IP Library Granted Patent US 10,567,281
Granted Patent B2
US 10,567,281 · App. 15/690,231 · Granted Feb 18, 2020

Stateful connection optimization over stretched networks using packet introspection

Inventors: Weiqing Wu (Cupertino, CA); Aravind Srinivasan (Santa Clara, CA); Leon Cui (Beijing, CN); Todd Sabin (Morganville, NJ); Serge Maskalik (Los Gatos, CA); Sachin Thakkar (San Jose, CA)
Assignee: VMware, Inc.
H04L45/74G06F9/45558G06F9/5077H04L12/462H04L41/083H04L41/0816H04L45/38H04L45/64H04L45/745H04L47/122H04L47/365H04L49/70H04L61/103H04L61/2007H04L61/6022H04L67/2814G06F2009/4557G06F2009/45595H04L41/5096H04L45/66H04L67/101H04L67/1031
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,567,281
App. No.
15/690,231
Granted
Feb 18, 2020
Kind
B2
Abstract

Techniques for stateful connection optimization over stretched networks are disclosed. In one embodiment, hypervisor filtering modules in a cloud computing system are configured to modify packets sent by virtual computing instances (e.g., virtual machines (VMs)) in the cloud to local destinations in the cloud such that those packets have the destination Media Access Control (MAC) address of a local router that is also in the cloud. Doing so prevents tromboning traffic flows in which packets sent by virtual computing instances in the cloud to location destinations are routed to a stretched network's default gateway that is not in the cloud.

Claims (31)

1. A computer-implemented method of optimizing connections over an extended network that spans a first computing system and a second computing system, the first computing system comprising a first plurality of virtual computing instances running on a first plurality of physical hosts and a first router, the second computing system comprising a second plurality of virtual computing instances running on a second plurality of physical hosts and a second router, wherein the second router is configured as a default gateway for the extended network including the first plurality of virtual computing instances and the second plurality of virtual computing instances, comprising:

configuring hypervisor filters in the first plurality of physical hosts with information indicating Internet protocol (IP) addresses of the first plurality of virtual computing instances that are local to the first computing system; and

configuring the hypervisor filters with at least one traffic filtering rule to divert packets having destination IP addresses of the first plurality of virtual computing instances that are local to the first computing system to the first router,

wherein, based on the at least one traffic filtering rule, the configured hypervisor filters:

receive packets which are sent by the first plurality of virtual computing instances, each packet including a destination IP address of at least one of the first plurality of virtual computing instances that are local to the first computing system and a destination media access control (MAC) address of the second router that is not local to the first computing system; and

modify the packets to include the destination MAC address of the first router that is local to the first computing system so the packets are forwarded to the first router in the first computing system instead of the second router in the second computing system that is configured as the default gateway.

2. The method of claim 1 , further comprising, responsive to determining a virtual computing instance has moved from the second computing system to the first computing system, configuring the hypervisor filters in the first plurality of physical hosts with additional information indicating the IP address of the moved virtual computing instance that is local to the first computing system.

3. The method of claim 1 , wherein the hypervisor filters are configured by a management application which maintains an inventory of virtual computing instances and networks that are local to the first computing system.

4. The method of claim 1 , wherein packets with destinations that are not local to the first computing system are routed to the second router configured as the default gateway.

5. The method of claim 1 , wherein at least one of the hypervisor filters imposes on a input output (I/O) path between a virtual network interface card (VNIC) of one of the first plurality of virtual computing instances and a port of a virtual switch.

6. The method of claim 1 , wherein the first computing system is one of a cloud computing system and an on-premise virtualized computing system.

7. A non-transitory computer-readable storage medium containing a program which, when executed by one or more processors, performs operations for optimizing connections over an extended network that spans a first computing system and a second computing system, the first computing system comprising a first plurality of virtual computing instances running on a first plurality of physical hosts and a first router, the second computing system comprising a second plurality of virtual computing instances running on a second plurality of physical hosts and a second router, wherein the second router is configured as a default gateway for the extended network including the first plurality of virtual computing instances and the second plurality of virtual computing instances, the operations comprising:

configuring hypervisor filters in the first plurality of physical hosts with information indicating Internet protocol (IP) addresses of the first plurality of virtual computing instances that are local to the first computing system; and

configuring the hypervisor filters with at least one traffic filtering rule to divert packets having destination IP addresses of the first plurality of virtual computing instances that are local to the first computing system to the first router,

wherein, based on the at least one traffic filtering rule, the configured hypervisor filters:

receive packets which are sent by the first plurality of virtual computing instances, each packet including a destination IP address of at least one of the first plurality of virtual computing instances that are local to the first computing system and a destination media access control (MAC) address of the second router that is not local to the first computing system; and

modify the packets to include the destination MAC address of the first router that is local to the first computing system so the packets are forwarded to the first router in the first computing system instead of the second router in the second computing system that is configured as the default gateway.

8. The computer-readable storage medium of claim 7 , the operations further comprising, responsive to determining a virtual computing instance has moved from the second computing system to the first computing system, configuring the hypervisor filters in the first plurality of physical hosts with additional information indicating the IP address of the moved virtual computing instance that is local to the first computing system.

9. The computer-readable storage medium of claim 7 , wherein the hypervisor filters are configured by a management application which maintains an inventory of virtual computing instances and networks that are local to the first computing system.

10. The computer-readable storage medium of claim 7 , wherein packets with destinations that are not local to the first computing system are routed to the second router configured as the default gateway.

11. The computer-readable storage medium of claim 7 , wherein at least one of the hypervisor filters imposes on a input output (I/O) path between a virtual network interface card (VNIC) of one of the first plurality of virtual computing instances and a port of a virtual switch.

12. The computer-readable storage medium of claim 7 , wherein the first computing system is one of a cloud computing system and an on-premise virtualized computing system.

13. A system, comprising:

a processor; and

a memory, wherein the memory includes a program executable in the processor to perform operations for optimizing connections over an extended network that spans a first computing system and a second computing system, the first computing system comprising a first plurality of virtual computing instances running on a first plurality of physical hosts and a first router, the second computing system comprising a second plurality of virtual computing instances running on a second plurality of physical hosts and a second router, wherein the second router is configured as a default gateway for the extended network including the first plurality of virtual computing instances and the second plurality of virtual computing instances, the operations comprising:

configuring hypervisor filters in the first plurality of physical hosts with information indicating Internet protocol (IP) addresses of the first plurality of virtual computing instances that are local to the first computing system; and

configuring the hypervisor filters with at least one traffic filtering rule to divert packets having destination IP addresses of the first plurality of virtual computing instances that are local to the first computing system to the first router,

wherein, based on the at least one traffic filtering rule, the configured hypervisor filters:

receive packets which are sent by the first plurality of virtual computing instances, each packet including a destination IP address of at least one of the first plurality of virtual computing instances that are local to the first computing system and a destination media access control (MAC) address of the second router that is not local to the first computing system; and

modify the packets to include the destination MAC address of the first router that is local to the first computing system so the packets are forwarded to the first router in the first computing system instead of the second router in the second computing system that is configured as the default gateway.

14. The system of claim 13 , the operations further comprising, responsive to determining a virtual computing instance has moved from the second computing system to the first computing system, configuring the hypervisor filters in the first plurality of physical hosts with additional information indicating the IP address of the moved virtual computing instance that is local to the first computing system.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 2, 2018
From: WU, WEIQING; SRINIVASAN, ARAVIND; CUI, LEON; SABIN, TODD; MASKALIK, SERGE; THAKKAR, SACHIN
To: VMWARE, INC.
Reel/Frame 045690/0549 →
Continuity (2)
Provisional Application 62380991 · Aug 29, 2016
Related Publication 20180063000A1 · Mar 1, 2018