Service insertion in basic virtual network environment
Abstract
A processing system includes: a first service machine having a first service module; and a first service switch; wherein the first service machine and the first service switch are configured for logically coupling between virtual machines and a virtual switch; wherein the first service machine comprises a first communication interface and a second communication interface, the second communication interface configured for communication with the first service switch. A processing system includes: a service module; a first communication interface for communication with a virtual switch, the virtual switch configured for communicating with virtual machines; a second communication interface for communication with the virtual switch; the first communication interface being associated with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and wherein the second communication interface is associated with original network segments at the virtual switch.
Claims
exact text as granted — not AI-modifiedWhat is claimed:
1 . A processing system, comprising:
a service module; a first communication interface for communication with a virtual switch, the virtual switch configured for communicating with a plurality of virtual machines; a second communication interface for communication with the virtual switch; wherein the service module, the first communication interface, and the second communication interface are parts of a service machine; wherein the first communication interface is associated with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and wherein the second communication interface is associated with original network segments at the virtual switch.
2 . The processing system of claim 1 , wherein the service machine comprises a mapping for mapping the original network segments and the VM-based network segments.
3 . The processing system of claim 1 , wherein at least one of the VM-based network segments is based on a VLAN, a bridge, a VMware port group.
4 . The processing system of claim 1 , wherein the service module comprises a firewall, an IPS, a WAF, a QoS, or a DPI.
5 . The processing system of claim 1 , wherein the service module is configured to provide a virtualized function.
6 . The processing system of claim 1 , further comprising the virtual switch.
7 . The processing system of claim 6 , wherein the virtual switch comprises a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch.
8 . The processing system of claim 1 , wherein the first communication interface is configured for communication with the virtual switch through a first trunk, and the second communication interface is configured for communication with the virtual switch through a second trunk.
9 . The processing system of claim 1 , wherein the service machine is configured to map packets into different network segments based on packet destinations.
10 . A data center having the processing system of claim 1 , an additional processing system, and a physical switch, wherein the processing system and the additional processing system are coupled to the physical switch, and wherein the additional processing system comprises:
an additional service module; a third communication interface for communication with an additional virtual switch, the additional virtual switch configured for communicating with an additional plurality of virtual machines; and a fourth communication interface for communication with the additional virtual switch; wherein the additional service module, the third communication interface, and the fourth communication interface are parts of an additional service machine.
11 . A method of implementing a processing system, comprising:
providing a service machine having a service module, a first communication interface, and a second communication interface, wherein the first communication interface is configured for communication with a virtual switch, and wherein the second communication interface is configured for communication with the virtual switch, the virtual switch configured for communicating with a plurality of virtual machines; and logically coupling the service machine to the virtual switch by:
associating the first communication interface with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and
associating the second communication interface with original network segments at the virtual switch.
12 . The method of claim 11 , further comprising providing the VM-based network segments at the virtual switch.
13 . The method of claim 11 , wherein the method further comprises providing a mapping at the service machine for mapping the original network segments and the VM-based network segments.
14 . The method of claim 11 , wherein at least one of the VM-based network segments is based on a VLAN, a bridge, a VMware port group.
15 . The method of claim 11 , wherein the service module comprises a firewall, an IPS, a WAF, a QoS, or a DPI.
16 . The method of claim 11 , wherein the service module is configured to provide a virtualized function.
17 . The method of claim 11 , wherein the virtual switch comprises a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch.
18 . The method of claim 11 , wherein the act of logically coupling the service machine and the virtual switch comprises communicatively coupling the service machine with the virtual switch through a first trunk, and communicatively coupling the service machine with the virtual switch through a second trunk.
19 . The method of claim 11 , further comprising configuring the service machine to map packets into different network segments based on packet destinations.Join the waitlist — get patent alerts
Track US2020007472A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.