SECURE AND EFFICIENT OFFLOADING OF NETWORK POLICIES TO NETWORK INTERFACE CARDS
    3.
    发明申请
    SECURE AND EFFICIENT OFFLOADING OF NETWORK POLICIES TO NETWORK INTERFACE CARDS 有权
    将网络政策安全有效地卸载到网络接口卡

    公开(公告)号:US20130061047A1

    公开(公告)日:2013-03-07

    申请号:US13565369

    申请日:2012-08-02

    CPC分类号: H04L45/586

    摘要: Techniques for efficient and secure implementation of network policies in a network interface controller (NIC) in a host computing device operating a virtualized computing environment. In some embodiments, the NIC may process and forward packets directly to their destinations, bypassing a parent partition of the host computing device. In particular, in some embodiments, the NIC may store network policy information to process and forward packets directly to a virtual machine (VM). If the NIC is unable to process a packet, then the NIC may forward the packet to the parent partition. In some embodiments, the NIC may use an encapsulation protocol to transmit address information in packet headers. In some embodiments, this address information may be communicated by the MC to the parent partition via a secure channel. The NIC may also obtain, and decrypt, encrypted addresses from the VMs for routing packets, bypassing the parent partition.

    摘要翻译: 用于在操作虚拟化计算环境的主机计算设备中的网络接口控制器(NIC)中有效和安全地实现网络策略的技术。 在一些实施例中,NIC可以绕过主计算设备的父分区来处理和转发数据包直接到其目的地。 特别地,在一些实施例中,NIC可以存储网络策略信息以直接处理和转发分组到虚拟机(VM)。 如果NIC无法处理数据包,则NIC可能会将数据包转发到父分区。 在一些实施例中,NIC可以使用封装协议来传送分组报头中的地址信息。 在一些实施例中,该地址信息可以由MC通过安全信道传送到父分区。 NIC也可以绕过父分区,从虚拟机获取和解密路由数据包的加密地址。

    Routable network subnet relocation systems and methods
    4.
    发明授权
    Routable network subnet relocation systems and methods 有权
    可路由网络子网重定位系统和方法

    公开(公告)号:US07653746B2

    公开(公告)日:2010-01-26

    申请号:US10632249

    申请日:2003-08-01

    摘要: A system and method for relocating a subnet to a remote location includes a tether router coupled to an anchor router via a link. The tether router is coupled to a plurality of nodes, each node corresponding to a network address of a plurality of network addresses allocated to a user. The plurality of network addresses is allocated to the user by a lease broker. The link may include a private tunnel for traversing a mechanism that otherwise hinders communication from the tether router to the anchor router, such as a network address translation (NAT) mechanism.

    摘要翻译: 用于将子网重新定位到远程位置的系统和方法包括经由链路耦合到锚定路由器的系绳路由器。 系绳路由器耦合到多个节点,每个节点对应于分配给用户的多个网络地址的网络地址。 多个网络地址由租赁代理分配给用户。 链路可以包括用于遍历机制的私有隧道,否则阻止从系绳路由器到锚定路由器的通信,诸如网络地址转换(NAT)机制。

    Distributed Routing Domains in Multi-Tenant Datacenter Virtual Networks
    5.
    发明申请
    Distributed Routing Domains in Multi-Tenant Datacenter Virtual Networks 有权
    多租户数据中心虚拟网络中的分布式路由域

    公开(公告)号:US20130058346A1

    公开(公告)日:2013-03-07

    申请号:US13603281

    申请日:2012-09-04

    IPC分类号: H04L12/56

    CPC分类号: H04L45/586

    摘要: A distributed routing domain is disclosed wherein each user or tenant can deploy a multi-subnet routing topology in a network-virtualized datacenter. A virtualization module implements the distributed routing domain and enforces a multi-subnet routing topology in a distributed fashion without requiring a standalone physical router or VM router. The topology and the routing rules are distributed in a network virtualization module on each hypervisor host, and collectively realize the multi-subnet topology for a virtual network over any physical network topology.

    摘要翻译: 公开了分布式路由域,其中每个用户或租户可以在网络虚拟化的数据中心中部署多子网路由拓扑。 虚拟化模块实现分布式路由域并以分布式方式实施多子网路由拓扑,而不需要独立的物理路由器或VM路由器。 拓扑和路由规则分布在每个管理程序主机上的网络虚拟化模块中,并通过任何物理网络拓扑统一实现虚拟网络的多子网拓扑。

    VIRTUAL MACHINE MIGRATION TO MINIMIZE PACKET LOSS IN VIRTUALIZED NETWORK
    6.
    发明申请
    VIRTUAL MACHINE MIGRATION TO MINIMIZE PACKET LOSS IN VIRTUALIZED NETWORK 有权
    虚拟机移动以最小化虚拟化网络中的分组丢失

    公开(公告)号:US20130031544A1

    公开(公告)日:2013-01-31

    申请号:US13192254

    申请日:2011-07-27

    IPC分类号: G06F9/46

    摘要: Methods and apparatus are provided for controlling live migration of a virtual machine from a first host to a second host in a data center. A virtual machine manager may distribute to at least one host in a virtual network an updated mapping policy that maps a customer address of the virtual machine to a provider address of the migrated virtual machine. The updated mapping policy enables hosts in the virtual network to communicate with the migrated virtual machine. The updated mapping policy can be a shadow policy. The shadow policy is transmitted to hosts in the virtual network by the virtual machine manager before live migration of the virtual machine completes and is maintained by recipient hosts in an inactive state until triggered. The virtual machine manager notifies hosts in the virtual network to activate the shadow policy when live migration completes.

    摘要翻译: 提供了用于控制虚拟机从数据中心的第一主机到第二主机的实时迁移的方法和装置。 虚拟机管理器可以向虚拟网络中的至少一个主机分发更新的映射策略,其将虚拟机的客户地址映射到迁移的虚拟机的提供商地址。 更新的映射策略使虚拟网络中的主机能够与迁移的虚拟机进行通信。 更新的映射策略可以是阴影策略。 在虚拟机的实时迁移完成之前,虚拟机管理器将虚拟策略传输到虚拟网络中的主机,并由处于非活动状态的收件人主机进行维护,直到触发。 虚拟机管理器通知虚拟网络中的主机,以便在实时迁移完成时激活阴影策略。

    Virtual machine migration to minimize packet loss in virtualized network
    7.
    发明授权
    Virtual machine migration to minimize packet loss in virtualized network 有权
    虚拟机迁移,以最大限度地减少虚拟化网络中的丢包

    公开(公告)号:US09424144B2

    公开(公告)日:2016-08-23

    申请号:US13192254

    申请日:2011-07-27

    摘要: Methods and apparatus are provided for controlling live migration of a virtual machine from a first host to a second host in a data center. A virtual machine manager may distribute to at least one host in a virtual network an updated mapping policy that maps a customer address of the virtual machine to a provider address of the migrated virtual machine. The updated mapping policy enables hosts in the virtual network to communicate with the migrated virtual machine. The updated mapping policy can be a shadow policy. The shadow policy is transmitted to hosts in the virtual network by the virtual machine manager before live migration of the virtual machine completes and is maintained by recipient hosts in an inactive state until triggered. The virtual machine manager notifies hosts in the virtual network to activate the shadow policy when live migration completes.

    摘要翻译: 提供了用于控制虚拟机从数据中心的第一主机到第二主机的实时迁移的方法和装置。 虚拟机管理器可以向虚拟网络中的至少一个主机分发更新的映射策略,其将虚拟机的客户地址映射到迁移的虚拟机的提供商地址。 更新的映射策略使虚拟网络中的主机能够与迁移的虚拟机进行通信。 更新的映射策略可以是阴影策略。 在虚拟机的实时迁移完成之前,虚拟机管理器将虚拟策略传输到虚拟网络中的主机,并由处于非活动状态的收件人主机进行维护,直到触发。 虚拟机管理器通知虚拟网络中的主机,以便在实时迁移完成时激活阴影策略。

    VIRTUALIZATION GATEWAY BETWEEN VIRTUALIZED AND NON-VIRTUALIZED NETWORKS
    8.
    发明申请
    VIRTUALIZATION GATEWAY BETWEEN VIRTUALIZED AND NON-VIRTUALIZED NETWORKS 有权
    虚拟化和非虚拟化网络之间的虚拟化网关

    公开(公告)号:US20130047151A1

    公开(公告)日:2013-02-21

    申请号:US13210510

    申请日:2011-08-16

    IPC分类号: G06F9/45

    摘要: Methods and apparatus are provided for controlling communication between a virtualized network and non-virtualized entities using a virtualization gateway. A packet is sent by a virtual machine in the virtualized network to a non-virtualized entity. The packet is routed by the host of the virtual machine to a provider address of the virtualization gateway. The gateway translates the provider address of the gateway to a destination address of the non-virtualized entity and sends the packet to the non-virtualized entity. The non-virtualized entity may be a physical resource, such as a physical server or a storage device. The physical resource may be dedicated to one customer or may be shared among customers.

    摘要翻译: 提供了用于使用虚拟化网关来控制虚拟化网络和非虚拟化实体之间的通信的方法和装置。 数据包由虚拟化网络中的虚拟机发送到非虚拟化实体。 数据包由虚拟机的主机路由到虚拟化网关的提供商地址。 网关将网关的提供商地址转换为非虚拟化实体的目标地址,并将数据包发送到非虚拟化实体。 非虚拟化实体可以是物理资源,例如物理服务器或存储设备。 物理资源可以专用于一个客户,或者可以在客户之间共享。

    Distributed routing domains in multi-tenant datacenter virtual networks
    10.
    发明授权
    Distributed routing domains in multi-tenant datacenter virtual networks 有权
    多租户数据中心虚拟网络中的分布式路由域

    公开(公告)号:US09042384B2

    公开(公告)日:2015-05-26

    申请号:US13603281

    申请日:2012-09-04

    IPC分类号: H04L12/28 H04L12/713

    CPC分类号: H04L45/586

    摘要: A distributed routing domain is disclosed wherein each user or tenant can deploy a multi-subnet routing topology in a network-virtualized datacenter. A virtualization module implements the distributed routing domain and enforces a multi-subnet routing topology in a distributed fashion without requiring a standalone physical router or VM router. The topology and the routing rules are distributed in a network virtualization module on each hypervisor host, and collectively realize the multi-subnet topology for a virtual network over any physical network topology.

    摘要翻译: 公开了分布式路由域,其中每个用户或租户可以在网络虚拟化的数据中心中部署多子网路由拓扑。 虚拟化模块实现分布式路由域并以分布式方式实施多子网路由拓扑,而不需要独立的物理路由器或VM路由器。 拓扑和路由规则分布在每个管理程序主机上的网络虚拟化模块中,并通过任何物理网络拓扑统一实现虚拟网络的多子网拓扑。