IP Library Granted Patent US 10,547,588
Granted Patent B2
US 10,547,588 · App. 15/421,183 · Granted Jan 28, 2020

Method of translating a logical switch into a set of network addresses

Inventors: Kaushal Bansal (Pleasanton, CA); Uday Masurekar (Sunnyvale, CA)
Assignee: NICIRA, INC.
H04L61/2061H04L61/2015H04L61/2507H04L61/2521H04L61/6068
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,547,588
App. No.
15/421,183
Granted
Jan 28, 2020
Kind
B2
Abstract

A method of providing a set of network addresses associated with a managed forwarding element (MFE) in a logical network that includes a set of data compute nodes (DCNs). The DCNs are hosted on a set of physical hosts. Each DCN is connected to an MFE on the corresponding host. The method receives a request to translate an MFE into a set of network addresses, the request comprising an identification of the MFE. The method identifies a logical network entity associated with the MFE based on the identification of the MFE. The method identifies a set of network addresses associated with the identified network entity and provides the set of network addresses as the set of network addresses associated with the identified network entity.

Claims (28)

1. A method of specifying rules for processing packets associated with a logical network implemented by forwarding elements executing on a plurality of host computers, the method comprising:

receiving a request to provide a set of network addresses associated with a logical entity in the logical network, the request comprising an identification of the logical entity for which a spoof guard policy is configured;

determining whether the logical entity is associated with a subnet of network addresses by identifying a subnet associated with the spoof guard policy; and

in response to the request for the set of network addresses:

when the logical entity is associated with the subnet of network addresses, providing the subnet of network addresses associated with the logical entity; and

when the logical entity is not associated with the subnet of network addresses, providing a list of one or more individual network addresses,

said provided network addresses for processing packets associated with the logical entity.

2. The method of claim 1 , wherein the subnet of network addresses are a subnet of Internet protocol (IP) addresses.

3. The method of claim 1 , wherein the network is stretched across a plurality of datacenters.

4. A non-transitory computer readable medium storing a program for specifying rules for processing packets associated with a logical network implemented by forwarding elements executing on a plurality of host computers, the program executable by a processing unit, the program comprising a set of instructions for:

receiving a request to provide a set of network addresses associated with a logical entity in the logical network, the request comprising an identification of the logical entity for which a spoof guard policy is configured;

determining whether the logical entity is associated with a subnet of network addresses by identifying a subnet associated with the spoof guard policy; and

in response to the request for the set of network addresses:

when the logical entity is associated with the subnet of network addresses, providing the subnet of network addresses associated with the logical entity; and

when the logical entity is not associated with the subnet of network addresses, providing a list of one or more individual network addresses,

said provided network addresses for processing packets associated with the logical entity.

5. The non-transitory computer readable medium of claim 2 , wherein the subnet of network addresses are a subnet of Internet protocol (IP) addresses.

6. The non-transitory computer readable medium of claim 2 , wherein the network is stretched across a plurality of datacenters.

7. A system comprising:

a set of processing units; and

a non-transitory computer readable medium storing a program for specifying rules for processing packets associated with a logical network implemented by forwarding elements executing on a plurality of host computers, the program executable by one of the processing unit, the program comprising a set of instructions for:

receiving a request to provide a set of network addresses associated with a logical entity in the logical network, the request comprising an identification of the logical entity for which a spoof guard policy is configured;

determining whether the logical entity is associated with a subnet of network addresses by identifying a subnet associated with the spoof guard policy; and

in response to the request for the set of network addresses:

when the logical entity is associated with the subnet of network addresses, providing the subnet of network addresses associated with the logical entity; and

when the logical entity is not associated with the subnet of network addresses, providing a list of one or more individual network addresses,

said provided network addresses for processing packets associated with the logical entity.

8. The system of claim 7 , wherein the subnet of network addresses are a subnet of Internet protocol (IP) addresses.

Assignments (2)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2017
From: BANSAL, KAUSHAL; MASUREKAR, UDAY
To: NICIRA, INC.
Reel/Frame 041138/0531 →
Continuity (2)
Provisional Application 62330130 · Apr 30, 2016
Related Publication 20170317972A1 · Nov 2, 2017