IP Library Granted Patent US 11,095,480
Granted Patent B2
US 11,095,480 · App. 16/573,874 · Granted Aug 17, 2021

Traffic optimization using distributed edge services

Inventors: Vijai Coimbatore Natarajan (San Jose, CA); Harish Manoharan (San Jose, CA)
Assignee: VMWARE, INC.
H04L12/66H04L12/4633H04L41/0806H04L41/0893H04L47/125H04L47/20H04L63/0254H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,095,480
App. No.
16/573,874
Granted
Aug 17, 2021
Kind
B2
Abstract

Some embodiments provide a novel method for configuring managed forwarding elements (MFEs) to handle data messages for multiple logical networks that are implemented in a data center at the MFEs and to provide gateway service processing (e.g., firewall, DNS, etc.). A controller, in some embodiments, identifies logical networks implemented in the datacenter and MFEs available to provide gateway service processing and assigns gateway service processing for each logical network to a particular MFE. The MFEs, in some embodiments, receive data messages from endpoints in the logical networks that are destined for an external network. In some embodiments, the MFEs identify that the data messages require gateway service processing before being sent to the external network. The MFEs, in some embodiments, identify a particular MFE that is assigned to provide the gateway service processing for logical networks associated with the data messages.

Claims (31)

1. A method of processing data messages at a first managed forwarding element (MFE) in a datacenter, wherein a plurality of logical networks are implemented in the datacenter, the method comprising:

at the first MFE, receiving a data message from an endpoint of a particular logical network, the data message destined for an external network;

identifying that the data message requires gateway service processing before being sent to the external network;

identifying a particular MFE assigned to provide the gateway service processing for the identified logical network, wherein different MFEs that are connected to endpoints of the plurality of logical networks are assigned to provide the gateway service processing for the different logical networks; and

when the particular MFE is the first MFE, providing the gateway service processing for the data message and forwarding the data message to a datacenter router that provides access to the external network, wherein if the particular MFE is a second MFE, the first MFE forwards the data message to the second MFE for the second MFE to perform the gateway service processing and forward the data message to the datacenter router.

2. The method of claim 1 , wherein the endpoint of the particular logical network executes on a same host computer as the MFE that receives the data message.

3. The method of claim 1 , wherein the first MFE executes in a first datacenter and the external network is a second datacenter.

4. The method of claim 3 , wherein the first and second datacenters are connected through a direct connection that does not require network address translation.

5. The method of claim 1 , wherein a return data message from the external network to the particular logical network is returned to the MFE that provides the gateway service processing for the particular logical network.

6. The method of claim 1 , wherein a set of logical networks in the plurality of logical networks are each assigned a MFE in a plurality of MFEs to provide gateway service processing for the logical network.

7. The method of claim 6 , wherein at least one MFE is assigned to provide gateway service processing for multiple logical networks.

8. The method of claim 6 , wherein the gateway service processing for the logical networks is assigned based on a load balancing operation.

9. The method of claim 8 , wherein the load balancing operation is based on a capacity of each MFE in the plurality of MFEs.

10. The method of claim 6 , wherein the set of logical networks comprises at least one logical network that requires stateful gateway service processing.

11. The method of claim 6 , wherein a controller computer determines the assignment of the gateway service processing for the different logical networks.

12. The method of claim 1 , wherein forwarding the data message to the second MFE comprises tunneling the data message to the second MFE.

13. The method of claim 1 , wherein the second MFE executes on a second host computer along with at least one other endpoint of the logical network.

14. The method of claim 1 , wherein the second MFE is an edge node that provides stateful gateway service processing for the particular logical network.

15. The method of claim 1 , wherein identifying a particular MFE assigned to provide the gateway service processing comprises using a policy-based routing entry to identify the particular MFE.

16. A non-transitory machine readable medium storing a program for execution by a set of processing units, the program for processing data messages at a first managed forwarding element (MFE) in a datacenter, wherein a plurality of logical networks are implemented in the datacenter, the program comprising sets of instruction for:

at the first MFE, receiving a data message from an endpoint of a particular logical network, the data message destined for an external network;

identifying that the data message requires gateway service processing before being sent to the external network;

identifying a particular MFE assigned to provide the gateway service processing for the identified logical network, wherein different MFEs that are connected to endpoints of the plurality of logical networks are assigned to provide the gateway service processing for the different logical networks;

when the particular MFE is the first MFE, providing the gateway service processing for the data message and forwarding the data message to a datacenter router that provides access to the external network; and

when the particular MFE is a second MFE, forwarding the data message to the second MFE for the second MFE to perform the gateway service processing and forward the data message to the datacenter router.

17. The non-transitory machine readable medium of claim 16 , wherein

the first MFE executes in a first datacenter and the external network is a second datacenter, and

the first and second datacenters are connected through a direct connection that does not require network address translation.

18. The non-transitory machine readable medium of claim 16 , wherein a return data message from the external network to the particular logical network is returned to the MFE that provides the gateway service processing for the particular logical network.

19. The non-transitory machine readable medium of claim 16 , wherein a set of logical networks in the plurality of logical networks are each assigned a MFE in a plurality of MFEs to provide gateway service processing for the logical network.

20. The non-transitory machine readable medium of claim 19 , wherein the gateway service processing for the logical networks is assigned based on a load balancing operation based on a capacity of each MFE in the plurality of MFEs.

Assignments (2)
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0314 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2019
From: COIMBATORE NATARAJAN, VIJAI; MANOHARAN, HARISH
To: VMWARE, INC.
Reel/Frame 050407/0501 →
Cited By (2)
US 12,250,194 US 12,375,533