LOAD BALANCING
    1.
    发明公开
    LOAD BALANCING 审中-公开
    负载均衡

    公开(公告)号:EP3201761A1

    公开(公告)日:2017-08-09

    申请号:EP14903376.3

    申请日:2014-12-30

    申请人: Nicira Inc.

    IPC分类号: G06F9/44 G06F9/46

    摘要: Some embodiments provide a novel method for load balancing data messages that are sent by a source compute node (SCN) to one or more different groups of destination compute nodes (DCNs). In some embodiments, the method deploys a load balancer in the source compute node's egress datapath. This load balancer receives each data message sent from the source compute node, and determines whether the data message is addressed to one of the DCN groups for which the load balancer spreads the data traffic to balance the load across (e.g., data traffic directed to) the DCNs in the group. When the received data message is not addressed to one of the load balanced DCN groups, the load balancer forwards the received data message to its addressed destination. On the other hand, when the received data message is addressed to one of load balancer's DCN groups, the load balancer identifies a DCN in the addressed DCN group that should receive the data message, and directs the data message to the identified DCN. To direct the data message to the identified DCN, the load balancer in some embodiments changes the destination address (e.g., the destination IP address, destination port, destination MAC address, etc.) in the data message from the address of the identified DCN group to the address (e.g., the destination IP address) of the identified DCN.

    摘要翻译: 一些实施例提供了一种用于对由源计算节点(SCN)发送到一个或多个不同组的目标计算节点(DCN)的数据消息进行负载平衡的新颖方法。 在一些实施例中,该方法在源计算节点的出口数据路径中部署负载平衡器。 该负载均衡器接收从源计算节点发送的每个数据消息,并且确定数据消息是否被寻址到负载平衡器为其分配数据流量以平衡负载两端的DCN组中的一个DCN组(例如,到达的数据流量) 组中的DCN。 当接收到的数据消息没有寻址到负载平衡DCN组之一时,负载均衡器将接收到的数据消息转发到其寻址的目的地。 另一方面,当接收到的数据消息寻址到负载均衡器的DCN组中的一个时,负载均衡器识别寻址的DCN组中应接收数据消息的DCN,并将数据消息引导到所标识的DCN。 为了将数据消息引导到所标识的DCN,在一些实施例中,负载平衡器从所标识的DCN组的地址改变数据消息中的目的地地址(例如,目的地IP地址,目的地端口,目的地MAC地址等) 到识别的DCN的地址(例如,目的地IP地址)。

    A FRAMEWORK FOR COORDINATION BETWEEN ENDPOINT SECURITY AND NETWORK SECURITY SERVICES
    2.
    发明公开
    A FRAMEWORK FOR COORDINATION BETWEEN ENDPOINT SECURITY AND NETWORK SECURITY SERVICES 审中-公开
    新框架端点之间的安全和网络安全服务协调

    公开(公告)号:EP2984600A1

    公开(公告)日:2016-02-17

    申请号:EP14725858.6

    申请日:2014-04-11

    申请人: Nicira Inc.

    IPC分类号: G06F21/56 G06F21/55

    摘要: Systems and techniques are described for virtual machine security. A described technique includes operating one or more virtual machines each in accordance with a respective security container, wherein the respective security container is associated with a respective rule that specifies transfer of the virtual machine from the respective security container to a quarantine container based on one or more criteria. One or more security services are operated on the one or more virtual machines to identify one or more security threats associated with one or more of the virtual machines. One or more tags generated by the endpoint security services are obtained, where each tag is for a virtual machine that is associated with one of the identified security threats. And one of the virtual machines is identified as requiring transfer to the quarantine container based on, at least, one or more of the Obtained tags and the one or more criteria.

    PROVISIONING NETWORK SERVICES IN A SOFTWARE DEFINED DATA CENTER
    9.
    发明公开
    PROVISIONING NETWORK SERVICES IN A SOFTWARE DEFINED DATA CENTER 审中-公开
    在软件定义数据中心提供网络服务

    公开(公告)号:EP3278222A1

    公开(公告)日:2018-02-07

    申请号:EP16719163.4

    申请日:2016-04-01

    申请人: Nicira Inc.

    IPC分类号: G06F9/50 H04L12/24

    摘要: A novel method for dynamic network service allocation that maps generic services into specific configurations of service resources in a network is provided. An application that is assigned to be performed by computing resources in the network is associated with a set of generic services, and the method maps the set of generic services to the service resources based on the assignment of the application to the computing resources. The mapping of generic services is further based on a level of service that is chosen for the application, where the set of generic services are mapped to different sets of network resources according to different levels of services.