IP Library Granted Patent US 11,375,005
Granted Patent B1
US 11,375,005 · App. 17/384,737 · Granted Jun 28, 2022

High availability solutions for a secure access service edge application

Inventors: Pierluigi Rolando (Santa Clara, CA); Jayant Jain (Cupertino, CA); Raju Koganty (San Jose, CA); Shadab Shah (Sunnyvale, CA); Abhishek Goliya (Pune, IN); Chandran Anjur Narasimhan (Milpitas, CA); Gurudutt Maiya Belur (San Carlos, CA); Vikas Kamath (Burlingame, CA)
Assignee: VMWARE, INC.
H04L67/10H04L12/4633H04L12/66
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,375,005
App. No.
17/384,737
Granted
Jun 28, 2022
Kind
B1
Abstract

A software-defined wide area network (SD-WAN) environment that leverages network virtualization management deployment is provided. Edge security services managed by the network virtualization management deployment are made available in the SD-WAN environment. Cloud gateways forward SD-WAN traffic to managed service nodes to apply security services. Network traffic is encapsulated with corresponding metadata to ensure that services can be performed according to the desired policy. Point-to-point tunnels are established between cloud gateways and the managed service nodes to transport the metadata to the managed service nodes using an overlay logical network. Virtual network identifiers (VNIs) in the metadata are used by the managed service nodes to identify tenants/policies. A managed service node receiving a packet uses provider service routers (T0-SR) and tenant service routers (T1-SRs) based on the VNI to apply the prescribed services for the tenant, and the resulting traffic is returned to the cloud gateway that originated the traffic.

Claims (44)

1. A method comprising:

operating first and second service nodes to process packets from a cloud gateway of a software-defined wide area network (SD-WAN),

wherein the first service node comprises a first plurality of tenant service routers (T1-SRs) that includes a first set of T1-SRs dedicated to a first tenant segment and a second set of T1-SRs dedicated to a second tenant segment,

wherein the second service node comprises a second plurality of T1-SRs that includes a third set of T1-SRs dedicated to the first tenant segment and a fourth set of T1-SRs dedicated to the second tenant segment;

receiving, at the first service node, packets from the cloud gateway to a first tunnel endpoint to be processed at the first plurality of T1-SRs;

receiving, at the second service node, packets from the cloud gateway to a second tunnel endpoint to be processed at the second plurality of T1-SRs;

wherein when the first service node fails, the second service node receives packets from the cloud gateway to both the first and second tunnel endpoints to be processed at the second plurality of T1-SRs.

2. The method of claim 1 , wherein a T1-SR dedicated to the first tenant segment in the first plurality of T1-SRs has a same MAC address as a T1-SR dedicated to the first tenant segment in the second plurality of T1-SRs.

3. The method of claim 1 , wherein the first service node implements a first provider service router (T0-SR) for decapsulating and demultiplexing packets to the first plurality of T1-SRs and the second service node implements a second T0-SR for decapsulating and demultiplexing packets to the second plurality of T1-SRs.

4. The method of claim 1 , wherein each T1-SR of the first and third sets of T1-SRs is for applying a set of security policies specific to the first tenant segment to packets from the first tenant segments.

5. The method of claim 1 , wherein the cloud gateway is configured by an orchestrator of the SD-WAN and the first and second service nodes are managed by a network virtualization management software.

6. The method of claim 1 , wherein the states of the second plurality of T1-SRs are synchronized with the states of the first plurality of T1-SRs.

7. The method of claim 1 , wherein when the first service node fails,

packets from the first tenant segment to the first and second tunnel endpoints are processed by the third set of T1-SRs and

packets from the second tenant segment to the first and second tunnel endpoints are processed by the fourth set of T1-SRs.

8. The method of claim 1 , wherein when the second service node fails, the first service node receives packets from the cloud gateway to both the first and second tunnel endpoints to be processed at the first plurality of T1-SRs.

9. A computing device comprising:

one or more processors; and

a computer-readable storage medium storing a plurality of computer-executable components that are executable by the one or more processors to perform a plurality of actions, the plurality of actions comprising:

operating first and second service nodes to process packets from a cloud gateway of a software-defined wide area network (SD-WAN),

wherein the first service node comprises a first plurality of tenant service routers (T1-SRs) that includes a first set of T1-SRs dedicated to a first tenant segment and a second set of T1-SRs dedicated to a second tenant segment,

wherein the second service node comprises a second plurality of T1-SRs that includes a third set of T1-SRs dedicated to the first tenant segment and a fourth set of T1-SRs dedicated to the second tenant segment;

receiving, at the first service node, packets from the cloud gateway to a first tunnel endpoint to be processed at the first plurality of T1-SRs;

receiving, at the second service node, packets from the cloud gateway to a second tunnel endpoint to be processed at the second plurality of T1-SRs;

wherein when the first service node fails, the second service node receives packets from the cloud gateway to both the first and second tunnel endpoints to be processed at the second plurality of T1-SRs.

10. The computing device of claim 9 , wherein a T1-SR dedicated to the first tenant segment in the first plurality of T1-SRs has a same MAC address as a T1-SR dedicated to the first tenant segment in the second plurality of T1-SRs.

11. The computing device of claim 9 , wherein the first service node implements a first provider service router (T0-SR) for decapsulating and demultiplexing packets to the first plurality of T1-SRs and the second service node implements a second T0-SR for decapsulating and demultiplexing packets to the second plurality of T1-SRs.

12. The computing device of claim 9 , wherein each T1-SR of the first and third sets of T1-SRs is for applying a set of security policies specific to the first tenant segment to packets from the first tenant segments.

13. The computing device of claim 9 , wherein the cloud gateway is configured by an orchestrator of the SD-WAN and the first and second service nodes are managed by a network virtualization management software.

14. The computing device of claim 9 , wherein the states of the second plurality of T1-SRs are synchronized with the states of the first plurality of T1-SRs.

15. The computing device of claim 9 , wherein when the first service node fails,

packets from the first tenant segment to the first and second tunnel endpoints are processed by the third set of T1-SRs and

packets from the second tenant segment to the first and second tunnel endpoints are processed by the fourth set of T1-SRs.

16. The computing device of claim 9 , wherein when the second service node fails, the first service node receives packets from the cloud gateway to both the first and second tunnel endpoints to be processed at the first plurality of T1-SRs.

17. A non-transitory machine-readable medium storing a program for execution by at least one hardware processing unit, the program comprising sets of instructions for:

operating first and second service nodes to process packets from a cloud gateway of a software-defined wide area network (SD-WAN),

wherein the first service node comprises a first plurality of tenant service routers (T1-SRs) that includes a first set of T1-SRs dedicated to a first tenant segment and a second set of T1-SRs dedicated to a second tenant segment,

wherein the second service node comprises a second plurality of T1-SRs that includes a third set of T1-SRs dedicated to the first tenant segment and a fourth set of T1-SRs dedicated to the second tenant segment;

receiving, at the first service node, packets from the cloud gateway to a first tunnel endpoint to be processed at the first plurality of T1-SRs;

receiving, at the second service node, packets from the cloud gateway to a second tunnel endpoint to be processed at the second plurality of T1-SRs;

wherein when the first service node fails, the second service node receives packets from the cloud gateway to both the first and second tunnel endpoints to be processed at the second plurality of T1-SRs.

18. The non-transitory machine-readable medium of claim 17 , wherein a T1-SR dedicated to the first tenant segment in the first plurality of T1-SRs has a same MAC address as a T1-SR dedicated to the first tenant segment in the second plurality of T1-SRs.

19. The non-transitory machine-readable medium of claim 17 , wherein the first service node implements a first provider service router (T0-SR) for decapsulating and demultiplexing packets to the first plurality of T1-SRs and the second service node implements a second T0-SR for decapsulating and demultiplexing packets to the second plurality of T1-SRs.

20. The non-transitory machine-readable medium of claim 17 , wherein each T1-SR of the first and third sets of T1-SRs is for applying a set of security policies specific to the first tenant segment to packets from the first tenant segments.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2025
From: VMWARE, LLC
To: VELOCLOUD NETWORKS, LLC
Reel/Frame 072326/0693 →
CHANGE OF NAME Recorded Apr 15, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067102/0395 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2021
From: ROLANDO, PIERLUIGI; JAIN, JAYANT; KOGANTY, RAJU; SHAH, SHADAB; GOLIYA, ABHISHEK; NARASIMHAN, CHANDRAN ANJUR; BELUR, GURUDUTT MAIYA; KAMATH, VIKAS
To: VMWARE, INC.
Reel/Frame 058562/0497 →
Cited By (43)
US 12,218,800 US 12,218,845 US 12,237,990 US 12,250,114 US 12,261,777 US 12,267,364 US 12,316,524 US 12,335,131 US 12,348,492 US 12,355,655 US 12,356,191 US 12,368,676 US 12,375,403 US 12,395,843 US 12,401,544 US 12,413,527 US 12,425,332 US 12,425,335 US 12,425,347 US 12,425,395 US 12,452,671 US 12,483,968 US 12,489,672 US 12,506,678 US 12,507,120 US 12,507,148 US 12,507,153 US 12,513,088 US 12,526,183 US 12,549,465 US 12,549,948 US 12,563,438 US 12,568,039 US 12,587,468 US 12,603,827 US 12,603,848 US 12,615,257 US 12,632,330 US 12,634,261 US 12,641,429 US 12,652,217 US 12,659,719 US 12,701,418