US2022124077A1PendingUtilityA1

Secure forwarding of tenant workloads in virtual networks

Assignee: JUNIPER NETWORKS INCPriority: Aug 15, 2018Filed: Dec 30, 2021Published: Apr 21, 2022
Est. expiryAug 15, 2038(~12 yrs left)· nominal 20-yr term from priority
H04L 45/745H04L 63/0485H04L 45/586H04L 63/0272H04L 12/4633H04L 63/029H04L 45/24H04L 12/4641H04L 2212/00H04L 63/164H04L 45/50H04L 47/125H04L 49/15H04L 45/16H04L 45/66H04L 45/64
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In general, techniques are described for enhancing operations of virtual networks. In some examples, a network system includes a plurality of servers interconnected by a switch fabric comprising a plurality of switches interconnected to form a physical network. Each of the servers comprises an operating environment executing one or more virtual machines in communication via one or more virtual networks. The servers comprise a set of virtual routers configured to extend the virtual networks to the operating environments of the virtual machines. A virtual router of the set of virtual routers is configured to prepare tunnel packets by forwarding packets received from virtual machines to an IPSec kernel executing in a host operating network stack, receiving the ESP packets back from the IPSec kernel and forwarding the ESP packets across the virtual networks.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method, comprising:
 receiving a packet at a virtual router, the virtual router executing in kernel space of a host computing device in a virtual network stack, the virtual network stack including an interface to a virtual network fabric, the packet including a source address and a destination address, the destination address associated with a virtual machine;   establishing a first Internet Protocol (IP) endpoint at the Network layer of the virtual network stack;   establishing a second IP endpoint at the Network layer of a host operating system (OS) networking stack of a host OS operating on the host computing device, the host OS networking stack connected to a physical network fabric operating as an underlay fabric for the virtual network fabric;   forwarding the packet from the first IP endpoint of the virtual router through the second IP endpoint of the host networking stack to a packet modification module executing at the Network layer of the host OS networking stack;   receiving the forwarded packet at the packet modification module and modifying the forwarded packet at the packet modification module to form a modified packet that preserves the source and destination addresses;   returning the modified packet via the first and second IP endpoints to the virtual router; and   transmitting the modified packet from the virtual router to the virtual machine associated with the destination address.   
     
     
         2 . The method of  claim 1 , wherein forwarding the packet from the first IP endpoint includes trapping the packet at the network layer of the virtual router network stack. 
     
     
         3 . The method of  claim 1 , wherein the packet is an encapsulated packet and wherein forwarding the packet from the first IP endpoint includes trapping the encapsulated packet at the network layer of the virtual router network stack. 
     
     
         4 . The method of  claim 1 , wherein receiving the forwarded packet includes trapping the packet received from the second IP endpoint in a network layer kernel of the host OS networking stack. 
     
     
         5 . The method of  claim 1 , wherein the encapsulated packets are IP/MPLS or VXLAN packets. 
     
     
         6 . A non-transitory computer-readable medium comprising instructions for causing one or more programmable processors of a computing device to:
 receive a packet at a virtual router, the virtual router executing in kernel space of a host computing device in a virtual network stack, the virtual network stack including an interface to a virtual network fabric, the packet including a source address and a destination address, the destination address associated with a virtual machine;   establish a first Internet Protocol (IP) endpoint at the Network layer of the virtual network stack;   establish a second IP endpoint at the Network layer of a host operating system (OS) networking stack of a host OS operating on the host computing device, the host OS networking stack connected to a physical network fabric operating as an underlay fabric for the virtual network fabric;   forward the packet from the first IP endpoint of the virtual router through the second IP endpoint of the host networking stack to a packet modification module executing at the Network layer of the host OS networking stack;   receive the forwarded packet at the packet modification module and modifying the forwarded packet at the packet modification module to form a modified packet that preserves the source and destination addresses;   return the modified packet via the first and second IP endpoints to the virtual router; and   transmit the modified packet from the virtual router to the virtual machine associated with the destination address.   
     
     
         7 . A method comprising:
 receiving a packet at a virtual router, the virtual router executing in kernel space of a host computing device in a virtual network stack, the virtual network stack including an interface to a virtual network fabric, the packet including a source address and a destination address, wherein receiving the packet includes trapping the packet at a Network layer of the virtual router;   establishing a first Internet Protocol (IP) endpoint at the Network layer of the virtual network stack;   establishing a second IP endpoint at the Network layer of a host operating system (OS) networking stack associated with a host OS operating on the host computing device;   forwarding the packet from the virtual router to the second IP endpoint of the host OS networking stack via the first IP endpoint, wherein the host OS networking stack includes a module that executes at the Network layer of the host OS networking stack in kernel space on the first computing device, wherein the host OS networking stack is connected to a physical network fabric operating as an underlay fabric for the virtual network fabric;   receiving the forwarded packet at the module and modifying the forwarded packet at the module to form a modified packet that preserves the source and destination addresses;   returning the modified packet to the Network layer of the virtual network stack of the virtual router, wherein returning includes transferring the modified packet via the second IP endpoint to the first IP endpoint; and   transmitting the modified packet from the virtual router to the virtual machine associated with the destination address via the physical network fabric.   
     
     
         8 . The method of  claim 7 , wherein the destination address is associated with a virtual machine executing on a different computing device. 
     
     
         9 . The method of  claim 7 , wherein the destination address is associated with a virtual machine executing on the host computing device.

Join the waitlist — get patent alerts

Track US2022124077A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.