SERVICE INSERTION AT LOGICAL NETWORK GATEWAY
    21.
    发明申请

    公开(公告)号:US20200076684A1

    公开(公告)日:2020-03-05

    申请号:US16120283

    申请日:2018-09-02

    Applicant: VMware, Inc.

    Abstract: Some embodiments provide a method for configuring a gateway machine in a datacenter. The method receives a definition of a logical network for implementation in the datacenter. The logical network includes at least one logical switch to which logical network endpoints attach and a logical router for handling data traffic between the logical network endpoints in the datacenter and an external network. The method receives configuration data attaching a third-party service to at least one interface of the logical router via an additional logical switch designated for service attachments. The third-party service is for performing non-forwarding processing on the data traffic between the logical network endpoints and the external network. The method configures the gateway machine in the datacenter to implement the logical router and redirect at least a subset of the data traffic between the logical network endpoints and the external network to the attached third-party service.

    SERVICE INSERTION AT LOGICAL NETWORK GATEWAY
    23.
    发明公开

    公开(公告)号:US20230179474A1

    公开(公告)日:2023-06-08

    申请号:US18102684

    申请日:2023-01-28

    Applicant: VMware, Inc.

    CPC classification number: H04L41/0806 H04L12/66 H04L67/53 H04L49/355 H04L45/42

    Abstract: Some embodiments provide a method for configuring a gateway machine in a datacenter. The method receives a definition of a logical network for implementation in the datacenter. The logical network includes at least one logical switch to which logical network endpoints attach and a logical router for handling data traffic between the logical network endpoints in the datacenter and an external network. The method receives configuration data attaching a third-party service to at least one interface of the logical router via an additional logical switch designated for service attachments. The third-party service is for performing non-forwarding processing on the data traffic between the logical network endpoints and the external network. The method configures the gateway machine in the datacenter to implement the logical router and redirect at least a subset of the data traffic between the logical network endpoints and the external network to the attached third-party service.

    Service insertion at logical network gateway

    公开(公告)号:US11595250B2

    公开(公告)日:2023-02-28

    申请号:US16120283

    申请日:2018-09-02

    Applicant: VMware, Inc.

    Abstract: Some embodiments provide a method for configuring a gateway machine in a datacenter. The method receives a definition of a logical network for implementation in the datacenter. The logical network includes at least one logical switch to which logical network endpoints attach and a logical router for handling data traffic between the logical network endpoints in the datacenter and an external network. The method receives configuration data attaching a third-party service to at least one interface of the logical router via an additional logical switch designated for service attachments. The third-party service is for performing non-forwarding processing on the data traffic between the logical network endpoints and the external network. The method configures the gateway machine in the datacenter to implement the logical router and redirect at least a subset of the data traffic between the logical network endpoints and the external network to the attached third-party service.

    Providing services at the edge of a network using selected virtual tunnel interfaces

    公开(公告)号:US11212356B2

    公开(公告)日:2021-12-28

    申请号:US16904399

    申请日:2020-06-17

    Applicant: VMware, Inc.

    Abstract: For traffic exiting a logical network through a particular VTI, some embodiments perform a service classification operation for different data messages to identify different VTIs that connect the edge forwarding element to a service node to provide services required by the data messages. Each data message, in some embodiments, is then forwarded to the identified VTI to receive the required service. The identified VTI does not perform a service classification operation. The service node then returns the serviced data message to the edge forwarding element. In some embodiments, the identified VTI is not configured to perform the service classification operation and is instead configured to mark all traffic directed to the edge forwarding element as having been serviced. The marked serviced data message is received at the edge forwarding element and forwarded to a destination of the data message through the particular VTI.

    USING ROUTER AS SERVICE NODE THROUGH LOGICAL SERVICE PLANE

    公开(公告)号:US20210314277A1

    公开(公告)日:2021-10-07

    申请号:US16904442

    申请日:2020-06-17

    Applicant: VMware, Inc.

    Abstract: Some embodiments facilitate the provision of a service reachable at a virtual internet protocol (VIP) address. The VIP address is used by clients to access a set of service nodes in the logical network. Facilitating the provision of the service, in some embodiments, includes returning a serviced data message to a load balancer that selected a service node to provide the service for the load balancer to track the state of the connection using the service logical forwarding element. To use the service logical forwarding element, some embodiments configure an egress datapath of the service nodes to intercept the serviced data message before being forwarded to a logical forwarding element in the datapath from the client to the service node, and determine if the serviced data message requires routing by the routing service provided as a service by the edge forwarding element.

    GENERATING FORWARD AND REVERSE DIRECTION CONNECTION-TRACKING RECORDS FOR SERVICE PATHS AT A NETWORK EDGE

    公开(公告)号:US20210314253A1

    公开(公告)日:2021-10-07

    申请号:US16904446

    申请日:2020-06-17

    Applicant: VMware, Inc.

    Abstract: Some embodiments provide stateful services in a chain of services identified for some data messages. The edge forwarding element receives a data message at a particular interface of the edge forwarding element that is traversing the edge forwarding element in a forward direction between two machines. The edge forwarding element identifies (1) a set of stateful services for the received data message and (2) a next hop associated with the identified set of stateful services in the forward direction and a next hop associated with the identified set of stateful services in the reverse direction. Based on the identified set of services and the next hops for the forward and reverse directions, the edge forwarding element generates and stores first and second connection tracking records for the forward and reverse data message flows, respectively used to forward data messages received subsequently for the flow.

    TUNNEL-BASED SERVICE INSERTION IN PUBLIC CLOUD ENVIRONMENTS

    公开(公告)号:US20210194807A1

    公开(公告)日:2021-06-24

    申请号:US17133555

    申请日:2020-12-23

    Applicant: VMware, Inc.

    Abstract: Example methods and systems are provided a network device to perform tunnel-based service insertion in a public cloud environment. An example method may comprise establishing a tunnel between the network device and a service path. The method may also comprise: in response to receiving a first encapsulated packet, identifying the service path specified by a service insertion rule; generating and sending a second encapsulated packet over the tunnel to cause the service path to process an inner packet according to one or more services. The method may further comprise: in response to receiving, from the service path via the tunnel, a third encapsulated packet that includes the inner packet processed by the service path, sending the inner packet processed by the service path, or a fourth encapsulated packet, towards a destination address of the inner packet.

Patent Agency Ranking