IP Library Granted Patent US 12,126,598
Granted Patent B2
US 12,126,598 · App. 17/715,993 · Granted Oct 22, 2024

Managing exchanges between edge gateways in a cloud environment to support a private network connection

Inventors: Yong Wang (San Jose, CA); Awan Kumar Sharma (Pune, IN); Abhishek Goliya (Pune, IN); Xinhua Hong (Campbell, CA); Bhargav Puvvada (Pune, IN)
Assignee: VMware LLC
H04L63/0272H04L12/66H04L61/2592H04L63/0485
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,126,598
App. No.
17/715,993
Granted
Oct 22, 2024
Kind
B2
Abstract

Described herein are systems, methods, and software to manage secure tunnel communications in multi-edge gateway computing environments. In one implementation, a control system identifies an edge gateway from a plurality of edge gateways to support a private network tunnel. The control system further identifies addressing attributes associated with communications directed over the private network tunnel and configures the plurality of edge gateways to forward packets associated with the addressing attributes to the identified edge gateway, wherein the edge gateway can process and forward the packets over the private network tunnel.

Claims (52)

1. A method comprising:

identifying an edge gateway from a plurality of edge gateways to support a private network tunnel, wherein the plurality of edge gateways forms a cluster for load balancing gateway services;

identifying addressing attributes associated with communications directed over the private network tunnel; and

configuring the plurality of edge gateways to forward packets associated with the addressing attributes to the identified edge gateway.

2. The method of claim 1 , wherein the addressing attributes comprise at least a destination internet protocol address.

3. The method of claim 2 , wherein the addressing attributes further comprise at least a source internet protocol address.

4. The method of claim 1 further comprising:

receiving a packet at a second edge gateway of the plurality of edge gateways;

in the second edge gateway, determining that second addressing attributes in the packet qualify the packet to be forwarded to the edge gateway based on a comparison of the second addressing attributes to the addressing attributes; and

in the second edge gateway and in response to determining that the second attributes in the packet qualify the packet to be forwarded to the edge gateway, forwarding the packet to the edge gateway.

5. The method of claim 4 further comprising:

in the edge gateway, receiving the packet;

in the edge gateway, processing the packet via at least one stateful service; and

in the edge gateway, forwarding the packet via the private network tunnel.

6. The method of claim 5 further comprising:

in a third edge gateway, receiving the packet;

in the third edge gateway, hashing at least one addressing attribute in the packet to select the second edge gateway from the plurality of edge gateways; and

in the third edge gateway, forwarding the packet to the second edge gateway.

7. The method of claim 6 , wherein the at least one addressing attribute comprises a source internet protocol address.

8. The method of claim 1 , wherein the private network tunnel comprises an IPsec tunnel.

9. The method of claim 1 , wherein configuring the plurality of edge gateways to forward packets associated with the addressing attributes to the identified edge gateway comprises configuring at least one routing table in each of the plurality of edge gateways other than the identified edge gateway to forward packets associated with the addressing attributes to the identified edge gateway.

10. A computing apparatus comprising:

a storage system;

a processing system operatively coupled to the storage system; and

program instructions stored on the storage system that, when executed by a processing system, direct the computing apparatus to:

identify an edge gateway from a plurality of edge gateways to support a private network tunnel, wherein the plurality of edge gateways forms a cluster for load balancing gateway services;

identify addressing attributes associated with communications directed over the private network tunnel; and

configure the plurality of edge gateways to forward packets associated with the addressing attributes to the identified edge gateway.

11. The computing apparatus of claim 10 , wherein the addressing attributes comprise at least a destination internet protocol address.

12. The computing apparatus of claim 11 , wherein the addressing attributes further comprise at least a source internet protocol address.

13. The computing apparatus of claim 10 , wherein the program instructions further direct the computing apparatus to:

receive a packet at a second edge gateway of the plurality of edge gateways;

in the second edge gateway, determine that second addressing attributes in the packet qualify the packet to be forwarded to the edge gateway based on a comparison of the second addressing attributes to the addressing attributes; and

in the second edge gateway and in response to determining that the second attributes in the packet qualify the packet to be forwarded to the edge gateway, forward the packet to the edge gateway.

14. The computing apparatus of claim 13 , wherein the program instructions further direct the computing apparatus to:

in the edge gateway, receive the packet;

in the edge gateway, process the packet via at least one stateful service; and

in the edge gateway, forward the packet via the private network tunnel.

15. The computing apparatus of claim 14 , wherein the program instructions further direct the computing apparatus to:

in a third edge gateway, receive the packet;

in the third edge gateway, hash at least one addressing attribute in the packet to select the second edge gateway from the plurality of edge gateways; and

in the third edge gateway, forward the packet to the second edge gateway.

16. The computing apparatus of claim 15 , wherein the at least one addressing attribute comprises a source internet protocol address.

17. The computing apparatus of claim 10 , wherein the private network tunnel comprises an IPsec tunnel.

18. The computing apparatus of claim 10 , wherein the plurality of edge gateways to forward packets associated with the addressing attributes to the identified edge gateway comprises configuring at least one routing table in each of the plurality of edge gateways other than the identified edge gateway to forward packets associated with the addressing attributes to the identified edge gateway.

19. A system comprising:

a plurality of edge gateways; and

a control system configured to:

identify an edge gateway from the plurality of edge gateways to support a private network tunnel, wherein the plurality of edge gateways forms a cluster for load balancing gateway services;

identify addressing attributes associated with communications directed over the private network tunnel; and

configure the plurality of edge gateways to forward packets associated with the addressing attributes to the identified edge gateway.

20. The system of claim 19 , wherein the addressing attributes comprise at least a destination internet protocol address.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2022
From: WANG, YONG; SHARMA, AWAN KUMAR; GOLIYA, ABHISHEK; HONG, XINHUA; PUVVADA, BHARGAV
To: VMWARE, INC.
Reel/Frame 059538/0449 →