IP Library Granted Patent US 11,288,088
Granted Patent B2
US 11,288,088 · App. 16/444,964 · Granted Mar 29, 2022

Service control plane messaging in service data plane

Inventors: Pierluigi Rolando (Santa Clara, CA); Kantesh Mundaragi (Pune, IN); Rahul Mishra (Mountain View, CA); Jayant Jain (Cupertino, CA); Raju Koganty (San Jose, CA)
Assignee: VMWARE, INC.
G06F9/45558G06F9/546H04L12/4633H04L41/0803H04L41/0816H04L41/5003H04L41/5054H04L45/26H04L45/308H04L45/38H04L45/586H04L45/66H04L45/74H04L45/745H04L47/125H04L47/17H04L47/19H04L47/2425H04L49/252H04L49/3009H04L61/2592H04L61/6022H04L67/10H04L67/101H04L67/1002H04L67/16H04L67/28H04L67/2814H04L67/32H04L69/321H04L69/324H04L69/325G06F2009/4557G06F2009/45595H04L41/0806H04L41/0893H04L2212/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,288,088
App. No.
16/444,964
Granted
Mar 29, 2022
Kind
B2
Abstract

Some embodiments provide novel methods for performing services for machines operating in one or more datacenters. For instance, for a group of related guest machines (e.g., a group of tenant machines), some embodiments define two different forwarding planes: (1) a guest forwarding plane and (2) a service forwarding plane. The guest forwarding plane connects to the machines in the group and performs L2 and/or L3 forwarding for these machines. The service forwarding plane (1) connects to the service nodes that perform services on data messages sent to and from these machines, and (2) forwards these data messages to the service nodes. In some embodiments, the guest machines do not connect directly with the service forwarding plane. For instance, in some embodiments, each forwarding plane connects to a machine or service node through a port that receives data messages from, or supplies data messages to, the machine or service node. In such embodiments, the service forwarding plane does not have a port that directly receives data messages from, or supplies data messages to, any guest machine. Instead, in some such embodiments, data associated with a guest machine is routed to a port proxy module executing on the same host computer, and this other module has a service plane port. This port proxy module in some embodiments indirectly can connect more than one guest machine on the same host to the service plane (i.e., can serve as the port proxy module for more than one guest machine on the same host).

Claims (35)

1. A method of performing a particular service operation on data messages, the method comprising:

at a particular service node that performs the particular service operation:

receiving, through a data plane implemented by at least one logical forwarding element that spans a plurality of computers, a data message on which the particular service operation has to be performed, the data message forwarded through the data plane by a source host computer that identified a set of service nodes to perform a set of service operations on the data message;

performing that particular service operation;

determining that the set of services have to be modified; and

outputting a control message to be forwarded in-band through the data plane in a data message back to the source host computer, in order to direct the source host computer to modify the performance of the set of services on other data messages in the flow.

2. The method of claim 1 , wherein the control message directs the source host computer to forego sending data messages that are part of the data message flow to the particular service node.

3. The method of claim 2 , wherein the control message directs the source host computer to either drop or allow all the data messages that are part of the data message flow without further processing by the particular service node.

4. The method of claim 1 , wherein the control message directs the source host computer to forego sending data messages that are part of the data message flow to the set of service nodes.

5. The method of claim 2 , wherein the control message directs the source host computer to either drop or allow all the data messages that are part of the data message flow without further processing by the set of service nodes.

6. The method of claim 1 , wherein the control message directs the source host computer to send data messages that are part of the data message flow to another set of service nodes that does not include the particular service node.

7. The method of claim 6 , wherein the other set of service nodes performs the same set of services on the data messages.

8. The method of claim 6 , wherein the other set of service nodes performs another set of services on the data messages.

9. The method of claim 1 , wherein the received data message comprises a first service path identifier that identifies a first service path that specifies the set of service nodes, wherein determining that the set of services have to be modified comprises:

generating a second service path identifier to specify another set of service nodes for processing the data message; and

providing the second service path identifier to be forwarded along with the data message.

10. The method of claim 1 , wherein the received first data message comprises a first service chain identifier that identifies the set of services, wherein determining that the set of services have to be modified comprises:

generating a second chain identifier to specify another set of service for processing the data message; and

providing the second service chain identifier to be forwarded along with the data message.

11. A non-transitory machine readable medium storing a particular service node for execution by at least one processing unit and for performing a particular service operation for data messages associated with a machine executing on a host computer, the particular service node comprising sets of instructions for:

receiving a data message on which the particular service operation has to be performed, the data message forwarded through a data plane by a source host computer that identified a set of service nodes to perform a set of service operations on the data message;

performing that particular service operation;

determining that the set of services have to be modified; and

outputting a control message to be forwarded in-band in a data message back to the source host computer through the data plane, in order to direct the source host computer to modify the performance of the set of services on other data messages in the flow.

12. The non-transitory machine readable medium of claim 11 , wherein the control message directs the source host computer to forego sending data messages that are part of the data message flow to the particular service node.

13. The non-transitory machine readable medium of claim 12 , wherein the control message directs the source host computer to either drop or allow all the data messages that are part of the data message flow without further processing by the particular service node.

14. The non-transitory machine readable medium of claim 11 , wherein the control message directs the source host computer to forego sending data messages that are part of the data message flow to the set of service nodes.

15. The non-transitory machine readable medium of claim 12 , wherein the control message directs the source host computer to either drop or allow all the data messages that are part of the data message flow without further processing by the set of service nodes.

16. The non-transitory machine readable medium of claim 11 , wherein the control message directs the source host computer to send data messages that are part of the data message flow to another set of service nodes that does not include the particular service node.

17. The non-transitory machine readable medium of claim 16 , wherein the other set of service nodes performs the same set of services on the data messages.

18. The non-transitory machine readable medium of claim 16 , wherein the other set of service nodes performs another set of services on the data messages.

19. The non-transitory machine readable medium of claim 11 , wherein the received data message comprises a first service path identifier that identifies a first service path that specifies the set of service nodes, wherein the set of instructions for determining that the set of services have to be modified comprises sets of instructions for:

generating a second service path identifier to specify another set of service nodes for processing the data message; and

providing the second service path identifier to be forwarded along with the data message.

20. The non-transitory machine readable medium of claim 11 , wherein the control message is included in an encapsulating header of the data message that is sent through the data plane back to the source host computer for a service insertion module executing on the source host computer to process.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2019
From: MUNDARAGI, KANTESH; MISHRA, RAHUL; ROLANDO, PIERLUIGI; JAIN, JAYANT; KOGANTY, RAJU
To: VMWARE, INC.
Reel/Frame 049508/0197 →
Cited By (1)
US 12,341,680