US2023370417A1PendingUtilityA1

Identifying routes with indirect addressing in a datacenter

Assignee: VMWARE INCPriority: Dec 31, 2020Filed: Jul 27, 2023Published: Nov 16, 2023
Est. expiryDec 31, 2040(~14.4 yrs left)· nominal 20-yr term from priority
H04L 61/2557H04L 61/2517H04L 61/256H04L 45/741H04L 61/2514H04L 61/2567
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Some embodiments provide a novel method of tracking connections in a network. The method receives an identification of a first network endpoint and a second network endpoint. The method then determines that the first network endpoint cannot directly address a packet flow to the second network endpoint. The method identifies an address translation rule of a network device that translates an address of the second network endpoint into a translated address. The method then determines that the first network endpoint can directly address a packet flow to the translated address. The method then identifies a route from the first network endpoint to the second endpoint through the network device that translates the address and displays the route including an identifier of the network device.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 - 20 . (canceled) 
     
     
         21 . A method of displaying routes between endpoints in a network, the method comprising:
 at a network analyzer:
 receiving identities of first and second network endpoints as part of a request to show a path between the first and second network endpoints; 
 using a set of network address translation rules that are used by a set of network address translators of the network to identify a particular network address translation rule that translates a first address associated with the second network endpoint to a second network address that is reachable through direct addressing from a third network address associated with the first network endpoint; 
 identifying a path from the first network endpoint to the second endpoint through a particular network address translator that uses the identified network address translation rule; 
 displaying, on a display screen, the identified path comprising representation of the first and second endpoints and the particular network address translator. 
   
     
     
         22 . The method of  claim 21 , wherein through direct addressing there is no path between the first and second network endpoints, as at least one network address specified for a packet flow that is destined to the second network endpoint and that is sent by the first network endpoint has to be translated at least one time. 
     
     
         23 . The method of  claim 22  further comprising determining, at the network analyzer, that the first network endpoint cannot directly address the second network endpoint. 
     
     
         24 . The method of  claim 23 , wherein said determining comprises analyzing forwarding records to determine whether the first network endpoint can directly address the second network endpoint. 
     
     
         25 . The method of  claim 24  further comprising collecting and storing forwarding records and network address translation rules from a plurality of forwarding elements and network address translators of the network. 
     
     
         26 . The method of  claim 22  further comprising receiving with the request an indication that the first network endpoint cannot directly address the second network endpoint. 
     
     
         27 . The method of  claim 21 , wherein the first network address is a network address of an interface of the second network endpoint. 
     
     
         28 . The method of  claim 21 , wherein 
 the identified particular address translation rule is a first address translation rule,   the first network address is a network address that is associated with the second network endpoint through a group of one or more other address translation rules, and   using a set of network address translation rules comprises identifying the first address translation rule along with the group of other address translation rules.   
     
     
         29 . The method of  claim 21 , wherein the network address translator is a load balancer or a network address translation (NAT) device that translates an IP (Internet Protocol) address of packets from the first network endpoint to the second network endpoint. 
     
     
         30 . The method of  claim 21 , wherein the network address translator is a load balancer or a network address translation (NAT) device that translates a layer four port address of packets from the first network endpoint to the second network endpoint. 
     
     
         31 . The method of  claim 21 , wherein displaying the path comprises displaying an interface option that when selected displays at least one address of a packet flow before the packet flow passes through the network address translator. 
     
     
         32 . The method of  claim 31 , wherein the interface option, when selected, displays an incoming address of a packet flow entering the network address translator and a translated address of the packet flow leaving the network address translator. 
     
     
         33 . The method of  claim 32 , wherein the incoming address is an incoming source address of the packet flow and the translated address is a translated source address of the packet flow. 
     
     
         34 . The method of  claim 32 , wherein the incoming address is an incoming destination address of the packet flow and the translated address is a translated destination address of the packet flow. 
     
     
         35 . The method of  claim 32 , wherein the interface option, when selected, further displays an incoming and outgoing interface identifier for the particular address translation rule. 
     
     
         36 . The method of  claim 32 , wherein the display of the incoming address comprises a display of an IP (Internet Protocol) address and a port address. 
     
     
         37 . The method of  claim 32 , wherein the display of the translated address comprises a display of an IP (Internet Protocol) address and a port address. 
     
     
         38 . A non-transitory machine readable medium storing a program which when executed by at least one processing unit displays routes between endpoints in a network, the program comprising sets of instructions for:
 receiving identities of first and second network endpoints as part of a request to show a path between the first and second network endpoints;   using a set of network address translation rules that are used by a set of network address translators of the network to identify a particular network address translation rule that translates a first address associated with the second network endpoint to a second network address that is reachable through direct addressing from a third network address associated with the first network endpoint;   identifying a path from the first network endpoint to the second endpoint through a particular network address translator that uses the identified network address translation rule;   displaying, on a display screen, the identified path comprising representation of the first and second endpoints and the particular network address translator.   
     
     
         39 . The non-transitory machine readable medium of  claim 38 , wherein through direct addressing there is no path between the first and second network endpoints, as at least one network address specified for a packet flow that is destined to the second network endpoint and that is sent by the first network endpoint has to be translated at least one time. 
     
     
         40 . The non-transitory machine readable medium of  claim 39 , wherein the program further comprises a set of instructions for determining that the first network endpoint cannot directly address the second network endpoint by analyzing forwarding records to determine whether the first network endpoint can directly address the second network endpoint.

Join the waitlist — get patent alerts

Track US2023370417A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.