FLOW GENERATION FROM SECOND LEVEL CONTROLLER TO FIRST LEVEL CONTROLLER TO MANAGED SWITCHING ELEMENT

    公开(公告)号:US20230421410A1

    公开(公告)日:2023-12-28

    申请号:US18244243

    申请日:2023-09-09

    申请人: Nicira, Inc.

    摘要: A network system that includes a first set of network hosts in a first domain and a second set of network hosts in a second domain. Within each of the domains, the system includes several edge switching elements (SEs) that each couple to the network hosts and forward network data to and from the set of network hosts. Within the first domain, the system includes (i) an interior SE that couples to a particular edge SE in order to receive network data for forwarding from the edge SE when the edge SE does not recognize a destination location of the network data and (ii) an interconnection SE that couples to the interior SE, the edge SE, and the second domain through an external network. When the edge SE receives network data with a destination address in the second domain, it forwards the network data directly to the interconnection SE.

    FLOW GENERATION FROM SECOND LEVEL CONTROLLER TO FIRST LEVEL CONTROLLER TO MANAGED SWITCHING ELEMENT

    公开(公告)号:US20210184898A1

    公开(公告)日:2021-06-17

    申请号:US17175548

    申请日:2021-02-12

    申请人: Nicira, Inc.

    摘要: A network system that includes a first set of network hosts in a first domain and a second set of network hosts in a second domain. Within each of the domains, the system includes several edge switching elements (SEs) that each couple to the network hosts and forward network data to and from the set of network hosts. Within the first domain, the system includes (i) an interior SE that couples to a particular edge SE in order to receive network data for forwarding from the edge SE when the edge SE does not recognize a destination location of the network data and (ii) an interconnection SE that couples to the interior SE, the edge SE, and the second domain through an external network. When the edge SE receives network data with a destination address in the second domain, it forwards the network data directly to the interconnection SE.

    Network operating system for managing and securing networks

    公开(公告)号:US10749736B2

    公开(公告)日:2020-08-18

    申请号:US15838317

    申请日:2017-12-11

    申请人: Nicira, Inc.

    IPC分类号: H04L12/24 H04L12/26

    摘要: Systems and methods for managing a network are described. A view of current state of the network is maintained where the current state of the network characterizes network topology and network constituents, including network entities and network elements residing in or on the network. Events are announced that correspond to changes in the state of the network and one or more network elements can be configured accordingly. Methods for managing network traffic are described that ensure forwarding and other actions taken by network elements implement globally declared network policy and refer to high-level names, independently of network topology and the location of network constituents. Methods for discovering network constituents are described, whereby are automatically configured. Routing may be performed using ACL and packets can be intercepted to permit host to continue in sleep mode. The methods are applicable to virtual environments.

    NETWORK OPERATING SYSTEM FOR MANAGING AND SECURING NETWORKS
    5.
    发明申请
    NETWORK OPERATING SYSTEM FOR MANAGING AND SECURING NETWORKS 审中-公开
    用于管理和保护网络的网络操作系统

    公开(公告)号:US20160013969A1

    公开(公告)日:2016-01-14

    申请号:US14746816

    申请日:2015-06-22

    申请人: Nicira, Inc.

    IPC分类号: H04L12/24

    摘要: Systems and methods for managing a network are described. A view of current state of the network is maintained where the current state of the network characterizes network topology and network constituents, including network entities and network elements residing in or on the network. Events are announced that correspond to changes in the state of the network and one or more network elements can be configured accordingly. Methods for managing network traffic are described that ensure forwarding and other actions taken by network elements implement globally declared network policy and refer to high-level names, independently of network topology and the location of network constituents. Methods for discovering network constituents are described, whereby are automatically configured. Routing may be performed using ACL and packets can be intercepted to permit host to continue in sleep mode. The methods are applicable to virtual environments.

    摘要翻译: 描述用于管理网络的系统和方法。 维持网络当前状态的视图,其中网络的当前状态表征网络拓扑和网络成分,包括驻留在网络中或网络上的网络实体和网络元素。 公布对应于网络状态的变化的事件,并且可以相应地配置一个或多个网络元件。 描述了用于管理网络流量的方法,其确保网元采取的转发和其他动作实现全球声明的网络策略,并且独立于网络拓扑和网络组成部分的位置来参考高级别名称。 描述了用于发现网络组件的方法,由此被自动配置。 可以使用ACL执行路由,并且可以拦截数据包以允许主机在睡眠模式下继续。 这些方法适用于虚拟环境。

    Method and Apparatus for Implementing and Managing Virtual Switches
    6.
    发明申请
    Method and Apparatus for Implementing and Managing Virtual Switches 审中-公开
    实现和管理虚拟交换机的方法和设备

    公开(公告)号:US20150180801A1

    公开(公告)日:2015-06-25

    申请号:US14594043

    申请日:2015-01-09

    申请人: Nicira, Inc.

    摘要: In general, the present invention relates to a virtual platform in which one or more distributed virtual switches can be created for use in virtual networking. According to some aspects, the distributed virtual switch according to the invention provides the ability for virtual and physical machines to more readily, securely, and efficiently communicate with each other even if they are not located on the same physical host and/or in the same subnet or VLAN. According other aspects, the distributed virtual switches of the invention can support integration with traditional IP networks and support sophisticated IP technologies including NAT functionality, stateful firewalling, and notifying the IP network of workload migration. According to further aspects, the virtual platform of the invention creates one or more distributed virtual switches which may be allocated to a tenant, application, or other entity requiring isolation and/or independent configuration state. According to still further aspects, the virtual platform of the invention manages and/or uses VLAN or tunnels (e.g, GRE) to create a distributed virtual switch for a network while working with existing switches and routers in the network. The present invention finds utility in both enterprise networks, datacenters and other facilities.

    摘要翻译: 通常,本发明涉及一种虚拟平台,其中可以创建一个或多个分布式虚拟交换机用于虚拟网络中。 根据一些方面,根据本发明的分布式虚拟交换机提供虚拟和物理机器更容易,安全并且有效地彼此通信的能力,即使它们不位于相同的物理主机上和/或相同 子网或VLAN。 根据其他方面,本发明的分布式虚拟交换机可以支持与传统IP网络的集成,并支持复杂的IP技术,包括NAT功能,状态防火墙,以及通知IP网络的工作负载迁移。 根据另外的方面,本发明的虚拟平台创建一个或多个分配的虚拟交换机,其可以被分配给需要隔离和/或独立配置状态的租户,应用或其他实体。 根据另外的方面,本发明的虚拟平台管理和/或使用VLAN或隧道(例如,GRE)来在网络中与现有交换机和路由器协同工作时为网络创建分布式虚拟交换机。 本发明可用于企业网络,数据中心和其他设施。

    METHOD AND APPARATUS FOR IMPLEMENTING AND MANAGING VIRTUAL SWITCHES

    公开(公告)号:US20220400088A1

    公开(公告)日:2022-12-15

    申请号:US17892110

    申请日:2022-08-21

    申请人: Nicira, Inc.

    摘要: In general, the present invention relates to a virtual platform in which one or more distributed virtual switches can be created for use in virtual networking. According to some aspects, the distributed virtual switch according to the invention provides the ability for virtual and physical machines to more readily, securely, and efficiently communicate with each other even if they are not located on the same physical host and/or in the same subnet or VLAN. According other aspects, the distributed virtual switches of the invention can support integration with traditional IP networks and support sophisticated IP technologies including NAT functionality, stateful firewalling, and notifying the IP network of workload migration. According to further aspects, the virtual platform of the invention creates one or more distributed virtual switches which may be allocated to a tenant, application, or other entity requiring isolation and/or independent configuration state. According to still further aspects, the virtual platform of the invention manages and/or uses VLAN or tunnels (e.g, GRE) to create a distributed virtual switch for a network while working with existing switches and routers in the network. The present invention finds utility in both enterprise networks, datacenters and other facilities.

    Method and apparatus for implementing and managing virtual switches

    公开(公告)号:US11425055B2

    公开(公告)日:2022-08-23

    申请号:US17178239

    申请日:2021-02-17

    申请人: Nicira, Inc.

    摘要: In general, the present invention relates to a virtual platform in which one or more distributed virtual switches can be created for use in virtual networking. According to some aspects, the distributed virtual switch according to the invention provides the ability for virtual and physical machines to more readily, securely, and efficiently communicate with each other even if they are not located on the same physical host and/or in the same subnet or VLAN. According other aspects, the distributed virtual switches of the invention can support integration with traditional IP networks and support sophisticated IP technologies including NAT functionality, stateful firewalling, and notifying the IP network of workload migration. According to further aspects, the virtual platform of the invention creates one or more distributed virtual switches which may be allocated to a tenant, application, or other entity requiring isolation and/or independent configuration state. According to still further aspects, the virtual platform of the invention manages and/or uses VLAN or tunnels (e.g, GRE) to create a distributed virtual switch for a network while working with existing switches and routers in the network. The present invention finds utility in both enterprise networks, datacenters and other facilities.

    Multi-domain interconnect
    9.
    发明授权

    公开(公告)号:US10193708B2

    公开(公告)日:2019-01-29

    申请号:US13757686

    申请日:2013-02-01

    申请人: Nicira, Inc.

    摘要: A network system that includes a first set of network hosts in a first domain and a second set of network hosts in a second domain. Within each of the domains, the system includes several edge switching elements (SEs) that each couple to the network hosts and forward network data to and from the set of network hosts. Within the first domain, the system includes (i) an interior SE that couples to a particular edge SE in order to receive network data for forwarding from the edge SE when the edge SE does not recognize a destination location of the network data and (ii) an interconnection SE that couples to the interior SE, the edge SE, and the second domain through an external network. When the edge SE receives network data with a destination address in the second domain, it forwards the network data directly to the interconnection SE.