IP Library Granted Patent US 10,237,090
Granted Patent B2
US 10,237,090 · App. 15/462,614 · Granted Mar 19, 2019

Rule-based network identifier mapping

Inventor: Ramakanth Josyula (Bangalore, IN)
Assignee: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
H04L12/4633H04L12/4641
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,237,090
App. No.
15/462,614
Granted
Mar 19, 2019
Kind
B2
Abstract

One embodiment of the present invention provides a switch. The switch includes a storage device, a rule management module, a network identifier module, and a packet processor. During operation, the rule management module stores, in the storage device, a first mapping that maps a virtual network identifier of a tunnel to a rule for classifying traffic. The virtual network identifier identifies a virtualized network associated with the tunnel. The network identifier module generates, for a virtualization manager of a virtual machine, a control packet comprising a representation of the first mapping for a respective local end device. The network identifier module then obtains, from a notification packet from the virtualization manger, a second mapping that maps the virtual network identifier to an identifier of the virtual machine and an identifier of the tunnel.

Claims (40)

1. A switch, comprising:

a storage device;

rule management circuitry configured to store, in the storage device, a first mapping that maps a virtual network identifier of a tunnel to a rule for classifying traffic, wherein the virtual network identifier identifies a virtualized network associated with the tunnel;

network identifier circuitry configured to:

generate, for a virtualization manager of a virtual machine, a control packet comprising a representation of the first mapping for a respective local end device; and

obtain, from a notification packet from the virtualization manger, a second mapping that maps the virtual network identifier to an identifier of the virtual machine and an identifier of the tunnel.

2. The switch of claim 1 , further comprising a packet processor configured to:

encapsulate a packet destined to the virtual machine with an encapsulation header; and

incorporate the virtual network identifier in the encapsulation header based on the second mapping.

3. The switch of claim 1 , further comprising tunnel management circuitry configured to operate the switch as a tunnel endpoint for the tunnel, wherein the switch is associated with an Internet Protocol (IP) address assigned to the tunnel endpoint.

4. The switch of claim 3 , wherein the tunnel endpoint operates based on a tunneling protocol, and wherein the tunneling protocol is one of; virtual extensible LAN (VXLAN), generic routing encapsulation (GRE), network virtualization using GRE (NVGRE), layer-2 tunneling protocol (L2TP), and multi-protocol label switching (MPLS).

5. The switch of claim 1 , wherein the role is based on one or more of: a flow definition, a flow identifier assigned to a flow defined by a flow definition, a media access control (MAC) address, an IP address, an IP subset, a customer VLAN tag, a service VLAN, and a global VLAN tag.

6. The switch of claim 5 , wherein the flow definition identifies a packet belonging to a flow, and wherein the flow definition is based on one or more of: a source MAC address of the packet, a destination MAC address of the packet, a source IP address of the packet, a destination IP address of the packet, an ingress port of the tunnel endpoint, and a transport protocol port.

7. The switch of claim 1 , wherein the switch is a member of a network of interconnected switches, which is identified based on a fabric identifier, wherein the network of interconnected switches operate as a tunnel endpoint for the tunnel.

8. The switch of claim 1 , wherein the virtual network identifier is a VXLAN network identifier (VNI).

9. A method, comprising:

storing, in local a storage device, a first mapping that maps a virtual network identifier of a tunnel to a rule for classifying traffic, wherein the virtual network identifier identifies a virtualized network associated with the tunnel;

generating, for a virtualization manager of a virtual machine, a control packet comprising a representation of the first mapping for a respective local end device; and

obtaining, from a notification packet from the virtualization manger, a second mapping that maps the virtual network identifier to an identifier of the virtual machine and an identifier of the tunnel.

10. The method, of claim 9 , further comprising:

encapsulating a packet destined to the virtual machine with an encapsulation header; and

incorporating the virtual network identifier in the encapsulation header based on the second mapping.

11. The method of claim 9 , further comprising operating the switch as a tunnel endpoint for the tunnel, wherein the switch is associated with an Internet Protocol (IP) address assigned to the tunnel endpoint.

12. The method of claim 11 , wherein the tunnel endpoint operates based on a tunneling protocol, and wherein the tunneling protocol is one of: virtual extensible LAN (VXLAN), generic routing encapsulation (GRE), network virtualization using GRE (NVGRE), layer-2 tunneling protocol (L2TP), and multi-protocol label switching (MPLS).

13. The method of claim 9 , wherein the rule is based on one or more of: a flow definition, a flow identifier assigned to a flow defined by a flow definition, a media access control (MAC) address, an IP address, an IP subnet, a customer VLAN tag, a service VLAN, and a global VLAN tag.

14. The method of claim 13 , wherein the flow definition identifies a packet belonging to a flow, and wherein the flow definition is based on one or more of:, a source MAC address of the packet, a destination MAC address of the packet, a source IP address of the packet, a destination IP address of the packet, an ingress port of the tunnel endpoint, and a transport protocol port.

15. The method of claim 9 , wherein the switch is a member of a network of interconnected switches, which is identified based on a fabric identifier, wherein the network of interconnected switches operate as a tunnel endpoint for the tunnel.

16. The method of claim 9 , wherein the virtual network identifier is a VXLAN network identifier (VNI).

17. A computer system; comprising;

a storage device;

a processor; and

a non-transitory computer-readable storage medium storing instructions which when executed by the processor causes the processor to perform a method, the method comprising:

storing, in the storage device, a first mapping that maps a virtual network identifier of a tunnel to a rule for classifying traffic, wherein the virtual network identifier identifies a virtualized network associated with the tunnel;

generating, for a virtualization manager of a virtual machine, a control packet comprising a representation of the first mapping for a respective local end device; and

obtaining, from a notification packet from the virtualization manger, a second mapping that maps the virtual network identifier to an identifier of the virtual machine and an identifier of the tunnel.

18. The computer system of claim 17 , wherein the method further comprises:

encapsulating a packet destined to the virtual machine with an encapsulation header; and

incorporating the virtual network identifier in the encapsulation header based on the second mapping.

19. The computer system of claim 18 , wherein the method further comprises operating the switch as a tunnel endpoint for the funnel, wherein the switch is associated with an Internet Protocol (IP) address assigned to the tunnel endpoint.

20. The computer system of claim 18 , wherein the rule is based on one or more of: a flow definition, a flow identifier assigned to a flow defined by a flow definition, a source MAC address, a source IP address, an IP subnet, a customer virtual area network (VLAN) tag, and a global VLAN tag.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2018
From: BROCADE COMMUNICATIONS SYSTEMS LLC
To: AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE. LIMITED
Reel/Frame 047270/0247 →
CHANGE OF NAME Recorded Dec 13, 2017
From: BROCADE COMMUNICATIONS SYSTEMS, INC.
To: BROCADE COMMUNICATIONS SYSTEMS LLC
Reel/Frame 044891/0536 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2017
From: JOSYULA, RAMAKANTH
To: BROCADE COMMUNICATIONS SYSTEMS, INC.
Reel/Frame 041647/0066 →
Continuity (2)
Provisional Application 62414585 · Oct 28, 2016
Related Publication 20180123827A1 · May 3, 2018