Managed forwarding element detecting invalid packet addresses
Abstract
Some embodiments provide a method for a managed forwarding element (MFE) executing on a data compute node (DCN) that operates on a host computer in a public datacenter. The MFE implements a logical network that connects multiple DCNs within the public datacenter. The method receives a packet, directed to the DCN, that (i) has a first logical network source address and (ii) is encapsulated with a second source address associated with an underlying public datacenter network. The method determines whether the first logical network source address is a valid source address for the packet based on a mapping table that maps logical network addresses to underlying public datacenter network addresses. When the first source address is not a valid source address for the packet, the method drops the packet.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method for performing spoof guarding, the method comprising:
at a managed forwarding element (MFE) executing on a data compute node (DCN) that operates on a host computer in a public datacenter, the MFE implementing a logical network that connects a plurality of DCNs within the public datacenter:
receiving a data message directed to the DCN, wherein the data message (i) has a logical network first source address and (ii) is encapsulated with a second source address associated with an underlying public datacenter network;
determining whether the logical network first source address is an expected logical network address corresponding to the second source address; and
when the logical network first source address is different from the expected logical network source address corresponding to the second source address, dropping the data message based on the data message using an invalid logical network address for a source of the data message.
22 . The method of claim 21 , wherein:
the DCN is a first DCN and the source of the data message is a second DCN; the logical network first source address is a logical network address for applications executing on the second DCN; and the physical network second source address is an address assigned to the second DCN by the public datacenter.
23 . The method of claim 21 , wherein:
a workload application executes on the DCN alongside the MFE; the data message has a logical network first destination address associated with the workload application; and the data message is further encapsulated with a second destination address associated with the DCN on the underlying public datacenter network.
24 . The method of claim 23 , wherein when the logical network first source address is a valid source address for the data message, the MFE forwards the data message to the workload application.
25 . The method of claim 21 , wherein:
the DCN is a first DCN; the second source address is an address assigned to a second DCN by the public datacenter; the expected logical network address is a logical network address for a third DCN having a third address assigned by the public datacenter; and the second DCN has been compromised by an attacker and is spoofing the third DCN to direct traffic to the first DCN by using the logical network address for the third DCN.
26 . The method of claim 21 , wherein the host computer is a first host computer that receives a set of mappings that map addresses associated with the underlying public datacenter network to logical network addresses from a network controller that (i) operates on a second host computer in the public datacenter and (ii) configures the MFE to implement the logical network.
27 . The method of claim 26 , wherein:
the network controller distributes the set of mappings to a controller agent executing on the first DCN; and the controller agent directly configures the MFE to implement the logical network and to use the set of mappings for performing spoof guarding.
28 . The method of claim 26 , wherein the network controller operating on the second host computer is a first network controller that manages a plurality of MFEs operating in the public datacenter to implement the logical network, wherein the first network controller receives logical network configuration data from a second network controller operating in a second datacenter.
29 . The method of claim 28 , wherein:
the second network controller has access to and provides configuration data MFEs operating in virtualization software of a plurality of host computers of the second datacenter, and the second network controller does not have access to forwarding elements operating in virtualization software of the first and second host computers of the first datacenter.
30 . The method of claim 29 , wherein the forwarding elements operating in virtualization software of the first and second host computers verify the second source address but do not verify the logical network first source address.
31 . A non-transitory machine-readable medium storing a managed forwarding element (MFE) which for execution within a data compute node (DCN) operating on a host computer in a public datacenter, by at least one processing unit of the host computer, the MFE implementing a logical network that connects a plurality of DCNs within the public datacenter and performing spoof guarding for the logical network, the MFE comprising sets of instructions for:
receiving a data message directed to the DCN, wherein the data message (i) has a logical network first source address and (ii) is encapsulated with a second source address associated with an underlying public datacenter network; determining whether the logical network first source address is an expected logical network address corresponding to the second source address; and when the logical network first source address is different from the expected logical network source address corresponding to the second source address, dropping the data message based on the data message using an invalid logical network address for a source of the data message.
32 . The non-transitory machine-readable medium of claim 31 , wherein:
the DCN is a first DCN and the source of the data message is a second DCN; the logical network first source address is a logical network address for applications executing on the second DCN; and the physical network second source address is an address assigned to the second DCN by the public datacenter.
33 . The non-transitory machine-readable medium of claim 31 , wherein:
a workload application executes on the DCN alongside the MFE; the data message has a logical network first destination address associated with the workload application; and the data message is further encapsulated with a second destination address associated with the DCN on the underlying public datacenter network.
34 . The non-transitory machine-readable medium of claim 33 , wherein the MFE further comprises a set of instructions for forwarding the data message to the workload application when the logical network first source address is a valid source address for the data message.
35 . The non-transitory machine-readable medium of claim 31 , wherein:
the DCN is a first DCN; the second source address is an address assigned to a second DCN by the public datacenter; the expected logical network address is a logical network address for a third DCN having a third address assigned by the public datacenter; and the second DCN has been compromised by an attacker and is spoofing the third DCN to direct traffic to the first DCN by using the logical network address for the third DCN.
36 . The non-transitory machine-readable medium of claim 31 , wherein the host computer is a first host computer that receives a set of mappings that map addresses associated with the underlying public datacenter network to logical network addresses from a network controller that (i) operates on a second host computer in the public datacenter and (ii) configures the MFE to implement the logical network.
37 . The non-transitory machine-readable medium of claim 36 , wherein:
the network controller distributes the set of mappings to a controller agent executing on the first DCN; and the controller agent directly configures the MFE to implement the logical network and to use the set of mappings for performing spoof guarding.
38 . The non-transitory machine-readable medium of claim 36 , wherein the network controller operating on the second host computer is a first network controller that manages a plurality of MFEs operating in the public datacenter to implement the logical network, wherein the first network controller receives logical network configuration data from a second network controller operating in a second datacenter.
39 . The non-transitory machine-readable medium of claim 38 , wherein:
the second network controller has access to and provides configuration data for MFEs operating in virtualization software of a plurality of host computers of the second datacenter, and the second network controller does not have access to forwarding elements operating in virtualization software of the first and second host computers of the first datacenter.
40 . The non-transitory machine-readable medium of claim 39 , wherein the forwarding elements operating in virtualization software of the first and second host computers verify the second source address but do not verify the logical network first source address.Join the waitlist — get patent alerts
Track US2022255896A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.