US2020007472A1PendingUtilityA1

Service insertion in basic virtual network environment

Assignee: HILLSTONE NETWORKS CORPPriority: Apr 20, 2015Filed: Sep 9, 2019Published: Jan 2, 2020
Est. expiryApr 20, 2035(~8.7 yrs left)· nominal 20-yr term from priority
H04L 49/70H04L 12/4641H04L 49/354
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A processing system includes: a first service machine having a first service module; and a first service switch; wherein the first service machine and the first service switch are configured for logically coupling between virtual machines and a virtual switch; wherein the first service machine comprises a first communication interface and a second communication interface, the second communication interface configured for communication with the first service switch. A processing system includes: a service module; a first communication interface for communication with a virtual switch, the virtual switch configured for communicating with virtual machines; a second communication interface for communication with the virtual switch; the first communication interface being associated with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and wherein the second communication interface is associated with original network segments at the virtual switch.

Claims

exact text as granted — not AI-modified
What is claimed: 
     
         1 . A processing system, comprising:
 a service module;   a first communication interface for communication with a virtual switch, the virtual switch configured for communicating with a plurality of virtual machines;   a second communication interface for communication with the virtual switch;   wherein the service module, the first communication interface, and the second communication interface are parts of a service machine;   wherein the first communication interface is associated with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and   wherein the second communication interface is associated with original network segments at the virtual switch.   
     
     
         2 . The processing system of  claim 1 , wherein the service machine comprises a mapping for mapping the original network segments and the VM-based network segments. 
     
     
         3 . The processing system of  claim 1 , wherein at least one of the VM-based network segments is based on a VLAN, a bridge, a VMware port group. 
     
     
         4 . The processing system of  claim 1 , wherein the service module comprises a firewall, an IPS, a WAF, a QoS, or a DPI. 
     
     
         5 . The processing system of  claim 1 , wherein the service module is configured to provide a virtualized function. 
     
     
         6 . The processing system of  claim 1 , further comprising the virtual switch. 
     
     
         7 . The processing system of  claim 6 , wherein the virtual switch comprises a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch. 
     
     
         8 . The processing system of  claim 1 , wherein the first communication interface is configured for communication with the virtual switch through a first trunk, and the second communication interface is configured for communication with the virtual switch through a second trunk. 
     
     
         9 . The processing system of  claim 1 , wherein the service machine is configured to map packets into different network segments based on packet destinations. 
     
     
         10 . A data center having the processing system of  claim 1 , an additional processing system, and a physical switch, wherein the processing system and the additional processing system are coupled to the physical switch, and wherein the additional processing system comprises:
 an additional service module;   a third communication interface for communication with an additional virtual switch, the additional virtual switch configured for communicating with an additional plurality of virtual machines; and   a fourth communication interface for communication with the additional virtual switch;   wherein the additional service module, the third communication interface, and the fourth communication interface are parts of an additional service machine.   
     
     
         11 . A method of implementing a processing system, comprising:
 providing a service machine having a service module, a first communication interface, and a second communication interface, wherein the first communication interface is configured for communication with a virtual switch, and wherein the second communication interface is configured for communication with the virtual switch, the virtual switch configured for communicating with a plurality of virtual machines; and   logically coupling the service machine to the virtual switch by:
 associating the first communication interface with a plurality of VM-based network segments at the virtual switch, the plurality of VM-based network segments corresponding with the plurality of virtual machines, respectively; and 
 associating the second communication interface with original network segments at the virtual switch. 
   
     
     
         12 . The method of  claim 11 , further comprising providing the VM-based network segments at the virtual switch. 
     
     
         13 . The method of  claim 11 , wherein the method further comprises providing a mapping at the service machine for mapping the original network segments and the VM-based network segments. 
     
     
         14 . The method of  claim 11 , wherein at least one of the VM-based network segments is based on a VLAN, a bridge, a VMware port group. 
     
     
         15 . The method of  claim 11 , wherein the service module comprises a firewall, an IPS, a WAF, a QoS, or a DPI. 
     
     
         16 . The method of  claim 11 , wherein the service module is configured to provide a virtualized function. 
     
     
         17 . The method of  claim 11 , wherein the virtual switch comprises a Linux bridge, an open vSwitch, a VMware vSphere standard switch, or a VMware vSphere distributed switch. 
     
     
         18 . The method of  claim 11 , wherein the act of logically coupling the service machine and the virtual switch comprises communicatively coupling the service machine with the virtual switch through a first trunk, and communicatively coupling the service machine with the virtual switch through a second trunk. 
     
     
         19 . The method of  claim 11 , further comprising configuring the service machine to map packets into different network segments based on packet destinations.

Join the waitlist — get patent alerts

Track US2020007472A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.