IP Library Granted Patent US 11,968,110
Granted Patent B2
US 11,968,110 · App. 17/823,860 · Granted Apr 23, 2024

Cloud network reachability analysis for virtual private clouds

Inventors: Hui Liu (San Ramon, CA); Leslie Choong (Mountain View, CA); Hongkun Yang (San Jose, CA); Shishir Agrawal (Mountain View, CA); Raj Yavatkar (Mountain View, CA); Tianqiong Luo (San Clara, CA); Gargi Adhav (San Jose, CA); Steffen Smolka (Ithaca, NY)
Assignee: Google LLC
H04L45/02H04L41/12H04L45/74
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,968,110
App. No.
17/823,860
Granted
Apr 23, 2024
Kind
B2
Abstract

A method for providing cloud network reachability analysis includes receiving a reachability query requesting a reachability status of a target including a packet header associated with a data packet. The packet header includes a source IP address and a destination IP address. The method also includes generating one or more simulated forwarding paths for the data packet based on the packet header using a data plane model. Each simulated forwarding path includes corresponding network configuration information. The method includes determining the reachability status of the target based on the one or more simulated forwarding paths and providing the determined reachability status and the one or more simulated forwarding paths to a user device associated with the reachability query which causes the user device to present the network configuration information for each simulated forwarding path.

Claims (56)

1. A computer-implemented method executed by data processing hardware that causes the data processing hardware to perform operations comprising:

receiving, from a user device, a virtual private cloud (VPC) reachability request requesting a reachability status of network traffic from a source Internet Protocol (IP) address of a VPC network to a destination IP address of the VPC network, the VPC reachability request comprising a protocol type;

obtaining network configuration information defining a configuration of the VPC network;

generating, using a model and the network configuration information, a simulated forwarding path for a data packet based on the source IP address and the destination IP address, the simulated forwarding path comprising a plurality of hops;

determining, based on a source instance and a destination instance of the simulated forwarding path, a type of the simulated forwarding path;

determining, based on the type of the simulated forwarding path, a path specific check comprising one or more state specific evaluations for the source instance and the destination instance of the simulated forwarding path;

determining, using the path specific check on the simulated forwarding path, that the destination IP address from the source IP address is unreachable;

in response to determining that the destination IP address is unreachable, generating a reachability report, the reachability report comprising:

each hop of the plurality of hops of the simulated forwarding path; and

a rationale that the destination IP address from the source IP address is unreachable; and

providing the reachability report to the user device.

2. The method of claim 1 , wherein the VPC reachability request further comprises a destination port.

3. The method of claim 1 , wherein determining that the destination IP address is unreachable comprises using a network abstract state machine.

4. The method of claim 1 , wherein the network configuration information comprises:

ports/interfaces for directing the data packet within the VPC network;

firewall rules applied to the data packet at each step along the simulated forwarding path; and

a network configuration associated with each hop of the plurality of hops along the simulated forwarding path.

5. The method of claim 1 , wherein determining that the destination IP address is unreachable comprises determining:

a dropped state indicating that the data packet will be dropped due to a configuration checkpoint failure or a missing configuration; or

an aborted state indicating the destination IP address is unreachable due to missing configurations.

6. The method of claim 1 , wherein the VPC reachability request further comprises:

a source port associated with the data packet; and

a destination port associated with the data packet.

7. The method of claim 1 , wherein:

the source IP address is associated with a first virtual machine (VM); and

the destination IP address is associated with a second VM.

8. The method of claim 1 , wherein at least one hop of the plurality of hops comprises a load balancer within the VPC network.

9. A system comprising:

data processing hardware; and

memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

receiving, from a user device, a virtual private cloud (VPC) reachability request requesting a reachability status of network traffic from a source Internet Protocol (IP) address of a VPC network to a destination IP address of the VPC network, the VPC reachability request comprising a protocol type;

obtaining network configuration information defining a configuration of the VPC network;

generating, using a model and the network configuration information, a simulated forwarding path for a data packet based on the source IP address and the destination IP address, the simulated forwarding path comprising a plurality of hops;

determining, based on a source instance and a destination instance of the simulated forwarding path, a type of the simulated forwarding path;

determining, based on the type of the simulated forwarding path, a path specific check comprising one or more state specific evaluations for the source instance and the destination instance of the simulated forwarding path;

determining, using the path specific check on the simulated forwarding path, that the destination IP address from the source IP address is unreachable;

in response to determining that the destination IP address is unreachable, generating a reachability report, the reachability report comprising:

each hop of the plurality of hops of the simulated forwarding path; and

a rationale that the destination IP address from the source IP address is unreachable; and

providing the reachability report to the user device.

10. The system of claim 9 , wherein the VPC reachability request further comprises a destination port.

11. The system of claim 9 , wherein determining that the destination IP address is unreachable comprises using a network abstract state machine.

12. The system of claim 9 , wherein the network configuration information comprises:

ports/interfaces for directing the data packet within the VPC network;

firewall rules applied to the data packet at each step along the simulated forwarding path; and

a network configuration associated with each hop of the plurality of hops along the simulated forwarding path.

13. The system of claim 9 , wherein determining that the destination IP address is unreachable comprises determining:

a dropped state indicating that the data packet will be dropped due to a configuration checkpoint failure or a missing configuration; or

an aborted state indicating the destination IP address is unreachable due to missing configurations.

14. The system of claim 9 , wherein the VPC reachability request further comprises:

a source port associated with the data packet; and

a destination port associated with the data packet.

15. The system of claim 9 , wherein:

the source IP address is associated with a first virtual machine (VM); and

the destination IP address is associated with a second VM.

16. The system of claim 9 , wherein at least one hop of the plurality of hops comprises a load balancer within the VPC network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2022
From: LIU, HUI; YAVATKAR, RAJ; CHOONG, LESLIE; YANG, HONGKUN; AGRAWAL, SHISHIR; LUO, TIANQIONG; ADHAV, GARGI; SMOLKA, STEFFEN
To: GOOGLE LLC
Reel/Frame 060962/0235 →
Continuity (3)
Continuation 16840084 · Apr 3, 2020
Provisional Application 62830159 · Apr 5, 2019
Related Publication 20230006915A1 · Jan 5, 2023