IP Library Granted Patent US 11,611,632
Granted Patent B2
US 11,611,632 · App. 15/343,139 · Granted Mar 21, 2023

Cloud to on-premise port forwarding with IP address bound to loopback alias

Inventors: Andrey Todorov Petrov (Sofia, BG); Martin Valkanov (Sofia, BG)
Assignee: NICIRA, INC.
H04L67/563H04L12/4633H04L61/256H04L61/2592H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,611,632
App. No.
15/343,139
Granted
Mar 21, 2023
Kind
B2
Abstract

An example method to provide communication between a first computer in a first computer network and a second computer in a second computer network is disclosed. The method includes aliasing the second computer's address in the second computer network to a loopback interface of a third computer in the first computer network and establishing a tunnel between the third computer and a fourth computer in the second computer network. Establishing the tunnel includes configuring the fourth computer to forward traffic received from the tunnel to the second computer. The method further includes configuring routing in the first computer network to direct traffic destined for the second computer network to the third computer, and configuring the first computer to transmit packets destined for the second computer with the second computer's address in the second computer network.

Claims (45)

1. A method to provide communication between a first computer in a first computer network and a second computer in a second computer network, the first computer network corresponding to at least part of a public cloud, comprising:

aliasing the second computer's address in the second computer network to a loopback interface of a third computer in the first computer network, wherein the second computer network corresponds to a private cloud protected by a firewall;

establishing a tunnel between the third computer and a fourth computer in the second computer network, wherein establishing the tunnel includes configuring the fourth computer to forward traffic received from the tunnel to the second computer;

configuring routing in the first computer network to direct traffic destined for the second computer network to the third computer; and

configuring the first computer to transmit packets destined for the second computer with the second computer's address in the second computer network.

2. The method of claim 1 , further comprising:

the first computer transmits a packet with the second computer's address in the second computer network;

the third computer receives the packet and sends the packet, via the loopback interface, to the tunnel; and

the fourth computer receives the packet from the tunnel and forwards the packet to the second computer.

3. The method of claim 1 , further comprising providing the second computer's address in the second computer network to the first computer.

4. The method of claim 1 , wherein the tunnel comprises a secure shell (SSH) tunnel, the third computer comprises a SSH server, the fourth computer comprises a SSH client.

5. The method of claim 1 , wherein the first computer network comprises a virtual private cloud in the public cloud.

6. The method of claim 1 , wherein the first computer, the second computer, the third computer, and the fourth computer are physical computers, virtual machines on physical host computers, or a combination of physical computers and virtual machines.

7. The method of claim 1 , wherein configuring routing in the first computer network comprising configuring a routing table of a router in the first computer network.

8. A non-transitory, computer-readable storage medium encoded with instructions executable by a processor to provide communication between a first computer in a first computer network and a second compute in a second computer, the first computer network corresponding to at least part of a public cloud, the instructions comprising:

aliasing the second computer's address in the second computer network to a loopback interface of a third computer in the first computer network, wherein the second computer network corresponds to a private cloud protected by a firewall;

establishing a tunnel between the third computer and a fourth computer in the second computer network, wherein establishing the tunnel includes configuring the fourth computer to forward traffic received from the tunnel to the second computer;

configuring routing in the first computer network to direct traffic destined for the second computer network to the third computer; and

configuring the first computer to transmit packets destined for the second computer with the second computer's address in the second computer network.

9. The storage medium of claim 8 , wherein the instructions further comprises:

the first computer transmits a packet with the second computer's address in the second computer network;

the third computer receives the packet and sends the packet, via the loopback interface, to the tunnel; and

the fourth computer receives the packet from the tunnel and forwards the packet to the second computer.

10. The storage medium of claim 8 , wherein the instructions further comprises providing the second computer's address in the second computer network to the first computer.

11. The storage medium of claim 8 , wherein the tunnel comprises a secure shell (SSH) tunnel, the third computer comprises a SSH server, the fourth computer comprises a SSH client.

12. The storage medium of claim 8 , wherein the first computer network comprises a virtual private cloud in the public cloud.

13. The storage medium of claim 8 , wherein the first computer, the second computer, the third computer, and the fourth computer are physical computers, virtual machines on physical host computers, or a combination of physical computers and virtual machines.

14. The storage medium of claim 8 , wherein configuring routing in the first computer network comprising configuring a routing table of a router in the first computer network.

15. A system for communication between a first computer in a first computer network and a second computer in a second computer network, the first computer network corresponding to at least part of a public cloud, comprising:

the first computer network, comprising:

the first computer configured to transmit packets destined for the second computer with the second computer's address in the second computer network, wherein the second computer network corresponds to a private cloud protected by a firewall;

a third computer configured with the second computer's address in the second computer network aliased on a loopback interface of the third computer; and

a router configured to direct traffic destined for the second computer network to the third computer; and

the second computer network comprising:

the second computer; and

a fourth configured with a tunnel to the third computer and to forward traffic received from to the tunnel second computer.

16. The system of claim 15 , wherein:

the first computer transmits a packet with the second computer's address in the second computer network;

the router directs the packet to the third computer;

the third computer sends the packet, via the loopback interface, to the tunnel; and

the fourth computer receives the packet from the tunnel and forwards the packet to the second computer.

17. The system of claim 15 , further comprising a fifth computer configured to receive the second machine's address from the second computer network and send the second computer's address to the first computer network.

18. The system of claim 15 , wherein the tunnel comprises a secure shell (SSH) tunnel, the third computer comprises a SSH server, the fourth computer comprises a SSH client.

19. The system of claim 15 , wherein the first computer network comprises a virtual private cloud in the public cloud.

20. The system of claim 15 , wherein the first computer, the second computer, the third computer, and the fourth computer are physical computers, virtual machines on physical host computers, or a combination of physical computers and virtual machines.

Assignments (2)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2016
From: PETROV, ANDREY TODOROV; VALKANOV, MARTIN
To: NICIRA, INC.
Reel/Frame 040218/0996 →
Continuity (1)
Related Publication 20180124198A1 · May 3, 2018