Intelligent Software-Defined Networking Based Service Paths
Abstract
An example method embodiment for networking includes managing, by a network controller, network services for one or more network devices connected to the network controller. Managing network services includes receiving a packet in a traffic flow from a network device. The network device is one of the one or more network devices connected to the network controller. Managing network services further includes determining applicable services for the packet, transmitting the packet to a service provider in accordance with the applicable services for the packet, receiving, from the service provider, service results corresponding to the packet, and creating a forwarding entry providing instructions for handling the traffic flow in a service path table at the network device in accordance with the service results corresponding to the packet.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
receiving, by a network device, a packet in a traffic flow; searching, by the network device, in a service path table on the network device for a forwarding entry providing instructions for handling the traffic flow; transmitting, by the network device, the packet to a service path controller when the forwarding entry is not in the service path table; and transmitting, by the network device, the packet in accordance with the instructions for handling the traffic flow when the forwarding entry is in the service path table.
2 . The method of claim 1 , wherein transmitting the packet in accordance with the instructions for handling the traffic flow comprises one of:
forwarding, by the network device, the packet towards a target virtual machine when a previously-received packet in the traffic flow passed applicable service rules; or dropping, by the network device, the packet when the previously-received packet in the traffic flow failed the applicable service rules.
3 . The method of claim 1 , wherein transmitting the packet in accordance with the instructions for handling the traffic flow comprises:
egressing, by the network device, the packet to an identified port in accordance with a load balancing algorithm.
4 . The method of claim 1 , further comprising:
synchronizing, by the network device, the service path table on the network device with a master service path table on the service path controller.
5 . The method of claim 1 , further comprising:
not transmitting, by the network device, the packet to the service path controller when the forwarding entry is in the service path table.
6 . The method of claim 1 , further comprising:
receiving, by the network device, the forwarding entry, the forwarding entry including the instructions for handling the traffic flow; and storing, by the networking device, the forwarding entry in the service path table.
7 . The method of claim 1 , further comprising:
receiving, by the network device, a second packet in a second traffic flow; and transmitting, by the network device, the second packet in accordance with the instructions for handling the traffic flow.
8 . The method of claim 1 , further comprising:
receiving, by the network device, a second packet in a second traffic flow; transmitting, by the network device, the second packet to the service path controller when a second forwarding entry for the second packet is not in the service path table; receiving, by the network device, the second forwarding entry, the second forwarding entry including second instructions for handling the second traffic flow; and transmitting, by the network device, the second packet in accordance with the second instructions for handling the second traffic flow.
9 . The method of claim 1 , wherein the instructions for handling the traffic flow are determined according to applicable services for a traffic flow service profile for the traffic flow.
10 . The method of claim 9 , wherein the applicable services include one of firewall services, load balancing services, security services, or a combination thereof.
11 . The method of claim 9 , wherein the instructions for handling the traffic flow are further determined according to layer four services, layer five services, layer six services, layer seven services, or a combination thereof.
12 . A network device comprising:
a non-transitory memory storage comprising instructions; and one or more processors in communication with the memory, wherein the one or more processors execute the instructions to:
receive a packet in a traffic flow;
search in a service path table on the network device for a forwarding entry providing instructions for handling the traffic flow;
transmit the packet to a service path controller when the forwarding entry is not in the service path table; and
transmit the packet in accordance with the instructions for handling the traffic flow when the forwarding entry is in the service path table.
13 . The network device of claim 12 , wherein the service path table is synchronized with a master service path table on the service path controller.
14 . The network device of claim 12 , wherein the instructions to transmit the packet in accordance with the instructions for handling the traffic flow comprises instructions to perform one of:
forward the packet towards a target virtual machine when a previously-received packet in the traffic flow passed applicable service rules; or drop the packet when the previously-received packet in the traffic flow failed the applicable service rules.
15 . The network device of claim 12 , wherein the one or more processors execute the instructions to further:
receive the forwarding entry, the forwarding entry including the instructions for handling the traffic flow; and store the forwarding entry in the service path table.
16 . The network device of claim 12 , wherein the instructions for handling the traffic flow comprises instructions to egress other data packets to a port in accordance with a load balancing algorithm.
17 . The network device of claim 12 , wherein the one or more processors execute the instructions to further:
receive a second packet in a second traffic flow; transmit the second packet to the service path controller when a second forwarding entry for the second packet is not in the service path table; receive the second forwarding entry, the second forwarding entry including second instructions for handling the second traffic flow; and transmit the second packet in accordance with the second instructions for handling the second traffic flow.
18 . The network device of claim 12 , wherein the instructions for handling the traffic flow are determined according to applicable services for a traffic flow service profile for the traffic flow.
19 . The network device of claim 18 , wherein the applicable services include one of firewall services, load balancing services, security services, or a combination thereof.
20 . The network device of claim 18 , wherein the instructions for handling the traffic flow are further determined according to layer four services, layer five services, layer six services, layer seven services, or a combination thereof.Join the waitlist — get patent alerts
Track US2017048157A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.