IP Library Granted Patent US 12,432,171
Granted Patent B2
US 12,432,171 · App. 17/691,976 · Granted Sep 30, 2025

Hybrid and efficient method to sync NAT sessions

Inventors: Saurav Suri (Bangalore, IN); Varun Lakkur Ambaji Rao (Bangalore, IN)
Assignee: VMware LLC
H04L61/2521H04L45/38H04L61/2514H04L61/255H04L61/4552H04L2101/668
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,171
App. No.
17/691,976
Granted
Sep 30, 2025
Kind
B2
Abstract

The method of synchronizes network address translation (NAT) records between an active gateway and a standby gateway. The method of some embodiments synchronizes NAT records of long-term data flows more frequently than those of short-term flows. Multiple data flows pass between a device at an internal source address and a device at an external destination address through the active NAT gateway. For each flow, the method generates a NAT record. The method then determines whether the data flow is a short-term flow or a long-term flow and synchronizes the NAT records of the long-term flows, but not the NAT records of the short-term flows, with the standby gateway. The method of some embodiments synchronizing NAT records more frequently when NAT records are being generated quickly relative to prior generation rates and less frequently when NAT records are being generated slowly relative to the prior generation rates.

Claims (32)

1. A method of synchronizing network address translation (NAT) records between an active gateway and a standby gateway, the method comprising iteratively:

waiting a set interval;

determining a data flow type for synchronization, the data flow type being selected between a long-term flow type and a short-term flow type;

providing decoding data from the active gateway to the standby gateway to enable the standby gateway to decode encoded NAT records;

encoding an internal source IP address in the NAT record by replacing the subnet portion of the IP address with a unique identifier while maintaining a portion of the address identifying the specific machine within the subnet;

synchronizing, for data flow type being a long-term flow type, a set of NAT records generated since an immediately prior synchronization; and

adjusting the interval based on a rate of NAT record generation relative to a threshold.

2. The method of claim 1 , wherein adjusting the interval comprises comparing a first number of NAT records synchronized in the immediately prior synchronization to a second number of NAT records synchronized in a current synchronization.

3. The method of claim 2 , wherein adjusting the interval comprises increasing the interval when the first number is greater than the second number by a first particular amount.

4. The method of claim 3 , wherein adjusting the interval comprises decreasing the interval when the first number is less than the second number by a second particular amount.

5. The method of claim 4 , wherein the first particular amount is calculated based on at least one of the first and second numbers and the second particular amount is calculated based on at least one of the first and second numbers.

6. The method of claim 5 , wherein the interval is bounded to remain between an upper bound and a lower bound.

7. A non-transitory machine readable medium storing a program which when executed by at least one processing unit synchronizes network address translation (NAT) records between an active gateway and a standby gateway, the program comprising sets of instructions for:

waiting a set interval;

determining a data flow type for synchronization, the data flow type being selected between a long-term flow type and a short-term flow type;

providing decoding data from the active gateway to the standby gateway to enable the standby gateway to decode encoded NAT records;

encoding an internal source IP address in the NAT record by replacing the subnet portion of the IP address with a unique identifier while maintaining a portion of the address identifying the specific machine within the subnet;

synchronizing, for data flow type being a long-term flow type, a set of NAT records generated since an immediately prior synchronization; and

adjusting the interval based on a rate of NAT record generation relative to a threshold.

8. The non-transitory machine readable medium of claim 7 , wherein the set of instructions for adjusting the interval comprises a set of instructions comparing a first number of NAT records synchronized in the immediately prior synchronization to a second number of NAT records synchronized in a current synchronization.

9. The non-transitory machine readable medium of claim 8 , wherein the set of instructions for adjusting the interval comprises a set of instructions increasing the interval when the first number is greater than the second number by a first particular amount.

10. The non-transitory machine readable medium of claim 9 , wherein the set of instructions for adjusting the interval comprises a set of instructions decreasing the interval when the first number is less than the second number by a second particular amount.

11. The non-transitory machine readable medium of claim 10 , wherein the first particular amount is calculated based on at least one of the first and second numbers and the second particular amount is calculated based on at least one of the first and second numbers.

12. The non-transitory machine readable medium of claim 11 , wherein the interval is bounded to remain between an upper bound and a lower bound.

13. A method of synchronizing network address translation (NAT) records between an active gateway and a standby gateway, the method comprising iteratively:

encoding a set of NAT records to reduce size before being sent to a standby gateway;

waiting a set interval;

determining a data flow type for synchronization, the data flow type being selected between a long-term flow type and a short-term flow type;

providing decoding data from the active gateway to the standby gateway to enable the standby gateway to decode encoded NAT records;

encoding an internal source IP address in the NAT record by replacing the subnet portion of the IP address with a unique identifier while maintaining a portion of the address identifying the specific machine within the subnet;

synchronizing, for data flow type being a long-term flow type, the set of NAT records generated since an immediately prior synchronization; and

adjusting the interval based on a rate of NAT record generation relative to a threshold.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 3, 2024
From: SURI, SAURAV; RAO, VARUN LAKKUR AMBAJI
To: VMWARE, INC.
Reel/Frame 069463/0275 →
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
Priority Claims (1)
IN 202041052107 · Nov 30, 2020 · national
Continuity (2)
Division 17151665 · Jan 19, 2021
Related Publication 20220200953A1 · Jun 23, 2022
References Cited (60)
US 6453357B1 · Crow et al. · 2002 [cited by applicant]
US 7042876B1 · Jayasenan et al. · 2006 [cited by applicant]
US 7647427B1 · Devarapalli · 2010 [cited by applicant]
US 9258271B1 · Anderson · 2016 [cited by applicant]
US 9331946B2 · Okita · 2016 [cited by applicant]
US 9614761B1 · Kamisetty et al. · 2017 [cited by applicant]
US 9832072B1 · Piecuch · 2017 [cited by applicant]
US 9853903B1 · Sharma et al. · 2017 [cited by applicant]
US 10587571B2 · Babu et al. · 2020 [cited by applicant]
US 11115381B1 · Suri et al. · 2021 [cited by applicant]
US 11303609B2 · Namburu et al. · 2022 [cited by applicant]
US 11316824B1 · Suri et al. · 2022 [cited by applicant]
US 20030081615A1 · Kohn et al. · 2003 [cited by applicant]
US 20040215752A1 · Satapati et al. · 2004 [cited by applicant]
US 20060120366A1 · Jayasenan et al. · 2006 [cited by applicant]
US 20080225866A1 · Sehgal et al. · 2008 [cited by applicant]
US 20080240132A1 · Sehgal et al. · 2008 [cited by applicant]
US 20100061380A1 · Barach et al. · 2010 [cited by applicant]
US 20100254255A1 · Devarapalli · 2010 [cited by applicant]
US 20110103387A1 · Jayasenan · 2011 [cited by examiner]
US 20120144043A1 · Huang et al. · 2012 [cited by applicant]
US 20120226804A1 · Raja · 2012 [cited by examiner]
US 20130067110A1 · Sarawat et al. · 2013 [cited by applicant]
US 20140181286A1 · Jayasenan et al. · 2014 [cited by applicant]
US 20150026398A1 · Kim · 2015 [cited by examiner]
US 20150295869A1 · Li et al. · 2015 [cited by applicant]
US 20150304275A1 · Ghai et al. · 2015 [cited by applicant]
US 20160094631A1 · Jain et al. · 2016 [cited by applicant]
US 20160234112A1 · Anand · 2016 [cited by applicant]
US 20170004057A1 · Brown et al. · 2017 [cited by applicant]
US 20170026468A1 · Kumar · 2017 [cited by examiner]
US 20170359305A1 · Yin et al. · 2017 [cited by applicant]
US 20180034769A1 · Modi et al. · 2018 [cited by applicant]
US 20180062923A1 · Katrekar et al. · 2018 [cited by applicant]
US 20180219983A1 · Lambeth et al. · 2018 [cited by applicant]
US 20180287996A1 · Tripathy et al. · 2018 [cited by applicant]
US 20190007316A1 · Congdon et al. · 2019 [cited by applicant]
US 20190073407A1 · Mandavilli · 2019 [cited by examiner]
US 20190097967A1 · Xu et al. · 2019 [cited by applicant]
US 20190364014A1 · Endou · 2019 [cited by applicant]
US 20190379600A1 · Bisht et al. · 2019 [cited by applicant]
US 20200304413A1 · MacCarthaigh · 2020 [cited by applicant]
US 20210109910A1 · Georg · 2021 [cited by examiner]
US 20220006776A1 · Namburu et al. · 2022 [cited by applicant]
US 20220006777A1 · Namburu et al. · 2022 [cited by applicant]
EP 2495920A1 · 2012 [cited by applicant]
EP 3780552A1 · 2021 [cited by applicant]
EP 3790260A1 · 2021 [cited by applicant]
JP 2014135721A · 2014 [cited by applicant]
WO 2006034023A2 · 2006 [cited by applicant]
WO 2011119019A1 · 2011 [cited by applicant]
WO 2014073148A1 · 2014 [cited by applicant]
WO 2022005606A1 · 2022 [cited by applicant]
Non-Published Commonly Owned Related U.S. Appl. No. 17/151,665 with similar specification, filed Jan. 19, 2021, 40 pages, VMware, Inc. [cited by applicant]
Paxton, Dr. Napoleon, et al., “Identifying Network Packets Across Translational Boundaries,” 10th International Conference on Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom2014), Oct. … [cited by applicant]
Penno, R., et al., “Network Address Translation (NAT) Behavioral Requirements Updates,” draft-penno-behave-rfc4787-532-5508-bis-04, Jan. 7, 2013, 15 pages, IETF Trust. [cited by applicant]
Tran, Thuy Vinh, et al., “FlowTracker: A SDN Stateful Firewall Solution with Adaptive Connection Tracking and Minimized Controller Processing,” 2016 International Conference on Software Networking (ICSN), May 23-26, 201… [cited by applicant]
Wu, Ruisi, et al., “Header-Translation Based Flow Aggregation for Scattered Address Allocating SDNs,” 2021 IEEE Conference on Dependable and Secure Computing (DSC), Jan. 30-Feb. 2, 2021, 8 pages, IEEE, Fukushima, Japan. [cited by applicant]
Zhang, Ke, et al., “A Matching Algorithm of Netfilter Connection Tracking Based on IP flow,” 2nd International Conference on Anti-Counterfeiting, Security, and Identification (ASID 2008), Aug. 20-23, 2008, 5 pages, IEEE… [cited by applicant]
Schellenberg, Sebastian, et al., “The Impact of Host Name Hashing on Name Resolution Traffic,” Jul. 2013, 6 pages, IEEE. [cited by applicant]