IP Library Granted Patent US 10,310,886
Granted Patent B2
US 10,310,886 · App. 15/398,709 · Granted Jun 4, 2019

Network control system for configuring middleboxes

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,310,886
App. No.
15/398,709
Granted
Jun 4, 2019
Kind
B2
Abstract

Some embodiments provide a method for configuring a logical middlebox in a hosting system that includes a set of nodes. The logical middlebox is part of a logical network that includes a set of logical forwarding elements that connect a set of end machines. The method receives a set of configuration data for the logical middlebox. The method uses a stored set of tables describing physical locations of the end machines to identify a set of nodes at which to implement the logical middlebox. The method provides the logical middlebox configuration for distribution to the identified nodes.

Claims (26)

1. A method for performing middlebox operations on a host computer executing a middlebox element having a plurality of middlebox instances and a plurality of end machines, the method comprising:

receiving a data packet from a managed forwarding element via a software port between the managed forwarding element and the middlebox element having the plurality of middlebox instances, wherein the managed forwarding element executes on the host computer to implement a plurality of logical networks;

based on a tag that the managed forwarding element associated with the data packet, selecting from the plurality of middlebox instances a particular middlebox instance associated with the tag;

using the selected middlebox instance to perform a middlebox operation on the received packet; and

sending the processed data packet to the managed forwarding element.

2. The method of claim 1 , wherein the tag identifies the particular middlebox instance, wherein the particular middlebox instance is associated with a particular logical network.

3. The method of claim 2 , wherein the managed forwarding element received the data packet from a particular end machine associated with the particular logical network, wherein the managed forwarding element selected the tag based on the particular logical network associated with the data packet.

4. The method of claim 1 , wherein the tag is prepended to the data packet by the managed forwarding element.

5. The method of claim 1 , wherein selecting the particular middlebox instance comprises mapping the tag to the particular middlebox instance using a binding table.

6. The method of claim 1 , wherein sending the processed data packet to the managed forwarding element comprises sending the processed packet with the tag.

7. The method of claim 1 , wherein the managed forwarding element sent the data packet to the middlebox element according to a routing policy that routes the data packet based on a data field other than a destination network address of the data packet.

8. The method of claim 7 , wherein the data field is an ingress port through which the data packet was received.

9. The method of claim 7 , wherein the managed forwarding element receives the processed data packet and subsequently routes the processed data packet based on the destination network address of the processed data packet.

10. A non-transitory machine readable medium storing a program for performing middlebox operations on a host computer executing a middlebox element having a plurality of middlebox instances and a plurality of end machines, the program comprising sets of instructions for:

receiving a data packet from a managed forwarding element via a software port between the managed forwarding element and the middlebox element having the plurality of middlebox instances, wherein the managed forwarding element executes on the host computer to implement a plurality of logical networks;

based on a tag that the managed forwarding element associated with the data packet, selecting from the plurality of middlebox instances a particular middlebox instance associated with the tag;

using the selected middlebox instance to perform a middlebox operation on the received packet; and

sending the processed data packet to the managed forwarding element.

11. The non-transitory machine readable medium of claim 10 , wherein the tag identifies the particular middlebox instance, wherein the particular middlebox instance is associated with a particular logical network.

12. The non-transitory machine readable medium of claim 11 , wherein the managed forwarding element received the data packet from a particular end machine associated with the particular logical network, wherein the managed forwarding element selected the tag based on the particular logical network associated with the data packet.

13. The non-transitory machine readable medium of claim 10 , wherein the tag is prepended to the data packet by the managed forwarding element.

14. The non-transitory machine readable medium of claim 10 , wherein the set of instructions for selecting the particular middlebox instance comprises a set of instructions for mapping the tag to the particular middlebox instance using a binding table.

15. The non-transitory machine readable medium of claim 10 , wherein the set of instructions for sending the processed data packet to the managed forwarding element comprises a set of instructions for sending the processed packet with the tag.

16. The non-transitory machine readable medium of claim 10 , wherein the managed forwarding element sent the data packet to the middlebox element according to a routing policy that routes the data packet based on a data field other than a destination network address of the data packet.

17. The non-transitory machine readable medium of claim 16 , wherein the data field is an ingress port through which the data packet was received, wherein the managed forwarding element receives the processed data packet from the middlebox element and subsequently routes the processed data packet based on the destination network address of the processed data packet.

18. The non-transitory machine readable medium of claim 10 , wherein the plurality of logical middleboxes are one of firewalls, network address translators, and load balancers.

Assignments (1)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
Cited By (1)
US 12,541,385