面指导被管理的互连交换元件转发网络数据。

    EXTENSION OF NETWORK CONTROL SYSTEM INTO PUBLIC CLOUD

    公开(公告)号:EP3731463A1

    公开(公告)日:2020-10-28

    申请号:EP20177886.7

    申请日:2017-01-17

    申请人: Nicira Inc.

    摘要: Some embodiments provide a method for a first network controller that manages a logical network implemented in a datacenter including forwarding elements to which the first network controller does not have access. The method identifies a first data compute node (DCN) in the datacenter configured to execute a second network controller. The method distributes configuration data defining the logical network to the first DCN. The second network controller distributes sets of the configuration data to local agents executing on additional DCNs in the datacenter that send and receive messages through the logical network. Both managed forwarding elements and the local agents execute on each of the additional DCNs. Each local agent on a particular DCN is for receiving a set of configuration data from the second network controller and configuring the managed forwarding element on the particular DCN to implement the logical network according to the set of configuration data.