IP Library Granted Patent US 12,177,067
Granted Patent B2
US 12,177,067 · App. 18/102,684 · Granted Dec 24, 2024

Service insertion at logical network gateway

Inventors: Akhila Naveen (Palo Alto, CA); Kantesh Mundaragi (Bangalore, IN); Rahul Mishra (Mountain View, CA); Fenil Kavathia (Sunnyvale, CA); Raju Koganty (San Jose, CA); Pierluigi Rolando (Santa Clara, CA); Yong Feng (Sunnyvale, CA); Jayant Jain (Cupertino, CA)
Assignee: VMware LLC
H04L41/0806H04L12/66H04L45/42H04L49/355H04L67/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,177,067
App. No.
18/102,684
Granted
Dec 24, 2024
Kind
B2
Abstract

Some embodiments provide a method for configuring a gateway machine in a datacenter. The method receives a definition of a logical network for implementation in the datacenter. The logical network includes at least one logical switch to which logical network endpoints attach and a logical router for handling data traffic between the logical network endpoints in the datacenter and an external network. The method receives configuration data attaching a third-party service to at least one interface of the logical router via an additional logical switch designated for service attachments. The third-party service is for performing non-forwarding processing on the data traffic between the logical network endpoints and the external network. The method configures the gateway machine in the datacenter to implement the logical router and redirect at least a subset of the data traffic between the logical network endpoints and the external network to the attached third-party service.

Claims (30)

1. A method for forwarding a data message, the method comprising:

performing a lookup to map a set of header fields of the data message to an identifier corresponding to a service that performs non-forwarding processing on data messages, the service comprising a third-party service virtual machine that performs non-forwarding processing on the data messages;

using a dynamically-updated data structure for the identifier to retrieve instructions for forwarding data messages to the service; and

forwarding the data message according to the retrieved instructions from the data structure for the identifier.

2. The method of claim 1 , wherein the method is performed by a gateway for a logical network implemented in a datacenter, the gateway for processing data messages between logical network endpoints operating in the datacenter and physical networks external to the datacenter.

3. The method of claim 2 , wherein:

the logical network comprises at least one logical switch to which the logical network endpoints connect and a logical router;

the logical router comprises a distributed routing component and one or more centralized routing components;

the gateway implements one of the centralized routing components to process data messages between the logical network endpoints and the physical networks external to the datacenter.

4. The method of claim 1 , wherein the lookup comprises a policy-based routing decision.

5. The method of claim 1 , wherein the set of header fields comprises at least a source network address of the data message.

6. The method of claim 1 , wherein the dynamically-updated data structure specifies a reachability status of the service that is dynamically updated based on a reachability protocol.

7. The method of claim 1 , wherein the service is connected using a layer 2 (L2) bump in the wire mode and the dynamically-updated data structure specifies an IP address for reaching the service.

8. The method of claim 7 , wherein the IP address is a dummy address that corresponds to an interface of a gateway that forwards the data message.

9. The method of claim 8 , wherein the interface is a first interface, wherein the gateway executes a bidirectional forwarding detection (BFD) thread that sends BFD messages to the service through a second interface and receives the BFD messages from the service through the first interface.

10. The method of claim 1 , wherein the dynamically-updated data structure specifies an IP address for a machine that implements the service.

11. The method of claim 1 , wherein the dynamically-updated data structure specifies a failover policy for when the service is not reachable, the failover policy specifying at least one of (i) dropping data messages when the service is not reachable, (ii) routing data messages based on the destination network address when the service is not reachable, and (iii) a backup service to which to redirect the data messages when the service is not reachable.

12. A non-transitory machine-readable medium storing a program which when executed by at least one processing unit forwards a data message, the program comprising sets of instructions for:

performing a lookup to map a set of header fields of the data message to an identifier corresponding to a service that performs non-forwarding processing on data messages, the service comprising a third-party service virtual machine that performs non-forwarding processing on the data messages;

using a dynamically-updated data structure for the identifier to retrieve instructions for forwarding data messages to the service; and

forwarding the data message according to the retrieved instructions from the data structure for the identifier.

13. The non-transitory machine-readable medium of claim 12 , wherein the program is performed by a gateway for a logical network implemented in a datacenter, the gateway for processing data messages between logical network endpoints operating in the datacenter and physical networks external to the datacenter.

14. The non-transitory machine-readable medium of claim 13 , wherein:

the logical network comprises at least one logical switch to which the logical network endpoints connect and a logical router;

the logical router comprises a distributed routing component and one or more centralized routing components;

the gateway implements one of the centralized routing components to process data messages between the logical network endpoints and the physical networks external to the datacenter.

15. The method of claim 12 , wherein the lookup comprises a policy-based routing decision.

16. The non-transitory machine-readable medium of claim 12 , wherein the set of header fields comprises at least a source network address of the data message.

17. The non-transitory machine-readable medium of claim 12 , wherein the dynamically-updated data structure specifies a reachability status of the service that is dynamically updated based on a reachability protocol.

18. The non-transitory machine-readable medium of claim 12 , wherein the service is connected using a layer 2 (L2) bump in the wire mode and the dynamically-updated data structure specifies an IP address for reaching the service.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2024
From: NAVEEN, AKHILA; MUNDARAGI, KANTESH; MISHRA, RAHUL; KAVATHIA, FENIL; KOGANTY, RAJU; ROLANDO, PIERLUIGI; FENG, YONG; JAIN, JAYANT
To: VMWARE, INC.
Reel/Frame 069052/0434 →
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
Continuity (2)
Continuation 16120283 · Sep 2, 2018
Related Publication 20230179474A1 · Jun 8, 2023