Private ethernet overlay networks over a shared ethernet in a virtual environment
Abstract
A system for private networking within a virtual infrastructure is presented. The system includes a virtual machine (VM) in a first host, the VM being associated with a first virtual network interface card (VNIC), a second VM in a second host, the second VM being associated with a second VNIC, the first and second VNICs being members of a fenced group of computers that have exclusive direct access to a private virtual network, wherein VNICs outside the fenced group do not have direct access to packets on the private virtual network, a filter in the first host that encapsulates a packet sent on the private virtual network from the first VNIC, the encapsulation adding to the packet a new header and a fence identifier for the fenced group, and a second filter in the second host that de-encapsulates the packet to extract the new header and the fence identifier.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method of forwarding packets through a particular private virtual network (PVN) defined over a shared physical network along with a plurality of other PVNs, the method comprising:
at a filter defined on a first host computer:
receiving a packet sent by a first machine executing on the first host computer, the packet addressed to a second machine executing on a second host computer;
encapsulating the packet with an overlay-network encapsulation header that stores an identifier identifying the particular PVN; and
sending the encapsulated packet to the second machine over the shared physical network.
22 . The method of claim 21 , wherein
the filter executing on the first host computer is a first filter, and a second filter executes on the second host computer and with the first filter forms a distributed virtual filter that adds and removes encapsulating headers with the particular PVN identifier to allow the first and second machines to exchange packets associated with the particular PVN.
23 . The method of claim 21 , wherein the first machine is a first virtual machine (VM) executing on the first host computer, and the second machine is a second VM executing on the second host machine.
24 . The method of claim 23 , wherein each VM has an associated virtual network interface card (VNIC), and the filter is associated with a VNIC of the first VM.
25 . The method of claim 23 , wherein the filter is a module that executes on the first host computer outside of the first VM and that processes packets sent by the first VM.
26 . The method of claim 21 , wherein receiving the packet sent by the first machine comprises obtaining the packet as the packet passes along an egress data path from the first machine to a physical network interface card (PNIC) of the first host computer.
27 . The method of claim 26 , wherein
the packet is obtained before the packet is processed by a software switch executing on the first host computer, sending the encapsulated packet to the second machine comprises sending the packet to the software switch for forwarding to the PNIC to send the encapsulated packet to the physical network, the physical network forwarding the encapsulated packet to the second host computer, which removes the encapsulated overlay-network header, uses a destination address in an original header of the packet to identify the second machine, and passes the packet to the second machine.
28 . The method of claim 21 , wherein the filter comprises a bridge table that stores addresses of destination hosts where machines of the private virtual network execute.
29 . The method of claim 21 further comprising:
when the size of the encapsulated packet exceeds the maximum-transmission unit (MTU) for the network, fragmenting the packet into at least two packets and encapsulating each of the two packets with an overlay encapsulation header before sending the encapsulated packets over the physical network.
30 . The method of claim 29 , wherein encapsulating the packet with an overlay-network encapsulation header further comprises encapsulating the packet with (i) a 2-bit field to indicate whether the packet has been fragmented and (ii) a fragment sequence number that indicates which fragment number corresponds to the packet.
31 . A non-transitory machine readable medium storing a filter for forwarding packets through a particular private virtual network (PVN) defined over a shared physical network along with a plurality of other PVNs, the filter for execution by at least one hardware processing unit of a first host computer, the filter comprising sets of instructions for:
receiving a packet sent by a first machine executing on the first host computer, the packet addressed to a second machine executing on a second host computer; encapsulating the packet with an overlay-network encapsulation header that stores an identifier identifying the particular PVN; and sending the encapsulated packet to the second machine over the shared physical network.
32 . The non-transitory machine readable medium of claim 31 ,
the filter executing on the first host computer is a first filter, and a second filter executes on the second host computer and with the first filter forms a distributed virtual filter that adds and removes encapsulating headers with the particular PVN identifier to allow the first and second machines to exchange packets associated with the particular PVN.
33 . The non-transitory machine readable medium of claim 31 , wherein the first machine is a first virtual machine (VM) executing on the first host computer, and the second machine is a second VM executing on the second host machine.
34 . The non-transitory machine readable medium of claim 33 , wherein each VM has an associated virtual network interface card (VNIC), and the filter is associated with a VNIC of the first VM.
35 . The non-transitory machine readable medium of claim 33 , wherein the filter is a program that executes on the first host computer outside of the first VM and that processes packets sent by the first VM.
36 . The non-transitory machine readable medium of claim 31 , wherein the set of instructions for receiving the packet sent by the first machine comprises a set of instructions for obtaining the packet as the packet passes along an egress data path from the first machine to a physical network interface card (PNIC) of the first hos computer.
37 . The non-transitory machine readable medium of claim 36 , wherein
the packet is obtained before the packet is processed by a software switch executing on the first host computer, the set of instructions for sending the encapsulated packet to the second machine comprises a set of instructions for sending the packet to the software switch for forwarding to the PNIC to send the encapsulated packet to the physical network, the physical network forwarding the encapsulated packet to the second host computer, which removes the encapsulated overlay-network header, uses a destination address in an original header of the packet to identify the second machine, and passes the packet to the second machine.
38 . The non-transitory machine readable medium of claim 31 , wherein the filter uses a bridge table that stores addresses of destination hosts where machines of the private virtual network execute.
39 . The non-transitory machine readable medium of claim 31 , wherein the filter further comprises sets of instructions for:
fragmenting the packet into at least two packets when the size of the encapsulated packet exceeds the maximum-transmission unit (MTU) for the network, and encapsulating each of the two packets with an overlay encapsulation header before sending the encapsulated packets over the physical network.
40 . The non-transitory machine readable medium of claim 39 , wherein the set of instructions for encapsulating the packet with an overlay-network encapsulation header further comprises a set of instructions for encapsulating the packet with (i) a 2-bit field to indicate whether the packet has been fragmented and (ii) a fragment sequence number that indicates which fragment number corresponds to the packet.Join the waitlist — get patent alerts
Track US2024031459A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.