IP Library Granted Patent US 9,985,911
Granted Patent B2
US 9,985,911 · App. 14/621,892 · Granted May 29, 2018

Methods and apparatus related to a flexible data center security architecture

Inventors: Pradeep Sindhu (Los Altos Hills, CA); Gunes Aybay (Los Altos, CA); Jean-Marc Frailong (Los Altos, CA); Anjan Venkatramani (Los Altos, CA); Quaizar Vohra (Santa Clara, CA)
Assignee: Juniper Networks, Inc.
H04L49/30H04L41/0806H04L41/0846H04L49/257H04L49/35H04L49/356H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,985,911
App. No.
14/621,892
Filed
Feb 13, 2015
Granted
May 29, 2018
Kind
B2
Examiner
DUONG, DUC T
Art Unit
2467
USPC
370/388
Abstract

In one embodiment, edge devices can be configured to be coupled to a multi-stage switch fabric and peripheral processing devices. The edge devices and the multi-stage switch fabric can collectively define a single logical entity. A first edge device from the edge devices can be configured to be coupled to a first peripheral processing device from the peripheral processing devices. The second edge device from the edge devices can be configured to be coupled to a second peripheral processing device from the peripheral processing devices. The first edge device can be configured such that virtual resources including a first virtual resource can be defined at the first peripheral processing device. A network management module coupled to the edge devices and configured to provision the virtual resources such that the first virtual resource can be migrated from the first peripheral processing device to the second peripheral processing device.

Claims (32)

1. An apparatus, comprising:

a network management module configured to be coupled to a plurality of edge devices having a first plurality of ports that are coupled to a multi-stage switch fabric and a second plurality of ports that are coupled to a plurality of peripheral processing devices;

the network management module configured to receive a first signal that includes (1) the data about the network resource operatively coupled to a peripheral processing device from the plurality of peripheral processing devices, (2) an access switch identifier, and (3) a port identifier;

the network management module configured to send a signal to a logical entity using the data about the network resource, the access switch identifier, and the port identifier such that the logical entity causes a virtual resource at a peripheral processing device from the plurality of peripheral processing devices to be provisioned when the virtual resource is attached to or separated from an edge device from the plurality of edge devices; and

the network management module configured to associate a network location with the virtual resource based on data received from the edge device.

2. The apparatus of claim 1 , wherein:

the virtual resource is provisioned such that the virtual resource is migratable from a first peripheral processing device from the plurality of peripheral processing devices to a second peripheral processing device from the plurality of peripheral processing devices.

3. The apparatus of claim 1 , wherein a number of ports in the first plurality of ports for the plurality of edge devices is less than a number of ports in the second plurality of ports of the plurality of edge devices.

4. The apparatus of claim 1 , wherein the plurality of peripheral processing devices include at least one of (1) a plurality of compute nodes, (2) a plurality of service nodes, (3) a plurality of routers, or (4) a plurality of storage nodes.

5. The apparatus of claim 1 , wherein the virtual resource is provisioned without a static description of a network that includes the virtual resource.

6. An apparatus, comprising:

a network management module configured to be operatively coupled to a plurality of edge devices that are operatively coupled to a plurality of peripheral processing devices,

the network management module configured to receive, from the edge device from the plurality of edge devices, information about a network resource operatively coupled to a peripheral processing device from the plurality of peripheral processing devices, when the network resource is attached to or separated from an edge device from the plurality of edge devices,

the network management module configured to determine network topology information for the network based on (1) the information about the network resource and (2) information about the edge device,

the network management module configured to store the information about the network resource, without storing the network topology information,

the network management module configured to send a signal to a logical entity, the signal including the network topology information and provisioning instructions and not including a static description of a network including the network resource.

7. The apparatus of claim 6 , wherein the plurality of peripheral processing devices include at least one of each of (1) a plurality of compute nodes, (2) a plurality of service nodes, (3) a plurality of routers, or (4) a plurality of storage nodes.

8. The apparatus of claim 6 , wherein:

the network resource is provisioned such that the network resource migratable from the first peripheral processing device to the second peripheral processing device from the plurality of peripheral processing devices.

9. The apparatus of claim 6 , wherein the network management module receives the information about the network resource from a network device included in the network.

10. The apparatus of claim 6 , wherein the information about the network resource is at least one of a network resource identifier or an identifier of the peripheral processing device operatively coupled to the network resource.

11. A method, comprising:

receiving a signal indicating that a status of a network resource associated with a peripheral processing device from a plurality of peripheral processing devices has changed;

querying the peripheral processing device for data about the network resource; and

sending, to a network management device, a signal that includes (1) the data about the network resource, (2) an access switch identifier, and (3) a port identifier, so as to instruct the network management device to initiate provisioning of the network resource using the data about the network resource, the access switch identifier, and the port identifier and not using a static description of a network including the network resource.

12. The method of claim 11 , wherein the data about the network resource includes a device identifier of the network resource.

13. The method of claim 11 , wherein the data about the network resource is queried using link layer discovery protocol (LLDP).

14. The method of claim 11 , wherein:

the peripheral processing device is a first peripheral processing device,

the network resource status indicates that the network resource has (1) been instantiated, (2) started, or (3) moved to a second peripheral processing device from the plurality of peripheral processing devices.

15. The method of claim 11 , wherein the port identifier is an identifier of a port at an access switch to which the peripheral processing device is operatively coupled, the access switch being identified by the access switch identifier.

16. The method of claim 11 , wherein the network resource is hosted at the peripheral processing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2017
From: SINDHU, PRADEEP; AYBAY, GUNES; FRAILONG, JEAN-MARC; VENKATRAMANI, ANJAN; VOHRA, QUAIZAR
To: JUNIPER NETWORKS, INC.
Reel/Frame 042612/0636 →
Continuity (15)
Continuation 13608799 · Sep 10, 2012
Continuation 12558126 · Sep 11, 2009
Continuation In Part 12343728 · Dec 24, 2008
Continuation In Part 12345500 · Dec 29, 2008
Continuation In Part 12345502 · Dec 29, 2008
Continuation In Part 12242224 · Sep 30, 2008
Continuation In Part 12242230 · Sep 30, 2008
Continuation In Part 12495337 · Jun 30, 2009
Continuation In Part 12495344 · Jun 30, 2009
Continuation In Part 12495358 · Jun 30, 2009
Continuation In Part 12495361 · Jun 30, 2009
Continuation In Part 12495364 · Jun 30, 2009
Provisional Application 61098516 · Sep 19, 2008
Provisional Application 61096209 · Sep 11, 2008
Related Publication 20150163171A1 · Jun 11, 2015