System and method for scaling multiclouds in a hybrid cloud architecture

    公开(公告)号:US10462072B2

    公开(公告)日:2019-10-29

    申请号:US15922673

    申请日:2018-03-15

    Abstract: According to one aspect, a method includes an Intercloud Fabric Switch (ICS) included in a public cloud and an ICS cluster obtaining a packet, and determining if the packet is obtained from a site-to-site link that links the ICS to an enterprise datacenter. If the packet is obtained from the site-to-site link, it is determined whether the packet is an unknown unicast packet. If the packet is an unknown unicast packet, the packet is dropped, and if not, the packet is provided to an access link that links the ICS to a virtual machine. If the packet is not obtained from the site-to-site link, it is determined whether the packet is obtained from an inter-ICS link that allows the ICS to communicate with the ICS cluster. If the packet is obtained from the inter-ICS link, the packet is dropped if it is an unknown unicast packet.

    Programmable infrastructure gateway for enabling hybrid cloud services in a network environment

    公开(公告)号:US10461959B2

    公开(公告)日:2019-10-29

    申请号:US15693340

    申请日:2017-08-31

    Abstract: An example method for a programmable infrastructure gateway for enabling hybrid cloud services in a network environment is provided and includes receiving an instruction from a hybrid cloud application executing in a private cloud, interpreting the instruction according to a hybrid cloud application programming interface, and executing the interpreted instruction in a public cloud using a cloud adapter. The method is generally executed in the infrastructure gateway including a programmable integration framework allowing generation of various cloud adapters using a cloud adapter software development kit, the cloud adapter being generated and programmed to be compatible with a specific public cloud platform of the public cloud. In specific embodiments, identical copies of the infrastructure gateway can be provided to different cloud service providers who manage disparate public cloud platforms; each copy of the infrastructure gateway can be programmed differently to generate corresponding cloud adapters compatible with the respective public cloud platforms.

    Infrastructure-exclusive service forwarding

    公开(公告)号:US10084703B2

    公开(公告)日:2018-09-25

    申请号:US15143253

    申请日:2016-04-29

    CPC classification number: H04L45/74 H04L45/00 H04L45/7453 H04L49/3009

    Abstract: A method is provided in one example embodiment and includes receiving at a network element a packet including a Network Services Header (“NSH”), in which the NSH includes an Infrastructure (“I”) flag and a service path header comprising a Service Index (“SI”), and a Service Path ID (“SPI”) and determining whether the I flag is set to a first value. The method further includes, if the I flag is set to the first value, setting the I flag to a second value and forwarding the packet to the service function that corresponds to the SI for processing. The method still further includes, if the I flag is not set to the first value, decrementing the SI and making a forwarding decision based on a new value of the SI and the SPI.

    DISTRIBUTED HYBRID CLOUD ORCHESTRATION MODEL
    54.
    发明申请

    公开(公告)号:US20180212896A1

    公开(公告)日:2018-07-26

    申请号:US15417021

    申请日:2017-01-26

    Abstract: Aspects of the instant disclosure relate to methods for facilitating intercloud resource migration. In some embodiments, a method of the subject technology can include steps for instantiating a first intercloud fabric provider platform (ICFPP) at a first cloud datacenter, instantiating a second ICFPP at a second cloud datacenter, and receiving a migration request at the first ICFPP, the migration request including a request to migrate a virtual machine (VM) workload from the first cloud datacenter to the second cloud datacenter. In some aspects, the method may further include steps for initiating, by the first ICFPP, a migration of the VM workload via the second ICFPP in response to the migration request. Systems and machine readable media are also provided.

    HIGH-EFFICIENCY SERVICE CHAINING WITH AGENTLESS SERVICE NODES

    公开(公告)号:US20180027101A1

    公开(公告)日:2018-01-25

    申请号:US15711768

    申请日:2017-09-21

    CPC classification number: H04L69/22 H04L12/4641 H04L45/302 H04L45/586

    Abstract: An example method for distributed service chaining is provided and includes receiving a packet belonging to a service chain in a distributed virtual switch (DVS) network environment, the packet includes a network service header (NSH) indicating a service path identifier identifying the service chain. The packet is provided to a virtual Ethernet module (VEM) connected to an agentless service node (SN) providing an edge service such as a server load balancer (SLB). The VEM associates a service path identifier corresponding to the service chain with a local identifier such as a virtual local area network (VLAN). The agentless SN returns the packet to the VEM for forwarding on the VLAN. Because the VLAN corresponds exactly to the service path and service chain, the packet is forwarded directly to the next node in the service chain. This can enable agentless SNs to efficiently provide a service chain for network traffic.

    Shortening of service paths in service chains in a communications network
    58.
    发明授权
    Shortening of service paths in service chains in a communications network 有权
    缩短通信网络中业务链中的业务路径

    公开(公告)号:US09559970B2

    公开(公告)日:2017-01-31

    申请号:US15055691

    申请日:2016-02-29

    Abstract: A method is provided in one embodiment and includes receiving at a network element a flow offload decision for a first service node that includes a portion of a service chain for processing a flow; recording the flow offload decision against the first service node at the network element; and propagating the flow offload decision backward on a service path to which the flow belongs if the first service node is hosted at the network element. Embodiments may also include propagating the flow offload decision backward on a service path to which the flow belongs if the flow offload decision is a propagated flow offload decision and the network element hosts a second service node that immediately precedes the service node on behalf of which the propagated flow offload decision was received and a flow offload decision has already been received by the network element from the second service node.

    Abstract translation: 在一个实施例中提供了一种方法,并且包括在网络元件处接收包括用于处理流的服务链的一部分的第一服务节点的流卸载决定; 记录网元上的第一服务节点的流量卸载决定; 并且如果第一服务节点驻留在网络元件处,则在流所属的服务路径上向后传播流卸载决策。 实施例还可以包括:如果流卸载决定是传播的流卸载决定,并且网络主机驻留在服务节点之前的第二服务节点,则在流所属的服务路径上向后传播流卸载决策, 接收到传播流卸载决定,网元从第二服务节点已经接收到流卸载决定。

    Zone-Based Firewall Policy Model for a Virtualized Data Center
    59.
    发明申请
    Zone-Based Firewall Policy Model for a Virtualized Data Center 审中-公开
    虚拟化数据中心基于区域的防火墙策略模型

    公开(公告)号:US20170012940A1

    公开(公告)日:2017-01-12

    申请号:US15270476

    申请日:2016-09-20

    Abstract: Techniques are provided for implementing a zone-based firewall policy. At a virtual network device, information is defined and stored that represents a security management zone for a virtual firewall policy comprising one or more common attributes of applications associated with the security zone. Information representing a firewall rule for the security zone is defined and comprises first conditions for matching common attributes of applications associated with the security zone and an action to be performed on application traffic. Parameters associated with the application traffic are received that are associated with properly provisioned virtual machines. A determination is made whether the application traffic parameters satisfy the conditions of the firewall rule and in response to determining that the conditions are satisfied, the action is performed.

    Abstract translation: 提供了实现基于区域的防火墙策略的技术。 在虚拟网络设备处,定义和存储表示虚拟防火墙策略的安全管理区域的信息,该虚拟防火墙策略包括与安全区域相关联的应用的一个或多个公共属性。 定义表示安全区域的防火墙规则的信息,并且包括用于匹配与安全区域相关联的应用的通用属性的第一条件以及要对应用流量执行的动作。 接收到与正确配置的虚拟机相关联的与应用程序流量相关联的参数。 确定应用业务参数是否满足防火墙规则的条件,并且响应于确定满足条件,执行动作。

    DEFAULT GATEWAY EXTENSION
    60.
    发明申请
    DEFAULT GATEWAY EXTENSION 审中-公开
    默认网关延伸

    公开(公告)号:US20160352682A1

    公开(公告)日:2016-12-01

    申请号:US14749391

    申请日:2015-06-24

    Abstract: Many hybrid cloud topologies require virtual machines in a public cloud to use a router in a private cloud, even when the virtual machine is transmitting to another virtual machine in the public cloud. Routing data through an enterprise router on the private cloud via the internet is generally inefficient. This problem can be overcome by placing a router within the public cloud that mirrors much of the routing functionality of the enterprise router. A switch configured to intercept address resolution protocol (ARP) request for the enterprise router's address and fabricate a response using the MAC address of the router in the public cloud.

    Abstract translation: 许多混合云拓扑需要公共云中的虚拟机在私有云中使用路由器,即使虚拟机正在传播到公共云中的另一个虚拟机。 通过互联网在私有云上通过企业路由器路由数据通常效率低下。 通过将路由器放置在公共云中来反映企业路由器的大部分路由功能,可以克服这个问题。 交换机被配置为拦截企业路由器地址的地址解析协议(ARP)请求,并使用公共云中的路由器的MAC地址来制定响应。

Patent Agency Ranking