IP Library Granted Patent US 11,206,213
Granted Patent B2
US 11,206,213 · App. 16/833,534 · Granted Dec 21, 2021

Forwarding element implementation for containers

Inventors: Jianjun Shen (Redwood City, CA); Donghai Han (Beijing, CN); Vadim Egorov (Palo Alto, CA); Corentin Derbois (San Jose, CA)
Assignee: NICIRA, INC.
H04L45/586G06F9/45558H04L41/0806H04L41/0893H04L45/16G06F2009/45562G06F2009/45566G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,206,213
App. No.
16/833,534
Granted
Dec 21, 2021
Kind
B2
Abstract

A method of creating containers in a physical host that includes a managed forwarding element (MFE) configured to forward packets to and from a set of data compute nodes (DCNs) hosted by the physical host. The method creates a container DCN in the host. The container DCN includes a virtual network interface card (VNIC) configured to exchange packets with the MFE. The method creates a plurality of containers in the container DCN. The method, for each container in the container DCN, creates a corresponding port on the MFE. The method sends packets addressed to each of the plurality of containers from the corresponding MFE port to the VNIC of the container DCN.

Claims (28)

1. A method of configuring forwarding of packets associated with a plurality of containers executing on a virtual machine (VM) on a host computer that also executes a managed forwarding element (MFE), the method comprising:

for each container in the plurality of containers executing on the VM,

creating a corresponding MFE port on the MFE for receiving packets sent to the container; and

configuring the MFE to forward the received packets sent to the container to the container's associated MFE port; and

for each MFE port associated with a particular container in the plurality of containers, configuring a dispatch filter to associate a tag identifier with each packet received from the corresponding MFE port in order to identify the corresponding MFE port's associated container, and to provide the received packet along with the tag identifier to the VM for the VM to use to identify the particular container with which the received packet is associated.

2. The method of claim 1 , wherein configuring the dispatch filter comprises configuring the dispatch filter to send the received packets to a virtual network interface card (VNIC) of the VM.

3. The method of claim 2 further comprising configuring the VNIC to identify the particular container for each received packet the VNIC receives from the tag identifier received with the packet received by the VNIC.

4. The method of claim 1 further comprising configuring the dispatch filter to receive, from the VM, the received packets associated with tag identifiers that identify the containers associated with the received packets, to use the tag identifiers to identify MFE ports associated with the received packets, and to provide each received packet in the received packets to the MFE port identified for the each received packet in the received packets.

5. The method of claim 4 , wherein configuring the dispatch filter to use the tag identifier comprises providing rules that match the tag identifiers with MFE ports.

6. The method of claim 4 , wherein configuring the dispatch filter further comprises configuring the dispatch filter to remove the tag identifiers from the received packets, in order to provide the received packets to the MFE port without the tag identifiers.

7. The method of claim 4 further comprising configuring a set of policies to be enforced on packets received at an MFE port associated with a container.

8. The method of claim 7 , wherein the set of policies comprises one or more of quality of service (QoS), access control lists (ACL), firewall, Internet protocol flow information export (IPFix), mirroring, spoof guard, and routing.

9. The method of claim 1 , wherein configuring the MFE comprising configuring a forwarding table of the MFE with forwarding rules to identify the particular container associated with the received packet received at the MFE with the particular container based on one or more header values of the received packet.

10. The method of claim 9 , wherein the header value set comprises a destination media access control (MAC) address the header of the received packet.

11. A non-transitory machine readable medium storing a program for configuring forwarding of packets associated with a plurality of containers executing on a virtual machine (VM) on a host computer that also executes a managed forwarding element (MFE), the program comprising sets of instructions for:

for each container in the plurality of containers executing on the VM,

creating a corresponding MFE port on the MFE for receiving packets sent to the container; and

configuring the MFE to forward the received packets sent to the container in the plurality of containers to the container's associated MFE port; and

configuring, for each MFE port associated with a particular container in the plurality of containers, a dispatch filter to associate a tag identifier with each packet received from the corresponding MFE port in order to identify the corresponding MFE port's associated container, and to provide the received packet along with the tag identifier to the VM for the VM to use to identify the particular container with which the received packet is associated.

12. The non-transitory machine readable medium of claim 11 , wherein the set of instructions for configuring the dispatch filter comprises a set of instructions for configuring the dispatch filter to send the received packets to a virtual network interface card (VNIC) of the VM.

13. The non-transitory machine readable medium of claim 12 , wherein the set of instructions further comprises a set of instructions for configuring the VNIC to identify the particular container for each received packet the VNIC receives from the tag identifier received with the packet received by the VNIC.

14. The non-transitory machine readable medium of claim 11 , the program further comprising sets of instructions for configuring the dispatch filter to receive, from the VM, the received packets associated with tag identifiers that identify the containers associated with the received packets, to use the tag identifiers to identify MFE ports associated with the received packets, and to provide each received packet in the received packets to the MFE port identified for the each received packet in the received packets.

15. The non-transitory machine readable medium of claim 14 , wherein the set of instructions for configuring the dispatch filter to use the tag identifier comprises a set of instructions providing rules that match the tag identifiers with MFE ports.

16. The non-transitory machine readable medium of claim 14 , wherein the set of instructions for configuring the dispatch filter further comprises a set of instructions for configuring the dispatch filter to remove the tag identifiers from the received packets, in order to provide the received packets to the MFE port without the tag identifiers.

17. The non-transitory machine readable medium of claim 14 further comprising a set of instructions for configuring a set of policies to be enforced on packets received at an MFE port associated with a container.

18. The non-transitory machine readable medium of claim 17 , wherein the set of policies comprises one or more of quality of service (QoS), access control lists (ACL), firewall, Internet protocol flow information export (IPFix), mirroring, spoof guard, and routing.

19. The non-transitory machine readable medium of claim 11 , wherein the set of instructions for configuring the MFE further comprises a set of instructions for configuring a forwarding table of the MFE with forwarding rules to identify the particular container associated with the received packet received at the MFE with the particular container based on one or more header values of the received packet.

20. The non-transitory machine readable medium of claim 19 , wherein the header value set comprises a destination media access control (MAC) address the header of the received packet.

Assignments (1)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
Continuity (3)
Continuation 16112689 · Aug 25, 2018
Continuation 14972000 · Dec 16, 2015
Related Publication 20200228447A1 · Jul 16, 2020
Cited By (8)
US 12,278,758 US 12,284,113 US 12,328,257 US 12,341,689 US 12,341,690 US 12,562,984 US 12,706,840 US 12,719,786