IP Library Granted Patent US 12,541,385
Granted Patent B2
US 12,541,385 · App. 14/687,869 · Granted Feb 3, 2026

Firewalls in logical networks

Inventors: Teemu Koponen (San Francisco, CA); Ronghua Zhang (San Jose, CA); Pankaj Thakkar (Santa Clara, CA); Martin Casado (Portola Valley, CA)
Assignee: VMware LLC
G06F9/45558G06F9/455G06F9/45533G06F15/177H04L41/0803H04L41/0806H04L41/0813H04L41/0823H04L41/0889H04L41/0894H04L41/0895H04L45/64H04L45/74H04L49/70H04L61/2503H04L61/2517H04L61/2521H04L61/256H04L63/0218H04L67/1008G06F2009/4557G06F2009/45595H04L45/02H04L49/15
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,541,385
App. No.
14/687,869
Granted
Feb 3, 2026
Kind
B2
Abstract

Some embodiments provide a method for configuring a logical firewall in a hosting system that includes a set of nodes. The logical firewall is part of a logical network that includes a set of logical forwarding elements. The method receives a configuration for the firewall that specifies packet processing rules for the firewall. The method identifies several of the nodes on which to implement the logical forwarding elements. The method distributes the firewall configuration for implementation on the identified nodes. At a node, the firewall of some embodiments receives a a packet, from a managed switching element within the node, through a software port between the managed switching element and the distributed firewall application. The firewall determines whether to allow the packet based on the received configuration. When the packet is allowed, the firewall the packet back to the managed switching element through the software port.

Claims (54)

1 . For a firewall application executing on a physical host computer, a method comprising:

receiving a packet from a managed forwarding element executing on the physical host computer;

identifying which of a plurality of sets of processing rules enforced by the firewall application applies to the packet, wherein:

(i) each set of processing rules of the plurality of sets of processing rules corresponds to a different one of a plurality of distributed firewalls;

(ii) each distributed firewall of the plurality of distributed firewalls is associated with a different one of a plurality of logical networks;

(iii) each respective logical network of the plurality of logical networks logically connects a respective set of end machines that operate on the physical host computer with other end machines that operate on a respective plurality of other physical host computers and that are connected to the respective logical network;

(iv) each respective logical network is implemented by a respective plurality of managed forwarding elements executing on the respective plurality of physical host computers on which at least one end machine connected to the respective logical network operates;

(v) for each respective logical network, the respective set of processing rules corresponding to the respective distributed firewall associated with the respective logical network is enforced by the firewall application executing on the physical host computer and by firewall applications executing on each of the other physical host computers on which at least one end machine connected to the respective logical network operates; and

(vi) identifying which of the plurality of sets of processing rules enforced by the firewall application applies to the packet comprises determining which of the plurality of logical networks the packet is traversing;

determining whether to allow the packet based on the identified set of processing rules; and

when the packet is allowed, sending the packet back to the managed forwarding element executing on the physical host computer.

2 . The method of claim 1 , wherein the plurality of sets of processing rules are received by the firewall application from a network control system that also configures the managed forwarding element.

3 . The method of claim 1 , wherein:

the plurality of distributed firewalls comprises a particular distributed firewall with a corresponding particular set of processing rules enforced by the firewall application; and

a particular logical network that comprises the particular distributed firewall logically connects a particular set of end machines through a set of logical forwarding elements.

4 . The method of claim 3 , wherein the particular distributed firewall logically connects to a logical router implemented by a particular one of the pluralities of managed forwarding elements, including the managed forwarding element executing on the physical host computer, the logical router comprising a set of routing policies that determines whether the managed forwarding element executing on the physical host computer sends the packet to the distributed firewall.

5 . The method of claim 3 , wherein the managed forwarding element implements the particular logical network by implementing the set of logical forwarding elements.

6 . The method of claim 1 , wherein when the identified set of processing rules specifies to drop the packet, the firewall application executing on the physical host computer does not send the packet back to the managed forwarding element executing on the physical host computer.

7 . The method of claim 1 , wherein the packet sent back to the managed forwarding element is treated as a new packet by the managed forwarding element.

8 . The method of claim 1 further comprising negotiating a software port with the managed forwarding element prior to receiving any packets from the managed forwarding element, wherein:

the packet is received by the firewall application from the managed forwarding element through the negotiated software port; and

the packet is sent back to the managed forwarding element through the negotiated software port.

9 . The method of claim 1 , wherein identifying which of the plurality of sets of processing rules applies to the packet comprises:

after receiving the packet, reading a slice identifier appended to the packet; and

matching the slice identifier with a particular set of processing rules that corresponds to a particular one of the plurality of distributed firewalls.

10 . The method of claim 9 , wherein the packet is a first packet, the particular set of processing rules is a first set of processing rules, the slice identifier is a first slice identifier, and the particular distributed firewall is a first distributed firewall, the method further comprising:

receiving a second packet, with a second slice identifier appended, from the managed forwarding element executing on the physical host computer;

matching the second slice identifier with a second set of processing rules of the plurality of sets of processing rules enforced by the firewall application, different from the first set of processing rules, the second set of processing rules corresponding to a second distributed firewall of the plurality of distributed firewalls; and

determining whether to allow the second packet based on the second set of processing rules.

11 . The method of claim 10 , wherein the first and second slice identifiers are appended to the first and second packets, respectively, by the managed forwarding element.

12 . The method of claim 1 , wherein each set of processing rules of the plurality of sets of processing rules comprises a set of rules for determining whether to allow, block, or drop packets based on information about the packets.

13 . The method of claim 12 , wherein the information about the packets comprises stateful transport connection information.

14 . A non-transitory machine readable medium storing a firewall application for execution by at least one processing unit of a physical host computer, the firewall application comprising sets of instructions for:

receiving a packet from a managed forwarding element executing on the physical host computer;

identifying which of a plurality of sets of processing rules enforced by the firewall application applies to the packet, wherein:

(i) each set of processing rules of the plurality of sets of processing rules corresponds to a different one of a plurality of distributed firewalls;

(ii) each distributed firewall of the plurality of distributed firewalls is associated with a different one of a plurality of logical networks;

(iii) each respective logical network of the plurality of logical networks logically connects a respective set of end machines that operate on the physical host computer with other end machines that operate on a respective plurality of other physical host computers and that are connected to the respective logical network;

(iv) each respective logical network is implemented by a respective plurality of managed forwarding elements executing on the respective plurality of physical host computers on which at least one end machine connected to the respective logical network operates

(v) for each respective logical network, the respective set of processing rules corresponding to the respective distributed firewall associated with the respective logical network is enforced by the firewall application executing on the physical host computer and by firewall applications executing on each of the other physical host computers on which at least one end machine connected to the respective logical network operates; and

(vi) identifying which of the plurality of sets of processing rules enforced by the firewall application applies to the packet comprises determining which of the plurality of logical networks the packet is traversing;

determining whether to allow the packet based on the identified set of processing rules; and

when the packet is allowed, sending the packet back to the managed forwarding element executing on the physical host computer.

15 . The non-transitory machine readable medium of claim 14 , wherein the plurality of sets of processing rules are received by the firewall application from a network control system that also configures the managed forwarding element.

16 . The non-transitory machine readable medium of claim 14 , wherein the set of instructions for identifying which of the plurality of sets of processing rules applies to the packet comprises sets of instructions for:

after receiving the packet, reading a slice identifier appended to the packet; and

matching the slice identifier with a particular set of processing rules that corresponds to a particular one of the plurality of distributed firewalls.

17 . The non-transitory machine readable medium of claim 16 , wherein the packet is a first packet, the particular set of processing rules is a first set of processing rules, the slice identifier is a first slice identifier, and the particular distributed firewall is a first distributed firewall, wherein the firewall application further comprises sets of instructions for:

receiving a second packet, with a second slice identifier appended, from the managed forwarding element executing on the physical host computer;

matching the second slice identifier with a second set of processing rules of the plurality of sets of processing rules enforced by the firewall application, different from the first set of processing rules, the second set of processing rules corresponding to a second distributed firewall of the plurality of distributed firewalls; and

determining whether to allow the second packet based on the second set of processing rules.

18 . The non-transitory machine readable medium of claim 14 , wherein each set of processing rules in the plurality of sets of processing rules comprises a set of rules for determining whether to allow, block, or drop packets based on information about the packets.

19 . The non-transitory machine readable medium of claim 18 , wherein the information about the packets comprises stateful transport connection information.

20 . The non-transitory machine readable medium of claim 14 , wherein when the identified set of processing rules specifies to drop the packet, the firewall application does not send the packet back to the managed forwarding element executing on the physical host computer.

Assignments (1)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
Continuity (3)
Division 13678504 · Nov 15, 2012
Provisional Application 61560279 · Nov 15, 2011
Related Publication 20150222598A1 · Aug 6, 2015
References Cited (400)
US 5473771A · Burd et al. · 1995 [cited by applicant]
US 5504921A · Dev et al. · 1996 [cited by applicant]
US 5550816A · Hardwick et al. · 1996 [cited by applicant]
US 5729685A · Chatwani et al. · 1998 [cited by applicant]
US 5751967A · Raab et al. · 1998 [cited by applicant]
US 5796936A · Watabe et al. · 1998 [cited by applicant]
US 6092121A · Bennett et al. · 2000 [cited by applicant]
US 6104699A · Holender et al. · 2000 [cited by applicant]
US 6219699B1 · McCloghrie et al. · 2001 [cited by applicant]
US 6353614B1 · Borella et al. · 2002 [cited by applicant]
US 6505192B1 · Godwin et al. · 2003 [cited by applicant]
US 6512745B1 · Abe et al. · 2003 [cited by applicant]
US 6539432B1 · Taguchi et al. · 2003 [cited by applicant]
US 6678274B1 · Walia et al. · 2004 [cited by applicant]
US 6680934B1 · Cain · 2004 [cited by applicant]
US 6781990B1 · Puri et al. · 2004 [cited by applicant]
US 6785843B1 · McRae et al. · 2004 [cited by applicant]
US 6862264B1 · Moura et al. · 2005 [cited by applicant]
US 6880089B1 · Bommareddy et al. · 2005 [cited by applicant]
US 6907042B1 · Oguchi · 2005 [cited by applicant]
US 6963585B1 · Le Pennec et al. · 2005 [cited by applicant]
US 7042912B2 · Smith et al. · 2006 [cited by applicant]
US 7046630B2 · Abe et al. · 2006 [cited by applicant]
US 7055027B1 · Gunter et al. · 2006 [cited by applicant]
US 7055173B1 · Chaganty et al. · 2006 [cited by applicant]
US 7126923B1 · Yang et al. · 2006 [cited by applicant]
US 7197572B2 · Matters et al. · 2007 [cited by applicant]
US 7206861B1 · Callon · 2007 [cited by applicant]
US 7209439B2 · Rawlins et al. · 2007 [cited by applicant]
US 7283465B2 · Zelig et al. · 2007 [cited by applicant]
US 7283473B2 · Arndt et al. · 2007 [cited by applicant]
US 7286490B2 · Saleh et al. · 2007 [cited by applicant]
US 7342916B2 · Das et al. · 2008 [cited by applicant]
US 7343410B2 · Mercier et al. · 2008 [cited by applicant]
US 7447775B1 · Zhu et al. · 2008 [cited by applicant]
US 7450598B2 · Chen et al. · 2008 [cited by applicant]
US 7467198B2 · Goodman et al. · 2008 [cited by applicant]
US 7478173B1 · Delco · 2009 [cited by applicant]
US 7512744B2 · Banga et al. · 2009 [cited by applicant]
US 7554995B2 · Short et al. · 2009 [cited by applicant]
US 7555002B2 · Arndt et al. · 2009 [cited by applicant]
US 7606229B1 · Foschiano et al. · 2009 [cited by applicant]
US 7606260B2 · Oguchi et al. · 2009 [cited by applicant]
US 7627692B2 · Pessi · 2009 [cited by applicant]
US 7647426B2 · Patel et al. · 2010 [cited by applicant]
US 7649851B2 · Takashige et al. · 2010 [cited by applicant]
US 7706266B2 · Plamondon · 2010 [cited by applicant]
US 7706325B2 · Fodor et al. · 2010 [cited by applicant]
US 7710872B2 · Vasseur · 2010 [cited by applicant]
US 7710874B2 · Balakrishnan et al. · 2010 [cited by applicant]
US 7725602B2 · Liu et al. · 2010 [cited by applicant]
US 7730486B2 · Herington · 2010 [cited by applicant]
US 7742398B1 · Tene et al. · 2010 [cited by applicant]
US 7761259B1 · Seymour · 2010 [cited by applicant]
US 7764599B2 · Doi et al. · 2010 [cited by applicant]
US 7792987B1 · Vohra et al. · 2010 [cited by applicant]
US 7802000B1 · Huang et al. · 2010 [cited by applicant]
US 7808929B2 · Wong et al. · 2010 [cited by applicant]
US 7818452B2 · Matthews et al. · 2010 [cited by applicant]
US 7826390B2 · Noel et al. · 2010 [cited by applicant]
US 7826482B1 · Minei et al. · 2010 [cited by applicant]
US 7839847B2 · Nadeau et al. · 2010 [cited by applicant]
US 7855950B2 · Zwiebel et al. · 2010 [cited by applicant]
US 7856549B2 · Wheeler · 2010 [cited by applicant]
US 7885276B1 · Lin · 2011 [cited by applicant]
US 7925661B2 · Broussard et al. · 2011 [cited by applicant]
US 7925850B1 · Waldspurger et al. · 2011 [cited by applicant]
US 7933198B1 · Pan · 2011 [cited by applicant]
US 7936770B1 · Frattura et al. · 2011 [cited by applicant]
US 7937438B1 · Miller et al. · 2011 [cited by applicant]
US 7941837B1 · Jiang · 2011 [cited by examiner]
US 7945658B1 · Nucci et al. · 2011 [cited by applicant]
US 7948986B1 · Ghosh et al. · 2011 [cited by applicant]
US 7953865B1 · Miller et al. · 2011 [cited by applicant]
US 7991859B1 · Miller et al. · 2011 [cited by applicant]
US 7995483B1 · Bayar et al. · 2011 [cited by applicant]
US 8005015B2 · Belqasmi et al. · 2011 [cited by applicant]
US 8018866B1 · Kasturi et al. · 2011 [cited by applicant]
US 8027260B2 · Venugopal et al. · 2011 [cited by applicant]
US 8027354B1 · Portolani et al. · 2011 [cited by applicant]
US 8031606B2 · Memon et al. · 2011 [cited by applicant]
US 8031633B2 · Bueno et al. · 2011 [cited by applicant]
US 8046456B1 · Miller et al. · 2011 [cited by applicant]
US 8051180B2 · Mazzaferri et al. · 2011 [cited by applicant]
US 8054832B1 · Shukla et al. · 2011 [cited by applicant]
US 8055789B2 · Richardson et al. · 2011 [cited by applicant]
US 8060779B2 · Beardsley et al. · 2011 [cited by applicant]
US 8060875B1 · Lambeth · 2011 [cited by applicant]
US 8064362B2 · Mekkattuparamban et al. · 2011 [cited by applicant]
US 8131852B1 · Miller et al. · 2012 [cited by applicant]
US 8149737B2 · Metke et al. · 2012 [cited by applicant]
US 8155028B2 · Abu-Hamdeh et al. · 2012 [cited by applicant]
US 8166201B2 · Richardson et al. · 2012 [cited by applicant]
US 8190767B1 · Maufer et al. · 2012 [cited by applicant]
US 8194674B1 · Pagel et al. · 2012 [cited by applicant]
US 8196144B2 · Kagan et al. · 2012 [cited by applicant]
US 8199750B1 · Schultz et al. · 2012 [cited by applicant]
US 8204982B2 · Casado et al. · 2012 [cited by applicant]
US 8224931B1 · Brandwine et al. · 2012 [cited by applicant]
US 8224971B1 · Miller et al. · 2012 [cited by applicant]
US 8265071B2 · Sindhu et al. · 2012 [cited by applicant]
US 8265075B2 · Pandey · 2012 [cited by applicant]
US 8312129B1 · Miller et al. · 2012 [cited by applicant]
US 8321936B1 · Green et al. · 2012 [cited by applicant]
US 8339959B1 · Moisand et al. · 2012 [cited by applicant]
US 8339994B2 · Gnanasekaran et al. · 2012 [cited by applicant]
US 8456984B2 · Ranganathan et al. · 2013 [cited by applicant]
US 8463904B2 · Casado et al. · 2013 [cited by applicant]
US 8468548B2 · Kulkarni et al. · 2013 [cited by applicant]
US 8473557B2 · Ramakrishnan et al. · 2013 [cited by applicant]
US 8516158B1 · Wu et al. · 2013 [cited by applicant]
US 8543808B2 · Ahmed et al. · 2013 [cited by applicant]
US 8571031B2 · Davies et al. · 2013 [cited by applicant]
US 8611351B2 · Gooch et al. · 2013 [cited by applicant]
US 8612627B1 · Brandwine · 2013 [cited by applicant]
US 8615579B1 · Vincent et al. · 2013 [cited by applicant]
US 8621058B2 · Eswaran et al. · 2013 [cited by applicant]
US 8625594B2 · Safrai et al. · 2014 [cited by applicant]
US 8644188B1 · Brandwine et al. · 2014 [cited by applicant]
US 8650299B1 · Huang et al. · 2014 [cited by applicant]
US 8650618B2 · Asati et al. · 2014 [cited by applicant]
US 8705527B1 · Addepalli et al. · 2014 [cited by applicant]
US 8743885B2 · Khan et al. · 2014 [cited by applicant]
US 8762501B2 · Kempf et al. · 2014 [cited by applicant]
US 8813209B2 · Bhattacharya et al. · 2014 [cited by applicant]
US 8819678B2 · Tsirkin · 2014 [cited by applicant]
US 8874757B2 · Souza · 2014 [cited by applicant]
US 8913611B2 · Koponen et al. · 2014 [cited by applicant]
US 8913661B2 · Bivolarsky et al. · 2014 [cited by applicant]
US 8966024B2 · Koponen et al. · 2015 [cited by applicant]
US 8966029B2 · Zhang et al. · 2015 [cited by applicant]
US 8966035B2 · Casado et al. · 2015 [cited by applicant]
US 8996683B2 · Maltz et al. · 2015 [cited by applicant]
US 9015823B2 · Koponen et al. · 2015 [cited by applicant]
US 9104458B1 · Brandwine et al. · 2015 [cited by applicant]
US 9172603B2 · Padmanabhan et al. · 2015 [cited by applicant]
US 9195491B2 · Zhang et al. · 2015 [cited by applicant]
US 9203747B1 · Brandwine et al. · 2015 [cited by applicant]
US 9237132B2 · Mihelich et al. · 2016 [cited by applicant]
US 9306843B2 · Koponen et al. · 2016 [cited by applicant]
US 9306909B2 · Koponen et al. · 2016 [cited by applicant]
US 9329886B2 · Vincent · 2016 [cited by applicant]
US 9424144B2 · Sridharan et al. · 2016 [cited by applicant]
US 9448821B2 · Wang · 2016 [cited by applicant]
US 9552219B2 · Zhang et al. · 2017 [cited by applicant]
US 9558027B2 · Zhang et al. · 2017 [cited by applicant]
US 9697030B2 · Koponen et al. · 2017 [cited by applicant]
US 9697033B2 · Koponen et al. · 2017 [cited by applicant]
US 10089127B2 · Padmanabhan et al. · 2018 [cited by applicant]
US 10191763B2 · Koponen et al. · 2019 [cited by applicant]
US 10235199B2 · Zhang et al. · 2019 [cited by applicant]
US 10310886B2 · Zhang et al. · 2019 [cited by applicant]
US 10514941B2 · Zhang et al. · 2019 [cited by applicant]
US 10884780B2 · Koponen et al. · 2021 [cited by applicant]
US 10922124B2 · Zhang et al. · 2021 [cited by applicant]
US 10949248B2 · Zhang et al. · 2021 [cited by applicant]
US 10977067B2 · Padmanabhan et al. · 2021 [cited by applicant]
US 11372671B2 · Koponen et al. · 2022 [cited by applicant]
US 11593148B2 · Zhang et al. · 2023 [cited by applicant]
US 20010043614A1 · Viswanadham et al. · 2001 [cited by applicant]
US 20020034189A1 · Haddock et al. · 2002 [cited by applicant]
US 20020093952A1 · Gonda · 2002 [cited by applicant]
US 20020161867A1 · Cochran et al. · 2002 [cited by applicant]
US 20020194369A1 · Rawlins et al. · 2002 [cited by applicant]
US 20030009559A1 · Ikeda · 2003 [cited by applicant]
US 20030058850A1 · Rangarajan et al. · 2003 [cited by applicant]
US 20030069972A1 · Yoshimura et al. · 2003 [cited by applicant]
US 20030079000A1 · Chamberlain · 2003 [cited by applicant]
US 20030093481A1 · Mitchell et al. · 2003 [cited by applicant]
US 20030097454A1 · Yamakawa et al. · 2003 [cited by applicant]
US 20030131116A1 · Jain · 2003 [cited by examiner]
US 20040049701A1 · Le Pennec et al. · 2004 [cited by applicant]
US 20040054793A1 · Coleman · 2004 [cited by applicant]
US 20040073659A1 · Rajsic et al. · 2004 [cited by applicant]
US 20040098505A1 · Clemmensen · 2004 [cited by applicant]
US 20040131059A1 · Ayyakad et al. · 2004 [cited by applicant]
US 20040199587A1 · McKnight · 2004 [cited by applicant]
US 20050013280A1 · Buddhikot et al. · 2005 [cited by applicant]
US 20050018669A1 · Arndt et al. · 2005 [cited by applicant]
US 20050021683A1 · Newton et al. · 2005 [cited by applicant]
US 20050027881A1 · Figueira et al. · 2005 [cited by applicant]
US 20050050377A1 · Chan et al. · 2005 [cited by applicant]
US 20050060365A1 · Robinson et al. · 2005 [cited by applicant]
US 20050083953A1 · May · 2005 [cited by applicant]
US 20050108709A1 · Sciandra et al. · 2005 [cited by applicant]
US 20050132030A1 · Hopen et al. · 2005 [cited by applicant]
US 20050240654A1 · Wolber et al. · 2005 [cited by applicant]
US 20050249199A1 · Albert et al. · 2005 [cited by applicant]
US 20060026225A1 · Canali et al. · 2006 [cited by applicant]
US 20060059551A1 · Borella · 2006 [cited by applicant]
US 20060092976A1 · Lakshman et al. · 2006 [cited by applicant]
US 20060215684A1 · Capone et al. · 2006 [cited by applicant]
US 20060221961A1 · Basso et al. · 2006 [cited by applicant]
US 20070101323A1 · Foley et al. · 2007 [cited by applicant]
US 20070101421A1 · Wesinger · 2007 [cited by examiner]
US 20070140128A1 · Klinker et al. · 2007 [cited by applicant]
US 20070233455A1 · Zimmer et al. · 2007 [cited by applicant]
US 20070233838A1 · Takamoto et al. · 2007 [cited by applicant]
US 20070239987A1 · Hoole et al. · 2007 [cited by applicant]
US 20070266433A1 · Moore · 2007 [cited by applicant]
US 20070283348A1 · White · 2007 [cited by applicant]
US 20070286185A1 · Eriksson et al. · 2007 [cited by applicant]
US 20080002579A1 · Lindholm et al. · 2008 [cited by applicant]
US 20080005293A1 · Bhargava et al. · 2008 [cited by applicant]
US 20080049621A1 · McGuire et al. · 2008 [cited by applicant]
US 20080071900A1 · Hecker et al. · 2008 [cited by applicant]
US 20080072305A1 · Casado et al. · 2008 [cited by applicant]
US 20080151893A1 · Nordmark et al. · 2008 [cited by applicant]
US 20080163207A1 · Reumann et al. · 2008 [cited by applicant]
US 20080186990A1 · Abali et al. · 2008 [cited by applicant]
US 20080189769A1 · Casado et al. · 2008 [cited by applicant]
US 20080196100A1 · Madhavan et al. · 2008 [cited by applicant]
US 20080205377A1 · Chao et al. · 2008 [cited by applicant]
US 20080225853A1 · Melman et al. · 2008 [cited by applicant]
US 20080232250A1 · Park · 2008 [cited by applicant]
US 20080240122A1 · Richardson et al. · 2008 [cited by applicant]
US 20080281908A1 · McCanne et al. · 2008 [cited by applicant]
US 20090025077A1 · Trojanowski · 2009 [cited by examiner]
US 20090031041A1 · Clemmensen · 2009 [cited by applicant]
US 20090063750A1 · Dow · 2009 [cited by applicant]
US 20090064305A1 · Stiekes et al. · 2009 [cited by applicant]
US 20090070877A1 · Davids et al. · 2009 [cited by applicant]
US 20090083445A1 · Ganga · 2009 [cited by applicant]
US 20090092137A1 · Haigh et al. · 2009 [cited by applicant]
US 20090122710A1 · Bar-Tor et al. · 2009 [cited by applicant]
US 20090129271A1 · Ramankutty et al. · 2009 [cited by applicant]
US 20090150527A1 · Tripathi et al. · 2009 [cited by applicant]
US 20090161547A1 · Riddle et al. · 2009 [cited by applicant]
US 20090199177A1 · Edwards et al. · 2009 [cited by applicant]
US 20090240924A1 · Yasaki et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090249472A1 · Litvin · 2009 [cited by examiner]
US 20090249473A1 · Cohn · 2009 [cited by applicant]
US 20090279536A1 · Unbehagen et al. · 2009 [cited by applicant]
US 20090292858A1 · Lambeth et al. · 2009 [cited by applicant]
US 20090300210A1 · Ferris · 2009 [cited by applicant]
US 20090303880A1 · Maltz et al. · 2009 [cited by applicant]
US 20090327464A1 · Archer et al. · 2009 [cited by applicant]
US 20090327781A1 · Tripathi · 2009 [cited by applicant]
US 20100036903A1 · Ahmad et al. · 2010 [cited by applicant]
US 20100046530A1 · Hautakorpi et al. · 2010 [cited by applicant]
US 20100046531A1 · Louati et al. · 2010 [cited by applicant]
US 20100098092A1 · Luo et al. · 2010 [cited by applicant]
US 20100103837A1 · Jungck et al. · 2010 [cited by applicant]
US 20100115080A1 · Kageyama · 2010 [cited by applicant]
US 20100115101A1 · Lain et al. · 2010 [cited by applicant]
US 20100125667A1 · Soundararajan · 2010 [cited by applicant]
US 20100128623A1 · Dunn et al. · 2010 [cited by applicant]
US 20100131636A1 · Suri et al. · 2010 [cited by applicant]
US 20100131638A1 · Kondamuru · 2010 [cited by applicant]
US 20100138830A1 · Astete et al. · 2010 [cited by applicant]
US 20100146074A1 · Srinivasan · 2010 [cited by applicant]
US 20100153554A1 · Anschutz et al. · 2010 [cited by applicant]
US 20100162036A1 · Linden et al. · 2010 [cited by applicant]
US 20100165876A1 · Shukla et al. · 2010 [cited by applicant]
US 20100165877A1 · Shukla et al. · 2010 [cited by applicant]
US 20100169467A1 · Shukla et al. · 2010 [cited by applicant]
US 20100214949A1 · Smith et al. · 2010 [cited by applicant]
US 20100254385A1 · Sharma et al. · 2010 [cited by applicant]
US 20100257263A1 · Casado et al. · 2010 [cited by applicant]
US 20100275199A1 · Smith et al. · 2010 [cited by applicant]
US 20100284402A1 · Narayanan · 2010 [cited by applicant]
US 20100287548A1 · Zhou et al. · 2010 [cited by applicant]
US 20100306408A1 · Greenberg et al. · 2010 [cited by applicant]
US 20100318665A1 · Demmer et al. · 2010 [cited by applicant]
US 20100322255A1 · Hao et al. · 2010 [cited by applicant]
US 20100333165A1 · Basak · 2010 [cited by examiner]
US 20110002346A1 · Wu · 2011 [cited by applicant]
US 20110004698A1 · Wu · 2011 [cited by applicant]
US 20110004876A1 · Wu et al. · 2011 [cited by applicant]
US 20110004877A1 · Wu · 2011 [cited by applicant]
US 20110022695A1 · Dalal et al. · 2011 [cited by applicant]
US 20110026521A1 · Gamage et al. · 2011 [cited by applicant]
US 20110075674A1 · Li et al. · 2011 [cited by applicant]
US 20110085557A1 · Gnanasekaran et al. · 2011 [cited by applicant]
US 20110085559A1 · Chung et al. · 2011 [cited by applicant]
US 20110085563A1 · Kotha et al. · 2011 [cited by applicant]
US 20110113483A1 · Rangegowda · 2011 [cited by examiner]
US 20110119748A1 · Edwards et al. · 2011 [cited by applicant]
US 20110173692A1 · Liu et al. · 2011 [cited by applicant]
US 20110197039A1 · Green et al. · 2011 [cited by applicant]
US 20110225594A1 · Iyengar et al. · 2011 [cited by applicant]
US 20110255538A1 · Srinivasan · 2011 [cited by examiner]
US 20110261825A1 · Ichino · 2011 [cited by applicant]
US 20110289230A1 · Ueno · 2011 [cited by applicant]
US 20110299534A1 · Koganti et al. · 2011 [cited by applicant]
US 20110299538A1 · Maruta · 2011 [cited by applicant]
US 20110310899A1 · Alkhatib et al. · 2011 [cited by applicant]
US 20120011264A1 · Izawa · 2012 [cited by applicant]
US 20120014386A1 · Xiong et al. · 2012 [cited by applicant]
US 20120144014A1 · Natham et al. · 2012 [cited by applicant]
US 20120147894A1 · Mulligan · 2012 [cited by examiner]
US 20120155266A1 · Patel et al. · 2012 [cited by applicant]
US 20120185577A1 · Giaretta et al. · 2012 [cited by applicant]
US 20120210416A1 · Mihelich et al. · 2012 [cited by applicant]
US 20120210417A1 · Shieh · 2012 [cited by applicant]
US 20120236734A1 · Sampath et al. · 2012 [cited by applicant]
US 20120240182A1 · Narayanaswamy et al. · 2012 [cited by applicant]
US 20120246637A1 · Kreeger et al. · 2012 [cited by applicant]
US 20120281540A1 · Khan et al. · 2012 [cited by applicant]
US 20120303790A1 · Singh et al. · 2012 [cited by applicant]
US 20130003735A1 · Chao et al. · 2013 [cited by applicant]
US 20130019015A1 · Devarakonda et al. · 2013 [cited by applicant]
US 20130036416A1 · Raju et al. · 2013 [cited by applicant]
US 20130041987A1 · Warno · 2013 [cited by applicant]
US 20130054761A1 · Kempf et al. · 2013 [cited by applicant]
US 20130058250A1 · Casado et al. · 2013 [cited by applicant]
US 20130058350A1 · Fulton · 2013 [cited by applicant]
US 20130061047A1 · Sridharan et al. · 2013 [cited by applicant]
US 20130073743A1 · Ramasamy et al. · 2013 [cited by applicant]
US 20130074066A1 · Sanzgiri et al. · 2013 [cited by applicant]
US 20130074181A1 · Singh · 2013 [cited by applicant]
US 20130097356A1 · Dang et al. · 2013 [cited by applicant]
US 20130103834A1 · Dzerve et al. · 2013 [cited by applicant]
US 20130121209A1 · Padmanabhan et al. · 2013 [cited by applicant]
US 20130125120A1 · Zhang et al. · 2013 [cited by applicant]
US 20130125230A1 · Koponen et al. · 2013 [cited by applicant]
US 20130128891A1 · Koponen et al. · 2013 [cited by applicant]
US 20130132531A1 · Koponen et al. · 2013 [cited by applicant]
US 20130132532A1 · Zhang et al. · 2013 [cited by applicant]
US 20130132533A1 · Padmanabhan et al. · 2013 [cited by applicant]
US 20130132536A1 · Zhang et al. · 2013 [cited by applicant]
US 20130163427A1 · Beliveau et al. · 2013 [cited by applicant]
US 20130163475A1 · Beliveau et al. · 2013 [cited by applicant]
US 20130163594A1 · Sharma et al. · 2013 [cited by applicant]
US 20130227097A1 · Yasuda et al. · 2013 [cited by applicant]
US 20130332619A1 · Xie et al. · 2013 [cited by applicant]
US 20130332983A1 · Koorevaar et al. · 2013 [cited by applicant]
US 20140016501A1 · Kamath et al. · 2014 [cited by applicant]
US 20140019639A1 · Ueno · 2014 [cited by applicant]
US 20140068602A1 · Gember et al. · 2014 [cited by applicant]
US 20140153577A1 · Janakiraman et al. · 2014 [cited by applicant]
US 20140169375A1 · Khan et al. · 2014 [cited by applicant]
US 20140195666A1 · Dumitriu et al. · 2014 [cited by applicant]
US 20140359620A1 · Kerkwyk et al. · 2014 [cited by applicant]
US 20150081861A1 · Koponen et al. · 2015 [cited by applicant]
US 20150098360A1 · Koponen et al. · 2015 [cited by applicant]
US 20150124651A1 · Zhang et al. · 2015 [cited by applicant]
US 20150142938A1 · Koponen et al. · 2015 [cited by applicant]
US 20160070588A1 · Zhang et al. · 2016 [cited by applicant]
US 20160087840A1 · Miller et al. · 2016 [cited by applicant]
US 20160241491A1 · Tripathi et al. · 2016 [cited by applicant]
US 20170116023A1 · Zhang et al. · 2017 [cited by applicant]
US 20170126493A1 · Zhang et al. · 2017 [cited by applicant]
US 20170277557A1 · Koponen et al. · 2017 [cited by applicant]
US 20190034220A1 · Padmanabhan et al. · 2019 [cited by applicant]
US 20190138343A1 · Koponen et al. · 2019 [cited by applicant]
US 20190258507A1 · Zhang et al. · 2019 [cited by applicant]
US 20200081732A1 · Zhang et al. · 2020 [cited by applicant]
US 20210149708A1 · Koponen et al. · 2021 [cited by applicant]
US 20210191750A1 · Zhang et al. · 2021 [cited by applicant]
US 20210200572A1 · Zhang et al. · 2021 [cited by applicant]
US 20220326980A1 · Koponen et al. · 2022 [cited by applicant]
CN 1886962A · 2006 [cited by applicant]
CN 101904155A · 2010 [cited by applicant]
CN 102113274A · 2011 [cited by applicant]
EP 1653688 · 2006 [cited by applicant]
EP 2395712A1 · 2011 [cited by applicant]
EP 2748750 · 2014 [cited by applicant]
JP 2000332817A · 2000 [cited by applicant]
JP 2003124976 · 2003 [cited by applicant]
JP 2003318949 · 2003 [cited by applicant]
JP 2005260299A · 2005 [cited by applicant]
JP 2011188433A · 2011 [cited by applicant]
JP 2011211502A · 2011 [cited by applicant]
JP 2012525017A · 2012 [cited by applicant]
WO 9918534A2 · 1999 [cited by applicant]
WO WO2005112390 · 2005 [cited by applicant]
WO WO2008095010 · 2008 [cited by applicant]
WO 2010090182A1 · 2010 [cited by applicant]
WO 2010116606A1 · 2010 [cited by applicant]
WO 2012051884A1 · 2012 [cited by applicant]
WO WO2013074827 · 2013 [cited by applicant]
WO WO2013074828 · 2013 [cited by applicant]
WO WO2013074831 · 2013 [cited by applicant]
WO WO2013074842 · 2013 [cited by applicant]
WO WO2013074844 · 2013 [cited by applicant]
WO WO2013074847 · 2013 [cited by applicant]
WO WO2013074855 · 2013 [cited by applicant]
NPL Search Terms (Year: 2022). [cited by examiner]
International Search Report and Written Opinion for PCT/US2012/065341, Jan. 28, 2013 (mailing date), Nicira, Inc. [cited by applicant]
Portions of prosecution history of EP12849295.6, Sep. 23, 2015 (mailing date), Nicira, Inc. [cited by applicant]
Andersen, David, et al., “Resilient Overlay Networks,” Oct. 2001, 15 pages, 18th ACM Symp. On Operating Systems Principles (SOSP), Banff, Canada, ACM. [cited by applicant]
Anderson, Thomas, et al., “Overcoming the Internet Impasse through Virtualization,” Apr. 2005, pp. 34-41, IEEE Computer Society. [cited by applicant]
Anhalt, Fabienne, et al., “Analysis and evaluation of a XEN based virtual router,” Sep. 2008, pp. 1-60, Unite de recherché INRA Phone-Alpes, Montbonnot Saint-Ismier, France. [cited by applicant]
Author Unknown , “Cisco Nexis 1000V Series Switches,” Date Unknown but prior to Jul. 29, 2010, 2 pages, Cisco Systems, Inc., http:/web.archive.org/web/20100729045626/http://www.cisco.com/en/US/Products/ps9902/index.html. [cited by applicant]
Author Unknown , “Cisco VN-Link: Virtualization-Aware Networking,” Month Unknown, 2009, 10 pages, Cisco Systems, Inc. [cited by applicant]
Author Unknown , “VMare for Linux Networking Support,” Date Unknown but prior to Nov. 17, 1999, pp. 1-5, VMWare, Inc. [cited by applicant]
Author Unknown, “Cisco VN-Link: Virtual Machine-Aware Networking,” Apr. 2009, 2 pages, Cisco Systems, Inc. [cited by applicant]
Author Unknown, “Intel 82599 10 Gigabit Ethernet Controller: Datasheet, Revision: 2.73,” Dec. 2011, 930 pages, Intel Corporation. [cited by applicant]
Author Unknown, “Virtual Machine Device Queues,” White Paper, Month Unknown, 2007, pp. 1-4, Intel Corporation. [cited by applicant]
Barham, Paul, et al., “Xen and the Art of Virtualization,” Oct. 19-22, 2003, pp. 1-14, SOSP'03, Bolton Landing New York, USA. [cited by applicant]
Cai, Zheng, et al., “The Preliminary Design and Implementation of the Maestro Network Control Platform,” Oct. 1, 2008, pp. 1-17, NSF. [cited by applicant]
Casado, Martin, et al. “Ethane: Taking Control of the Enterprise,” SIGCOMM'07, Aug. 27-31, 2007, pp. 1-12, ACM, Kyoto, Japan. [cited by applicant]
Casado, Martin, et al., “Rethinking Packet Forwarding Hardware,” Seventh ACM SIGCOMM HotNets Workshop, Nov. 2008, pp. 1-6, ACM. [cited by applicant]
Casado, Martin, et al., “SANE: A Protection Architecture for Enterprise Networks,” In proceedings of Usenix Security, Aug. 2006, pp. 1-15. [cited by applicant]
Casado, Martin, et al., “Scaling Out: Network Virtualization Revisited,” Month Unknown, 2010, pp. 1-8. [cited by applicant]
Casado, Martin, et al., “Virtualizing the Network Forwarding Plane,” Dec. 2010, pp. 1-6. [cited by applicant]
Congdon, Paul, “Virtual Ethernet Port Aggregator Standards body Discussion,” Nov. 10, 2008, pp. 1-26, HP. [cited by applicant]
Das, Suarav, et al. “Simple Unified Control for Packet and Circuit Networks,” Month Unknown, 2009, pp. 147-148, IEEE. [cited by applicant]