Logical L3 daemon
For a network controller for managing hosts in a network, a method for configuring a host to resolve network addresses is described. The method configures an address resolution module in a host to resolve a network address. The method configures a managed forwarding element in the host to (1) avoid sending a request to resolve the network address to another host by using the address resolution module to resolve the network address and (2) forward packets using the resolved network address.
1. A method of performing routing, the method comprising:
at a first host computer on which a plurality of machines execute:
receiving a packet sent from a source machine executing on the host computer, the packet associated with a logical network implemented over a shared physical network and addressed to a destination machine executing on a second host computer;
performing a logical routing operation at a first managed forwarding element (MFE) that executes on the host computer and implements a logical router with other MFEs executing on other host computers;
performing a logical network address translation (NAT) operation to modify a first logical network address stored in a header of the packet to a second logical network address, wherein performing the logical NAT operation comprises, after the MFE performs the logical routing operation, using a NAT daemon executing on the host computer to perform the NAT operation that translates the first logical network address to the second logical network address;
using a tunnel header to encapsulate the packet with physical network addresses defined for the shared physical network; and
forwarding the encapsulated packet along the shared physical network, wherein the packet has the second logical network address when delivered to the destination machine on a second host computer.
2. The method of claim 1 , wherein the NAT operation is a destination NAT operation, wherein the second logical network address identifies the destination machine associated with the logical network that executes on the second host computer.
3. The method of claim 1 , wherein the NAT operation is a source NAT operation, wherein the first logical network address identifies the source machine of the packet that is associated with the logical network.
4. The method of claim 1 , wherein the first and second logical network addresses are defined for the logical network and are separate from the physical network addresses used for the shared physical network.
5. The method of claim 1 , wherein the tunnel header enables the forwarding of the encapsulated packet along the shared physical network.
6. The method of claim 5 , wherein:
the logical network is an overlay logical network; and
the encapsulating header encapsulates a header of the packet that stores network addresses defined for the logical network, including the second logical network address.
7. The method of claim 6 , wherein logical network addresses for multiple logical networks are defined over the shared physical network.
8. A non-transitory machine readable medium storing sets of instructions for performing routing on a first host computer on which a plurality of machines execute, the sets of instructions for execution by at least one processing unit of the host computer, the sets of instructions for:
receiving a packet sent from a source machine executing on the host computer, the packet associated with a logical network implemented over a shared physical network and addressed to a destination machine executing on a second host computer;
performing a logical routing operation at a first managed forwarding element (MFE) that executes on the host computer and implements a logical router with other MFEs executing on other host computers;
performing a logical network address translation (NAT) operation to modify a first logical network address stored in a header of the packet to a second logical network address, wherein performing the logical NAT operation comprises, after the MFE performs the logical routing operation, using a NAT daemon executing on the host computer to perform the NAT operation that translates the first logical network address to the second logical network address;
using a tunnel header to encapsulate the packet with physical network addresses defined for the shared physical network; and
forwarding the encapsulated packet along the shared physical network, wherein the packet has the second logical network address when delivered to the destination machine on a second host computer.
9. The non-transitory machine readable medium of claim 8 , wherein the NAT operation is a destination NAT operation, wherein the second logical network address identifies the destination machine associated with the logical network that executes on the second host computer.
10. The non-transitory machine readable medium of claim 8 , wherein the NAT operation is a source NAT operation, wherein the first logical network address identifies the source machine of the packet that is associated with the logical network.
11. The non-transitory machine readable medium of claim 8 , wherein the first and second logical network addresses are defined for the logical network and are separate from the physical network addresses used for the shared physical network.
12. The non-transitory machine readable medium of claim 8 , wherein the tunnel header enables the forwarding of the encapsulated packet along the shared physical network.
13. The non-transitory machine readable medium of claim 12 , wherein:
the logical network is an overlay logical network; and
the encapsulating header encapsulates a header of the packet that stores network addresses defined for the logical network, including the second logical network address.
14. The non-transitory machine readable medium of claim 13 , wherein logical network addresses for multiple logical networks are defined over the shared physical network.
15. A non-transitory machine readable medium storing sets of instructions for performing routing on a first host computer on which a plurality of machines execute, the sets of instructions for execution by at least one processing unit of the host computer, the sets of instructions for:
receiving a packet sent from a source machine executing on the host computer, the packet associated with a logical network implemented over a shared physical network and addressed to a destination machine executing on a second host computer;
performing a logical routing operation at a first managed forwarding element (MFE) that executes on the host computer and implements a logical router with other MFEs executing on other host computers;
performing a logical network address translation (NAT) operation to modify a first logical network address stored in a header of the packet to a second logical network address, wherein performing the logical NAT operation comprises using a NAT daemon executing on the host computer to perform the NAT operation that translates the first logical network address to the second logical network address, wherein the NAT daemon provides information to the MFE such that the MFE performs the NAT operation on subsequent data messages sent from the source machine to the destination machine;
using a tunnel header to encapsulate the packet with physical network addresses defined for the shared physical network; and
forwarding the encapsulated packet along the shared physical network, wherein the packet has the second logical network address when delivered to the destination machine on a second host computer.
16. A method of performing routing, the method comprising:
at a first host computer on which a plurality of machines execute:
receiving a packet sent from a source machine executing on the host computer, the packet associated with a logical network implemented over a shared physical network and addressed to a destination machine executing on a second host computer;
performing a logical routing operation at a first managed forwarding element (MFE) that executes on the host computer and implements a logical router with other MFEs executing on other host computers;
performing a logical network address translation (NAT) operation to modify a first logical network address stored in a header of the packet to a second logical network address, wherein performing the logical NAT operation comprises using a NAT daemon executing on the host computer to perform the NAT operation that translates the first logical network address to the second logical network address, wherein the NAT daemon provides information to the MFE such that the MFE performs the NAT operation on subsequent data messages sent from the source machine to the destination machine;
using a tunnel header to encapsulate the packet with physical network addresses defined for the shared physical network; and
forwarding the encapsulated packet along the shared physical network, wherein the packet has the second logical network address when delivered to the destination machine on a second host computer.