Secure forwarding of tenant workloads in virtual networks
Abstract
In general, techniques are described for enhancing operations of virtual networks. In some examples, a network system includes a plurality of servers interconnected by a switch fabric comprising a plurality of switches interconnected to form a physical network. Each of the servers comprises an operating environment executing one or more virtual machines in communication via one or more virtual networks. The servers comprise a set of virtual routers configured to extend the virtual networks to the operating environments of the virtual machines. A virtual router of the set of virtual routers is configured to prepare tunnel packets by forwarding packets received from virtual machines to an IPSec kernel executing in a host operating network stack, receiving the ESP packets back from the IPSec kernel and forwarding the ESP packets across the virtual networks.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method, comprising:
receiving a packet at a virtual router, the virtual router executing in kernel space of a host computing device in a virtual network stack, the virtual network stack including an interface to a virtual network fabric, the packet including a source address and a destination address, the destination address associated with a virtual machine; establishing a first Internet Protocol (IP) endpoint at the Network layer of the virtual network stack; establishing a second IP endpoint at the Network layer of a host operating system (OS) networking stack of a host OS operating on the host computing device, the host OS networking stack connected to a physical network fabric operating as an underlay fabric for the virtual network fabric; forwarding the packet from the first IP endpoint of the virtual router through the second IP endpoint of the host networking stack to a packet modification module executing at the Network layer of the host OS networking stack; receiving the forwarded packet at the packet modification module and modifying the forwarded packet at the packet modification module to form a modified packet that preserves the source and destination addresses; returning the modified packet via the first and second IP endpoints to the virtual router; and transmitting the modified packet from the virtual router to the virtual machine associated with the destination address.
2 . The method of claim 1 , wherein forwarding the packet from the first IP endpoint includes trapping the packet at the network layer of the virtual router network stack.
3 . The method of claim 1 , wherein the packet is an encapsulated packet and wherein forwarding the packet from the first IP endpoint includes trapping the encapsulated packet at the network layer of the virtual router network stack.
4 . The method of claim 1 , wherein receiving the forwarded packet includes trapping the packet received from the second IP endpoint in a network layer kernel of the host OS networking stack.
5 . The method of claim 1 , wherein the encapsulated packets are IP/MPLS or VXLAN packets.
6 . A non-transitory computer-readable medium comprising instructions for causing one or more programmable processors of a computing device to:
receive a packet at a virtual router, the virtual router executing in kernel space of a host computing device in a virtual network stack, the virtual network stack including an interface to a virtual network fabric, the packet including a source address and a destination address, the destination address associated with a virtual machine; establish a first Internet Protocol (IP) endpoint at the Network layer of the virtual network stack; establish a second IP endpoint at the Network layer of a host operating system (OS) networking stack of a host OS operating on the host computing device, the host OS networking stack connected to a physical network fabric operating as an underlay fabric for the virtual network fabric; forward the packet from the first IP endpoint of the virtual router through the second IP endpoint of the host networking stack to a packet modification module executing at the Network layer of the host OS networking stack; receive the forwarded packet at the packet modification module and modifying the forwarded packet at the packet modification module to form a modified packet that preserves the source and destination addresses; return the modified packet via the first and second IP endpoints to the virtual router; and transmit the modified packet from the virtual router to the virtual machine associated with the destination address.
7 . A method comprising:
receiving a packet at a virtual router, the virtual router executing in kernel space of a host computing device in a virtual network stack, the virtual network stack including an interface to a virtual network fabric, the packet including a source address and a destination address, wherein receiving the packet includes trapping the packet at a Network layer of the virtual router; establishing a first Internet Protocol (IP) endpoint at the Network layer of the virtual network stack; establishing a second IP endpoint at the Network layer of a host operating system (OS) networking stack associated with a host OS operating on the host computing device; forwarding the packet from the virtual router to the second IP endpoint of the host OS networking stack via the first IP endpoint, wherein the host OS networking stack includes a module that executes at the Network layer of the host OS networking stack in kernel space on the first computing device, wherein the host OS networking stack is connected to a physical network fabric operating as an underlay fabric for the virtual network fabric; receiving the forwarded packet at the module and modifying the forwarded packet at the module to form a modified packet that preserves the source and destination addresses; returning the modified packet to the Network layer of the virtual network stack of the virtual router, wherein returning includes transferring the modified packet via the second IP endpoint to the first IP endpoint; and transmitting the modified packet from the virtual router to the virtual machine associated with the destination address via the physical network fabric.
8 . The method of claim 7 , wherein the destination address is associated with a virtual machine executing on a different computing device.
9 . The method of claim 7 , wherein the destination address is associated with a virtual machine executing on the host computing device.Join the waitlist — get patent alerts
Track US2022124077A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.