IP Library Granted Patent US 8,966,024
Granted Patent B2
US 8,966,024 · App. 13/678,498 · Granted Feb 24, 2015

Architecture of networks with middleboxes

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,966,024
App. No.
13/678,498
Granted
Feb 24, 2015
Kind
B2
Abstract

Some embodiments provide a system for implementing a logical network that includes a set of end machines, a first logical middlebox, and a second logical middlebox connected by a set of logical forwarding elements. The system includes a set of nodes. Each of several nodes includes (i) a virtual machine for implementing an end machine of the logical network, (ii) a managed switching element for implementing the set of logical forwarding elements of the logical network, and (iii) a middlebox element for implementing the first logical middlebox of the logical network. The system includes a physical middlebox appliance for implementing the second logical middlebox.

Claims (52)

1. A method for configuring a logical network in a hosting system comprising a plurality of nodes, the method comprising:

receiving a first configuration for a first middlebox of the logical network and a second configuration for a second middlebox of the logical network, the logical network comprising a plurality of end machines hosted on a subset of the plurality of nodes;

identifying the subset of the plurality of the nodes as nodes for implementing the first middlebox;

distributing the first configuration for implementation of the first middlebox on the identified nodes, wherein each of the identified nodes receives the same first configuration for the first middlebox; and

distributing the second configuration for implementation of the second middle box on a single physical machine.

2. The method of claim 1 , wherein the single physical machine comprises a single node that hosts an end machine for implementing the second middlebox.

3. The method of claim 1 , wherein the single physical machine comprises a physical middlebox appliance separate from the plurality of nodes.

4. The method of claim 1 , wherein the method is performed by a first network controller.

5. The method of claim 4 , wherein distributing the first configuration comprises:

automatically identifying a plurality of additional network controllers that manage the identified nodes; and

distributing the first configuration to the identified network controllers for subsequent distribution to the identified nodes.

6. The method of claim 5 , wherein each of the identified nodes is managed by a single one of the additional network controllers.

7. The method of claim 4 , wherein distributing the second configuration comprises:

automatically identifying a particular additional network controller that manages the single physical machine from a set of additional network controllers; and

distributing the second configuration to the identified particular network controller for subsequent distribution to the single physical machine.

8. The method of claim 1 , wherein receiving the first configuration for the first middlebox of the logical network and the second configuration for the second middlebox of the logical network comprises receiving a configuration through a first application programming interface (API) specific to the first middlebox and a second configuration through a second API specific to the second middlebox.

9. The method of claim 1 , wherein the first configuration is received as a set of database table records, wherein the method does not translate the records before distributing the records.

10. The method of claim 1 , wherein the first configuration defines a manner of processing a set of packets by the first middlebox for the plurality of end machines of the logical network.

11. A non-transitory machine readable medium storing a program which when executed by at least one processing unit configures a logical network in a hosting system comprising a plurality of nodes, the program comprising sets of instructions for:

receiving a first configuration for a first middlebox of the logical network and a second configuration for a second middlebox of the logical network, the logical network comprising a plurality of end machines hosted on a subset of the plurality of nodes;

identifying the subset of the plurality of the nodes as nodes for implementing the first middlebox;

distributing the first configuration for implementation of the first middlebox on the identified nodes, wherein each of the identified nodes receives the same first configuration for the first middlebox; and

distributing the second configuration for implementation of the second middle box on a single physical machine.

12. The machine readable medium of claim 11 , wherein the single physical machine comprises a single node that hosts an end machine for implementing the second middlebox.

13. The machine readable medium of claim 11 , wherein the single physical machine comprises a physical middlebox appliance separate from the plurality of nodes.

14. The machine readable medium of claim 11 , wherein the program is performed by a first network controller.

15. The machine readable medium of claim 14 , wherein the set of instructions for distributing the first configuration comprises sets of instructions for:

automatically identifying a plurality of additional network controllers that manage the identified nodes; and

distributing the first configuration to the identified network controllers for subsequent distribution to the identified nodes.

16. The machine readable medium of claim 15 , wherein each of the identified nodes is managed by a single one of the additional network controllers.

17. The machine readable medium of claim 14 , wherein the set of instructions for distributing the second configuration comprises sets of instructions for:

automatically identifying a particular additional network controller that manages the single physical machine from a set of additional network controllers; and

distributing the second configuration to the identified particular network controller for subsequent distribution to the single physical machine.

18. The machine readable medium of claim 11 , wherein the set of instructions for receiving the first configuration for the first middlebox of the logical network and the second configuration for the second middlebox of the logical network comprises a set of instructions for receiving a configuration through a first application programming interface (API) specific to the first middlebox and a second configuration through a second API specific to the second middlebox.

19. The machine readable medium of claim 11 , wherein the first configuration is received as a set of database table records, wherein the set of instructions for distributing the records does not translate the records before distributing them.

20. The machine readable medium of claim 11 , wherein the first configuration defines a manner of processing a set of packets by the first middlebox for the plurality of end machines of the logical network.

21. An apparatus comprising:

a set of processing units for executing sets of instructions; and

a machine readable medium storing a program which when executed by at least one of the processing units configures a logical network in a hosting system comprising a plurality of nodes, the program comprising sets of instructions for:

receiving a first configuration for a first middlebox of the logical network and a second configuration for a second middlebox of the logical network, the logical network comprising a plurality of end machines hosted on a subset of the plurality of nodes;

identifying the subset of the plurality of the nodes as nodes for implementing the first middlebox;

distributing the first configuration for implementation of the first middlebox on the identified nodes, wherein each of the identified nodes receives the same first configuration for the first middlebox; and

distributing the second configuration for implementation of the second middle box on a single physical machine.

22. The apparatus of claim 21 , wherein the program is performed by a first network controller.

23. The apparatus of claim 22 , wherein the set of instructions for distributing the first configuration comprises sets of instructions for:

automatically identifying a plurality of additional network controllers that manage the identified nodes; and

distributing the first configuration to the identified network controllers for subsequent distribution to the identified nodes.

24. The machine readable medium of claim 23 , wherein each of the identified nodes is managed by a single one of the additional network controllers.

25. The apparatus of claim 22 , wherein the set of instructions for distributing the second configuration comprises sets of instructions for:

automatically identifying a particular additional network controller that manages the single physical machine from a set of additional network controllers; and

distributing the second configuration to the identified particular network controller for subsequent distribution to the single physical machine.

26. The apparatus of claim 21 , wherein the set of instructions for receiving the first configuration for the first middlebox of the logical network and the second configuration for the second middlebox of the logical network comprises a set of instructions for receiving a configuration through a first application programming interface (API) specific to the first middlebox and a second configuration through a second API specific to the second middlebox.

Assignments (2)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 1, 2013
From: KOPONEN, TEEMU; ZHANG, RONGHUA; THAKKAR, PANKAJ; CASADO, MARTIN
To: NICIRA, INC.
Reel/Frame 029740/0069 →