IP Library Granted Patent US 10,469,529
Granted Patent B2
US 10,469,529 · App. 15/649,203 · Granted Nov 5, 2019

Address checking to protect against denial of service attack

Inventors: Hongya Qu (San Jose, CA); Timothy Petty (San Francisco, CA)
Assignee: Nicira, Inc.
H04L63/1458H04L12/4633H04L45/66H04L45/74H04L49/70H04L61/103H04L61/2007H04L63/029H04L63/0428H04L67/10H04L69/22H04L45/64H04L47/32H04L61/6022
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,469,529
App. No.
15/649,203
Granted
Nov 5, 2019
Kind
B2
Abstract

Certain embodiments described herein are generally directed to checking packets at a hardware tunnel endpoint. In some embodiments, an encapsulated packet is received at a hardware tunnel endpoint. It is determined if an inner source media access control (MAC) address is associated with an outer source internet protocol (IP) address of the encapsulated packet based on a mapping of MAC addresses of virtual computing instances to IP addresses of tunnel endpoints stored at the hardware tunnel endpoint. If it is determined the inner source MAC address is not associated with the outer source IP address, the packet is dropped.

Claims (38)

1. A method for checking packets at a hardware tunnel endpoint, the method comprising:

receiving, at the hardware tunnel endpoint from a controller, information regarding a mapping of media access control (MAC) addresses of virtual computing instances to internet protocol (IP) addresses of tunnel endpoints;

receiving, at the hardware tunnel endpoint, an encapsulated packet, the encapsulated packet comprising an outer header comprising an outer destination IP address and an outer source IP address, and an inner header comprising an inner source MAC address;

determining, at the hardware tunnel endpoint, if the inner source MAC address is associated with the outer source IP address based on the mapping stored at the hardware tunnel endpoint;

dropping, at the hardware tunnel endpoint, the packet if it is determined the inner source MAC address is not associated with the outer source IP address; and

forwarding, by the hardware tunnel endpoint, the packet based on the inner header if it is determined the inner source MAC address is associated with the outer source IP address.

2. The method of claim 1 , wherein the mapping is further associated with a network identifier, wherein the network identifier is included in the encapsulated packet.

3. The method of claim 1 , further comprising:

determining, at the hardware tunnel endpoint, if the outer source IP address is valid based on a list of IP addresses of tunnel endpoints stored at the hardware tunnel endpoint; and

dropping, at the hardware tunnel endpoint, the packet if it is determined the outer source IP address is not valid and not performing determining if the inner source MAC address is associated with the outer source IP.

4. The method of claim 1 , wherein forwarding the packet comprises decapsulating the encapsulated packet to retrieve an inner packet and forwarding the inner packet.

5. The method of claim 1 , wherein the mapping is for virtual computing instances associated with a logical layer-2 network identified by a network identifier included in the encapsulated packet.

6. The method of claim 5 , wherein the hardware tunnel endpoint is part of the logical layer-2 network.

7. A non-transitory computer readable medium comprising instructions to be executed in a computer system, wherein the instructions when executed in the computer system perform a method for checking packets at a hardware tunnel endpoint, the method comprising:

receiving, at the hardware tunnel endpoint from a controller, information regarding a mapping of media access control (MAC) addresses of virtual computing instances to internet protocol (IP) addresses of tunnel endpoints;

receiving, at the hardware tunnel endpoint, an encapsulated packet, the encapsulated packet comprising an outer header comprising an outer destination IP address and an outer source IP address, and an inner header comprising an inner source MAC address;

determining, at the hardware tunnel endpoint, if the inner source MAC address is associated with the outer source IP address based on the mapping stored at the hardware tunnel endpoint;

dropping, at the hardware tunnel endpoint, the packet if it is determined the inner source MAC address is not associated with the outer source IP address; and

forwarding, by the hardware tunnel endpoint, the packet based on the inner header if it is determined the inner source MAC address is associated with the outer source IP address.

8. The non-transitory computer readable medium of claim 7 , wherein the mapping is further associated with a network identifier, wherein the network identifier is included in the encapsulated packet.

9. The non-transitory computer readable medium of claim 7 , wherein the method further comprises:

determining, at the hardware tunnel endpoint, if the outer source IP address is valid based on a list of IP addresses of tunnel endpoints stored at the hardware tunnel endpoint; and

dropping, at the hardware tunnel endpoint, the packet if it is determined the outer source IP address is not valid and not performing determining if the inner source MAC address is associated with the outer source IP.

10. The non-transitory computer readable medium of claim 7 , wherein forwarding the packet comprises decapsulating the encapsulated packet to retrieve an inner packet and forwarding the inner packet.

11. The non-transitory computer readable medium of claim 7 , wherein the mapping is for virtual computing instances associated with a logical layer-2 network identified by a network identifier included in the encapsulated packet.

12. The non-transitory computer readable medium of claim 11 , wherein the hardware tunnel endpoint is part of the logical layer-2 network.

13. A computer system, wherein system software for the computer system is programmed to execute a method for checking packets at a hardware tunnel endpoint, said method comprising:

receiving, at the hardware tunnel endpoint from a controller, information regarding a mapping of media access control (MAC) addresses of virtual computing instances to internet protocol (IP) addresses of tunnel endpoints;

receiving, at the hardware tunnel endpoint, an encapsulated packet, the encapsulated packet comprising an outer header comprising an outer destination IP address and an outer source IP address, and an inner header comprising an inner source MAC address;

determining, at the hardware tunnel endpoint, if the inner source MAC address is associated with the outer source IP address based on the mapping stored at the hardware tunnel endpoint;

dropping, at the hardware tunnel endpoint, the packet if it is determined the inner source MAC address is not associated with the outer source IP address; and

forwarding, by the hardware tunnel endpoint, the packet based on the inner header if it is determined the inner source MAC address is associated with the outer source IP address.

14. The computer system of claim 13 , wherein the mapping is further associated with a network identifier, wherein the network identifier is included in the encapsulated packet.

15. The computer system of claim 13 , wherein the method further comprises:

determining, at the hardware tunnel endpoint, if the outer source IP address is valid based on a list of IP addresses of tunnel endpoints stored at the hardware tunnel endpoint; and

dropping, at the hardware tunnel endpoint, the packet if it is determined the outer source IP address is not valid and not performing determining if the inner source MAC address is associated with the outer source IP.

16. The computer system of claim 13 , wherein forwarding the packet comprises decapsulating the encapsulated packet to retrieve an inner packet and forwarding the inner packet.

17. The computer system of claim 13 , wherein the mapping is for virtual computing instances associated with a logical layer-2 network identified by a network identifier included in the encapsulated packet.

Assignments (2)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2017
From: QU, HONGYA; PETTY, TIMOTHY
To: NICIRA, INC.
Reel/Frame 043311/0839 →
Continuity (1)
Related Publication 20190020679A1 · Jan 17, 2019
Cited By (1)
US 12,640,955