US2023179475A1PendingUtilityA1

Common connection tracker across multiple logical switches

Assignee: VMWARE INCPriority: Jan 14, 2020Filed: Jan 28, 2023Published: Jun 8, 2023
Est. expiryJan 14, 2040(~13.5 yrs left)· nominal 20-yr term from priority
H04L 41/0895H04L 12/66H04L 41/0806H04L 49/25H04L 61/50H04L 41/0663H04L 41/0894H04L 12/4641H04L 2101/622H04L 12/4645H04L 43/0805
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Some embodiments of the invention provide novel methods for providing a stateful service at a network edge device (e.g., an NSX edge) that has a plurality of north-facing interfaces (e.g., interfaces to an external network) and a plurality of corresponding south-facing interfaces (e.g., interfaces to a logical network). In some embodiments, each interface associated with a different bridge calls a service engine based on identifiers included in data messages received at the interface. Each data message flow is associated with a particular identifier that is associated with a particular service engine instance that provides the stateful service. In some embodiments, the interface that receives a data message identifies a service engine to provide the stateful service and provides the data message to the identified service engine. After processing the data message, the service engine provides the data message to the egress interface associated with the ingress interface.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method for providing a stateful service on data messages sent from a first gateway device of a first network to a second gateway device of a second network, the method comprising:
 configuring a network edge device, that is deployed between the first and second gateway devices, to implement a logical switch to connect pairs of associated interfaces of the first and second gateway devices;   configuring the logical switch to forward to a set of one or more service engines one or more data message flows that pass between the first and second gateways through the logical switch;   configuring the set of service engines to perform a set of one or more stateful services on the data message flows and to store state information related to data message flows in a common connection tracker.   
     
     
         22 . The method of  claim 21 , wherein the network edge device comprises a first set of interfaces connected to a first corresponding set of interfaces of the first set of gateway devices and a second set of interfaces connected to a second corresponding set of interfaces of the second set of gateway devices. 
     
     
         23 . The method of  claim 22 , wherein the logical switch implements a plurality of datapaths through the network edge device, each datapath defined, at least in part, by identifying a first interface in the first set of interfaces and a corresponding second interface in the second set of interfaces that are connected through the logical switch. 
     
     
         24 . The method of  claim 23 , wherein configuring the logical switch comprises configuring the logical switch (i) to receive each flow in a plurality of flows at a particular ingress interface in the first set of interfaces, (ii) to provide the flow to a service engine associated with the particular ingress interface to perform a service and store state about the service in the common connection tracker, and (iii) to forward the flow to an interface in the second set of interfaces associated with a same datapath as the ingress interface in the first set on which the data message was received. 
     
     
         25 . The method of  claim 24 , wherein the logical switch comprises a bridge connecting the paired corresponding interfaces in the first and second interfaces. 
     
     
         26 . The method of  claim 24 , wherein a pair of corresponding interfaces in the first and second interfaces are associated with first and second ports of the logical switch that bridges the first and second networks. 
     
     
         27 . The method of  claim 23 , wherein
 a particular datapath in the plurality of datapaths is defined by:
 one interface in the first set of interfaces of the network edge device that is addressable at a first media access control (MAC) address, 
 one interface in the second set of interfaces of the network edge device that is addressable at a second MAC address, and 
 the logical switch. 
   
     
     
         28 . The method of  claim 27 , wherein the first and second plurality of interfaces are link aggregation groups. 
     
     
         29 . The method of  claim 21 , wherein the set of stateful services comprises a stateful firewall. 
     
     
         30 . The method of  claim 21 , wherein the first network is a logical network and the second network is a physical network. 
     
     
         31 . The method of  claim 21 , wherein the first and second networks are logical networks. 
     
     
         32 . The method of  claim 21 , wherein the first and second networks are physical networks. 
     
     
         33 . A non-transitory machine readable medium storing a program for execution by at least one processing unit, the program comprising sets of instructions for:
 configuring a network edge device, that is deployed between the first and second gateway devices, to provide a stateful service on data messages sent from a first gateway device of a first network to a second gateway device of a second network, the network edge device configured to implement a logical switch to connect pairs of associated interfaces of the first and second gateway devices;   configuring the logical switch to forward to a set of one or more service engines one or more data message flows that pass between the first and second gateways through the logical switch;   configuring the set of service engines to perform a set of one or more stateful services on the data message flows and to store state information related to data message flows in a common connection tracker.   
     
     
         34 . The non-transitory machine readable medium of  claim 33 , wherein the network edge device comprises a first set of interfaces connected to a first corresponding set of interfaces of the first set of gateway devices and a second set of interfaces connected to a second corresponding set of interfaces of the second set of gateway devices. 
     
     
         35 . The non-transitory machine readable medium of  claim 34 , wherein the logical switch implements a plurality of datapaths through the network edge device, each datapath defined, at least in part, by identifying a first interface in the first set of interfaces and a corresponding second interface in the second set of interfaces that are connected through the logical switch. 
     
     
         36 . The non-transitory machine readable medium of  claim 35 , wherein the set of instructions for configuring the logical switch comprises a set of instructions for configuring the logical switch (i) to receive each flow in a plurality of flows at a particular ingress interface in the first set of interfaces, (ii) to provide the flow to a service engine associated with the particular ingress interface to perform a service and store state about the service in the common connection tracker, and (iii) to forward the flow to an interface in the second set of interfaces associated with a same datapath as the ingress interface in the first set on which the data message was received. 
     
     
         37 . The non-transitory machine readable medium of  claim 36 , wherein the logical switch comprises a bridge connecting the paired corresponding interfaces in the first and second interfaces. 
     
     
         38 . The non-transitory machine readable medium of  claim 36 , wherein a pair of corresponding interfaces in the first and second interfaces are associated with first and second ports of the logical switch that bridges the first and second networks. 
     
     
         39 . The non-transitory machine readable medium of  claim 35 , wherein
 a particular datapath in the plurality of datapaths is defined by:
 one interface in the first set of interfaces of the network edge device that is addressable at a first media access control (MAC) address, 
 one interface in the second set of interfaces of the network edge device that is addressable at a second MAC address, and 
 the logical switch. 
   
     
     
         40 . The non-transitory machine readable medium of  claim 39 , wherein the first and second plurality of interfaces are link aggregation groups.

Join the waitlist — get patent alerts

Track US2023179475A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.