IP Library Granted Patent US 11,005,684
Granted Patent B2
US 11,005,684 · App. 15/972,083 · Granted May 11, 2021

Creating virtual networks spanning multiple public clouds

Inventors: Israel Cidon (San Francisco, CA); Chen Dar (Magshimim, IL); Prashanth Venugopal (San Francisco, CA)
Assignee: VMWARE, INC.
H04L12/4641H04L12/14H04L12/1403H04L12/1428H04L12/2854H04L12/2859H04L12/4633H04L41/0803H04L43/0829H04L43/0852H04L43/0888H04L45/04H04L45/12H04L45/14H04L45/64H04L45/74H04L45/745H04L61/1511H04L61/25H04L61/255H04L61/2514H04L61/305H04L63/0245H04L63/20H04L67/10H04M15/00H04M15/51H04L41/046H04L43/08H04L63/0263H04L63/0272H04L63/0281H04L2212/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,005,684
App. No.
15/972,083
Granted
May 11, 2021
Kind
B2
Abstract

Some embodiments establish for an entity a virtual network over several public clouds of several public cloud providers and/or in several regions. In some embodiments, the virtual network is an overlay network that spans across several public clouds to interconnect one or more private networks (e.g., networks within branches, divisions, departments of the entity or their associated datacenters), mobile users, and SaaS (Software as a Service) provider machines, and other web applications of the entity. The virtual network in some embodiments can be configured to optimize the routing of the entity's data messages to their destinations for best end-to-end performance, reliability and security, while trying to minimize the routing of this traffic through the Internet. Also, the virtual network in some embodiments can be configured to optimize the layer 4 processing of the data message flows passing through the network.

Claims (26)

1. A method of establishing a virtual network over a plurality of public cloud datacenters for a first entity, the method comprising:

receiving data from the first entity identifying a set of locations of machines of the first entity outside of the public cloud datacenters to connect;

configuring a set of forwarding elements, executing on a set of virtual machines that execute on a set of host computers, in first and second multi-tenant public cloud datacenters to implement a first virtual overlay wide area network (WAN) for the first entity, said first virtual overlay WAN (i) connecting each forwarding element to at least one other forwarding element through an overlay tunnel and (ii) spanning the first and second multi-tenant public cloud datacenters to connect the first entity's locations identified in the data received from the first entity, each of a plurality of the first entity's locations comprising a plurality of machines, wherein at least one of the forwarding elements in the set of forwarding elements is configured to establish a second virtual overlay WAN to connect a set of machines of a second entity outside of the public cloud datacenters; and

forwarding, through the first virtual overlay WAN, data messages between machines of the first entity that reside outside of the first and second multi-tenant public cloud datacenters, said forwarding using a tenant identifier identifying the first entity as a tenant that uses the set of forwarding elements that implement the first virtual overlay WAN over the first and second multi-tenant public cloud datacenters,

wherein each of the first and second multi-tenant public cloud datacenters comprises host computers executing machines of a plurality of tenants of the public cloud datacenter.

2. The method of claim 1 , wherein the set of machine locations of the first entity includes two or more office locations.

3. The method of claim 2 , wherein the set of machine locations of the first entity further includes at least one datacenter location.

4. The method of claim 3 , wherein the set of machine locations of the first entity further includes remote device locations.

5. The method of claim 1 , wherein the set of machine locations of the first entity includes an office location and a datacenter location.

6. The method of claim 5 , wherein the set of machine locations of the first entity further includes a location comprising a plurality of machines of a SaaS (Software as a Service) provider.

7. The method of claim 1 , wherein the machines include at least one of virtual machines, containers, or standalone computers.

8. The method of claim 1 , wherein:

configuring the set of forwarding elements comprises configuring the set of forwarding elements to use a set of overlay virtual WAN headers to encapsulate data messages exchanged between the first entity machines in different machine locations; and

the set of overlay virtual WAN headers storing the tenant identifier identifying the first entity.

9. The method of claim 1 further comprising:

using a set of one or more controllers of a virtual network provider to deploy forwarding elements in the first and second multi-tenant public cloud datacenters; and

wherein the configuring of the set of forwarding elements comprises using the set of one or more controllers of the virtual network provider to configure the set of forwarding elements with next-hop forwarding rules that establish the overlay WAN, the virtual network provider deploying different virtual WANs for different entities over public cloud datacenters of different public cloud providers and in different regions.

10. The method of claim 1 , wherein the set of forwarding elements comprises a plurality of software forwarding elements executing on virtual machines.

11. The method of claim 1 , wherein at least a subset of virtual machines on which the plurality of software forwarding elements execute on host computers along with other machines.

12. A non-transitory machine readable medium storing a program for establishing virtual networks over a plurality of public cloud datacenters, the program for execution by at least one hardware processing unit, the program comprising sets of instructions for:

receiving data from the first entity identifying a set of locations of machines of the first entity outside of the public cloud datacenters to connect;

configuring a set of forwarding elements, executing on a set of virtual machines that execute on a set of host computers, in first and second multi-tenant public cloud datacenters to implement a first virtual overlay wide area network (WAN) for the first entity, said first virtual overlay WAN (i) connecting each forwarding element to at least one other forwarding element through an overlay tunnel and (ii) spanning the first and second multi-tenant public cloud datacenters to connect the first entity's locations identified in the data received from the first entity, each of a plurality of the first entity's locations comprising a plurality of machines, wherein at least one of the forwarding elements in the set of forwarding elements is configured to establish a second virtual overlay WAN to connect a set of machines of a second entity outside of the public cloud datacenters; and

forwarding, through the first virtual overlay WAN, data messages between machines of the first entity that reside outside of the first and second multi-tenant public cloud datacenters, said forwarding using a tenant identifier identifying the first entity as a tenant that uses the set of forwarding elements that implement the first virtual overlay WAN over the first and second multi-tenant public cloud datacenters,

wherein each of the first and second multi-tenant public cloud datacenters comprises host computers executing machines of a plurality of tenants of the public cloud datacenter.

13. The non-transitory machine readable medium of claim 12 , wherein the set of machine locations of the first entity includes at least one office location, one datacenter location and a plurality of remote user locations.

14. The non-transitory machine readable medium of claim 13 , wherein the set of machine locations of the first entity further includes a location comprising a plurality of machines of a SaaS (Software as a Service) provider.

Assignments (3)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2019
From: NICIRA, INC.
To: VMWARE, INC.
Reel/Frame 049743/0073 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2019
From: CIDON, ISRAEL; DAR, CHEN; VENUGOPAL, PRASHANTH
To: NICIRA, INC.
Reel/Frame 048732/0924 →
Continuity (2)
Provisional Application 62566524 · Oct 2, 2017
Related Publication 20190103990A1 · Apr 4, 2019
Cited By (33)
US 12,218,800 US 12,218,845 US 12,237,990 US 12,250,114 US 12,261,777 US 12,267,364 US 12,316,524 US 12,335,131 US 12,355,655 US 12,368,676 US 12,375,403 US 12,401,544 US 12,425,332 US 12,425,335 US 12,425,347 US 12,425,395 US 12,483,968 US 12,489,672 US 12,506,678 US 12,507,120 US 12,507,148 US 12,507,153 US 12,526,183 US 12,549,465 US 12,563,438 US 12,568,039 US 12,587,468 US 12,603,827 US 12,603,848 US 12,632,330 US 12,652,217 US 12,659,719 US 12,719,782