BFD offload in virtual network interface controller

    公开(公告)号:US11196651B2

    公开(公告)日:2021-12-07

    申请号:US16661879

    申请日:2019-10-23

    Applicant: VMware, Inc.

    Abstract: Some embodiments provide a method for monitoring the status of a network connection between first and second host computers. The method is performed in some embodiments by a tunnel monitor executing on the first host computer that also separately executes a machine, where the machine uses a tunnel to send and receive messages to and from the second host computer. The method establishes a liveness channel with the machine to iteratively determine whether the first machine is operational. The method further establishes a monitoring session with the second host computer to iteratively determine whether the tunnel is operational. When a determination is made through the liveness channel that the machine is no longer operational, the method terminates the monitoring session with the second host computer. When a determination is made that the tunnel is no longer operational, the method notifies the machine through the liveness channel.

    Flow cache support for crypto operations and offload

    公开(公告)号:US10979542B2

    公开(公告)日:2021-04-13

    申请号:US16114987

    申请日:2018-08-28

    Applicant: VMware, Inc.

    Abstract: Certain embodiments described herein are generally directed to using a flow cache with packets comprising dynamic headers. Embodiments include receiving a packet of a packet flow from a network, parsing the packet in order to determine a flow key, and comparing the flow key to entries in the flow cache. Upon determining that the flow key does not match any of the entries, embodiments include determining whether the packet comprises a dynamic header. Upon determining that the packet comprises a dynamic header, embodiments include canceling recorded flow cache information for the packet, performing an operation on the packet, re-parsing the packet in order to determine a new flow key, and comparing the new flow key to the entries in the flow cache. Upon determining that the flow key matches an entry, embodiments include determining cached actions to perform for the packet based on the entry and performing the cached actions.

    Static routes for policy-based VPN
    53.
    发明授权

    公开(公告)号:US10938788B2

    公开(公告)日:2021-03-02

    申请号:US16218433

    申请日:2018-12-12

    Applicant: VMware, Inc.

    Abstract: Some embodiments provide a method for configuring a gateway datapath that processes data messages between a logical network implemented in a datacenter and an external network. The method receives configuration data including security policy rules for a logical router implemented by the datapath that indicate whether to apply a security protocol to certain data messages transmitted from a particular interface of the logical router. The method identifies a particular security policy rule that applies to data messages that (i) have a destination address in a set of destination addresses and (ii) meet at least one additional criteria. The method generates a static route, for a routing table used by the datapath to implement the logical router, that routes data messages with destination addresses in the set of destination addresses to the particular interface. The datapath applies the security policy rules for data messages transmitted from the particular interface.

    SPECIALIZING VIRTUAL NETWORK DEVICE PROCESSING TO AVOID INTERRUPT PROCESSING FOR HIGH PACKET RATE APPLICATIONS
    58.
    发明申请
    SPECIALIZING VIRTUAL NETWORK DEVICE PROCESSING TO AVOID INTERRUPT PROCESSING FOR HIGH PACKET RATE APPLICATIONS 有权
    专用虚拟网络设备处理以避免高分组速率应用的中断处理

    公开(公告)号:US20160182342A1

    公开(公告)日:2016-06-23

    申请号:US14574354

    申请日:2014-12-17

    Applicant: VMware, Inc.

    Abstract: A method of high packet rate network processing in a system that includes a physical host and a set of physical network interface controllers (PNICs). The physical host is hosting a set of data compute nodes (DCNs). Each DCN includes a virtual network interface controller (VNIC) for communicating with one or more PNICs to exchange packets. The method determines that a rate of packets received from a particular DCN at the VNIC of the particular DCN exceeds a predetermined threshold. The method performs polling to determine the availability of packets received at the VNIC from the particular DCN while the rate of packets received from the DCN at the VNIC is exceeding the threshold. The method utilizes interrupts to determine the availability of packets received at the VNIC from the particular DCN while the rate of packets received from the DCN at the VNIC does not exceed the threshold.

    Abstract translation: 在包括物理主机和一组物理网络接口控制器(PNIC)的系统中的高分组速率网络处理的方法。 物理主机正在托管一组数据计算节点(DCN)。 每个DCN包括用于与一个或多个PNIC通信以交换分组的虚拟网络接口控制器(VNIC)。 该方法确定从特定DCN的VNIC处的特定DCN接收到的分组的速率超过预定阈值。 该方法执行轮询以确定在VNIC处从特定DCN接收的分组的可用性,而从VNIC处的DCN接收到的分组的速率超过阈值。 该方法利用中断来确定在VNIC处从特定DCN接收的分组的可用性,而从VNIC处的DCN接收到的分组的速率不超过阈值。

    SCALING EDGE SERVICES WITH MINIMAL DISRUPTION

    公开(公告)号:US20230224240A1

    公开(公告)日:2023-07-13

    申请号:US17571409

    申请日:2022-01-07

    Applicant: VMware, Inc.

    Abstract: Some embodiments provide a method for forwarding data messages between edge nodes that perform stateful processing on flows between a logical network and an external network. At a particular edge node, the method receives a data message belonging to a flow. The edge nodes use a deterministic algorithm to select one of the edge nodes to perform processing for each flow. The method identifies a first edge node to perform processing for the flow in a previous configuration and a second edge node to perform processing for the flow in a new configuration according to the algorithm. When the first and second edge nodes are different, the method uses a probabilistic filter and a stateful connection tracker to determine whether the flow existed prior to a particular time. When the flow did not exist prior to that time, the method selects the second edge node for the received data message.

Patent Agency Ranking