IP Library Granted Patent US 10,425,382
Granted Patent B2
US 10,425,382 · App. 15/292,129 · Granted Sep 24, 2019

Method and system of a cloud-based multipath routing protocol

Inventors: Ajit Ramachandra Mayya (Saratoga, CA); Parag Pritam Thakore (Los Gatos, CA); Stephen Craig Connors (San Jose, CA); Alex Kompel (Santa Clara, CA); Thomas Harold Speeter (San Martin, CA)
Assignee: NICIRA, INC.
H04L63/0236H04L12/66H04L45/24H04L45/42H04L45/64H04L49/35H04L63/029H04L63/0272H04L63/0281H04L67/10H04L67/42G06N20/00H04L12/4633
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,425,382
App. No.
15/292,129
Granted
Sep 24, 2019
Kind
B2
Abstract

In one aspect, a computerized system useful for implementing a cloud-based multipath routing protocol to an Internet endpoint includes an edge device that provides an entry point into an entity's core network. The entity's core network includes a set of resources to be reliably accessed. The computerized system includes a cloud-edge device instantiated in a public-cloud computing platform. The cloud-edge device joins a same virtual routing and forwarding table as the edge device. The cloud-edge device receives a set of sources and destinations of network traffic that are permitted to access the edge device and the set of resources.

Claims (28)

1. A method for providing cloud-based multipath routing between a gateway and an edge device, the method comprising:

at the edge device, which connects a set of resources of a core network to at least one external network:

receiving a set of gateway configuration data comprising a set of forwarding rules and a set of access control list (ACL) rules, the set of ACL rules identifying a set of sources and destinations of network traffic that are permitted to access the set of resources; and

transmitting the received gateway configuration data to at least a first gateway, the set of forwarding rules of the gateway configuration data for configuring first and second gateways to implement a same virtual routing and forwarding (VRF) table,

wherein (i) the first gateway receives a first data message from a first client device, determines, based on the set of ACL rules, that the first client device is permitted to access the set of resources, and forwards, using the VRF table, the first data message to the edge device, and (ii) the second gateway receives a second data message from a second client device, determines, based on the set of ACL rules, that the second client device is permitted to access the set of resources, and forwards, using the VRF table, the second data message to the edge device, wherein the first and second client devices do not belong to the core network.

2. The method of claim 1 , wherein the core network comprises one of an enterprise's core network and a service-provider's core network.

3. The method of claim 1 , wherein the edge device is a virtual machine executing on a host in one of a branch office and a customer premises.

4. The method of claim 1 , wherein the first and second gateways implement a cloud gateway, each gateway of the cloud gateway implementing the VRF table and associated with a same logical identifier.

5. The method of claim 4 , wherein the first and second messages are addressed to a same public Internet protocol (IP) address of the cloud gateway.

6. The method of claim 5 , wherein the public IP address is the IP address of a gateway load balancer of the cloud gateway.

7. The method of claim 6 , wherein the first client device accesses the set of resources by accessing the public IP address assigned to the cloud gateway and does not connect to the set of resources by directly accessing an IP address associated with the set of resources, wherein the first client device securely connects to the set of resources over a virtual private network (VPN) via the first gateway.

8. The method of claim 1 , wherein the first data message is forwarded to the edge device via a first link of a multilink bundle connecting the edge device to the first gateway, wherein if the first link of the multilink bundle fails, remaining links of the multilink bundle continue to provide access to the set of resources via the first gateway.

9. The method of claim 1 , wherein the first and second gateways are configured to deny any inbound network traffic by default.

10. The method of claim 1 , wherein the first client device and the second client device are a same client device.

11. A non-transitory machine readable medium storing a program that, when executed by a set of processing units of an edge device, provides cloud-based multipath routing, the program comprising sets of instructions for:

at the edge device, which connects a set of resources of a core network to at least one external network:

receiving a set of gateway configuration data comprising a set of forwarding rules and a set of access control list (ACL) rules, the set of ACL rules identifying a set of sources and destinations of network traffic that are permitted to access the set of resources; and

transmitting the received gateway configuration data to at least a first gateway, the set of forwarding rules of the gateway configuration data for configuring first and second gateways to implement a same virtual routing and forwarding (VRF) table,

wherein (i) the first gateway receives a first data message from a first client device, determines, based on the set of ACL rules, that the first client device is permitted to access the set of resources, and forwards, using the VRF table, the first data message to the edge device, and (ii) the second gateway receives a second data message from a second client device, determines, based on the set of ACL rules, that the second client device is permitted to access the set of resources, and forwards, using the VRF table, the second data message to the edge device, wherein the first and second client devices do not belong to the core network.

12. The non-transitory machine readable medium of claim 11 , wherein the core network comprises one of an enterprise's core network and a service-provider's core network.

13. The non-transitory machine readable medium of claim 11 , wherein the edge device is a virtual machine executing on a host in one of a branch office and a customer premises.

14. The non-transitory machine readable medium of claim 11 , wherein the first and second gateways implement a cloud gateway, each gateway of the cloud gateway implementing the VRF table and associated with a same logical identifier.

15. The non-transitory machine readable medium of claim 14 , wherein the first and second messages are addressed to a same public Internet protocol (IP) address of the cloud gateway.

16. The non-transitory machine readable medium of claim 15 , wherein the public IP address is the IP address of a gateway load balancer of the cloud gateway.

17. The non-transitory machine readable medium of claim 15 , wherein the first client device accesses the set of resources by accessing the public IP address assigned to the cloud gateway and does not connect to the set of resources by directly accessing an IP address associated with the set of resources, wherein the first client device securely connects to the set of resources over a virtual private network (VPN) via the first gateway.

18. The non-transitory machine readable medium of claim 11 , wherein the first and second gateways are configured to deny any inbound network traffic by default.

19. The non-transitory machine readable medium of claim 11 , wherein the first data message is forwarded to the edge device via a first link of a multilink bundle connecting the edge device to the first gateway, wherein if the first link of the multilink bundle fails, remaining links of the multilink bundle continue to provide access to the set of resources via the first gateway.

20. The non-transitory machine readable medium of claim 11 , wherein the first client device and the second client device are a same client device.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2025
From: VMWARE, LLC
To: VELOCLOUD NETWORKS, LLC
Reel/Frame 072326/0693 →
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
CORRECTIVE ASSIGNMENT TO CORRECT THE INADVERTENT DISCREPANCIES IN THE ASSIGNMENT PREVIOUSLY RECORDED ON REEL 044917 FRAME 0102. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT OF ASSIGNOR'S INTEREST. Recorded Jun 18, 2018
From: VELOCLOUD NETWORKS, LLC
To: NICIRA, INC.
Reel/Frame 046129/0882 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 13, 2018
From: VELOCLOUD NETWORKS, LLC
To: NICIRA, INC.
Reel/Frame 044917/0102 →
CHANGE OF NAME Recorded Jan 30, 2018
From: VELOCLOUD NETWORKS, INC.
To: VELOCLOUD NETWORKS, LLC
Reel/Frame 045195/0741 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 26, 2017
From: MAYYA, AJIT RAMACHANDRA; THAKORE, PARAG PRITAM; CONNORS, STEPHEN CRAIG; KOMPEL, ALEX; SPEETER, THOMAS HAROLD
To: VELOCLOUD NETWORKS, INC.
Reel/Frame 043106/0347 →
Continuity (3)
Continuation In Part 15097282 · Apr 12, 2016
Provisional Application 62146786 · Apr 13, 2015
Related Publication 20170237710A1 · Aug 17, 2017
Cited By (33)
US 12,218,800 US 12,218,845 US 12,237,990 US 12,250,114 US 12,261,777 US 12,267,364 US 12,316,524 US 12,335,131 US 12,355,655 US 12,368,676 US 12,375,403 US 12,401,544 US 12,425,332 US 12,425,335 US 12,425,347 US 12,425,395 US 12,483,968 US 12,489,672 US 12,506,678 US 12,507,120 US 12,507,148 US 12,507,153 US 12,526,183 US 12,549,465 US 12,563,438 US 12,568,039 US 12,587,468 US 12,603,827 US 12,603,848 US 12,632,330 US 12,652,217 US 12,659,719 US 12,719,782