Configuring traffic optimization using distributed edge services
Abstract
Some embodiments provide a novel method for configuring managed forwarding elements (MFEs) to handle data messages for multiple logical networks that are implemented in a data center at the MFEs and to provide gateway service processing (e.g., firewall, DNS, etc.). A controller, in some embodiments, identifies logical networks implemented in the datacenter and MFEs available to provide gateway service processing and assigns gateway service processing for each logical network to a particular MFE. The MFEs, in some embodiments, receive data messages from endpoints in the logical networks that are destined for an external network. In some embodiments, the MFEs identify that the data messages require gateway service processing before being sent to the external network. The MFEs, in some embodiments, identify a particular MFE that is assigned to provide the gateway service processing for logical networks associated with the data messages.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method of performing gateway services for a first logical network spanning a first plurality of host computers in a datacenter, the method comprising:
at the first host computer:
receiving, from a machine that is part of the first logical network and executes on the first host computer, a data message destined for an external second network;
identifying that the data message requires gateway service processing before being sent to the external network;
identifying a second host computer, which executes at least one other machine that is part of the first logical network, as a host computer that will provide the gateway service processing for the first logical network,
forwarding that data message to the second host computer to perform the gateway service processing before forwarding the data message to the external network through a gateway of the first logical network.
22 . The method of claim 21 , wherein the first host computer executes in a first datacenter and the external network is a network of a second datacenter.
23 . The method of claim 22 , wherein the first and second datacenters are connected through a direct connection that does not require network address translation.
24 . The method of claim 21 , wherein a return data message from the external network to the first logical network is returned to the second host computer that provides the gateway service processing for the first logical network.
25 . The method of claim 21 , wherein the plurality of host computers implements a plurality of different logical networks, with at least two different host computers performing gateway services for at least two different logical networks and executing machines associated with the two different logical networks.
26 . The method of claim 25 , wherein at least one host computer is assigned to provide gateway service processing for multiple logical networks.
27 . The method of claim 25 , wherein the gateway service processing for the logical networks is assigned to the host computers based on a load balancing operation.
28 . The method of claim 25 , wherein a controller computer determines the assignment of the gateway service processing for the different logical networks.
29 . The method of claim 25 , wherein first and second service edge nodes executing on first and second host computers respectively provide gateway service processing for first and second logical networks respectively.
30 . The method of claim 21 , wherein the gateway service processing comprises stateful gateway service processing.
31 . A non-transitory machine readable medium storing a program, which when executed by at least one processing unit, performs gateway services for a first logical network spanning a first plurality of host computers in a datacenter, the program comprising sets of instructions for:
at the first host computer:
receiving, from a machine that is part of the first logical network and executes on the first host computer, a data message destined for an external second network;
identifying that the data message requires gateway service processing before being sent to the external network;
identifying a second host computer, which executes at least one other machine that is part of the first logical network, as a host computer that will provide the gateway service processing for the first logical network,
forwarding that data message to the second host computer to perform the gateway service processing before forwarding the data message to the external network through a gateway of the first logical network.
32 . The non-transitory machine readable medium of claim 31 , wherein the first host computer executes in a first datacenter and the external network is a network of a second datacenter.
33 . The non-transitory machine readable medium of claim 32 , wherein the first and second datacenters are connected through a direct connection that does not require network address translation.
34 . The non-transitory machine readable medium of claim 31 , wherein a return data message from the external network to the first logical network is returned to the second host computer that provides the gateway service processing for the first logical network.
35 . The non-transitory machine readable medium of claim 31 , wherein the plurality of host computers implements a plurality of different logical networks, with at least two different host computers performing gateway services for at least two different logical networks and executing machines associated with the two different logical networks.
36 . The non-transitory machine readable medium of claim 35 , wherein at least one host computer is assigned to provide gateway service processing for multiple logical networks.
37 . The non-transitory machine readable medium of claim 35 , wherein the gateway service processing for the logical networks is assigned to the host computers based on a load balancing operation.
38 . The non-transitory machine readable medium of claim 35 , wherein a controller computer determines the assignment of the gateway service processing for the different logical networks.
39 . The non-transitory machine readable medium of claim 35 , wherein first and second service edge nodes executing on first and second host computers respectively provide gateway service processing for first and second logical networks respectively.
40 . The non-transitory machine readable medium of claim 31 , wherein the set of instructions for identifying the second host computer comprises a set of instructions for using a policy-based routing entry to identify the second host computer.Join the waitlist — get patent alerts
Track US2022045881A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.