IP Library Granted Patent US 12,093,719
Granted Patent B2
US 12,093,719 · App. 18/114,613 · Granted Sep 17, 2024

Network control system for configuring middleboxes

Inventors: Ronghua Zhang (San Jose, CA); Teemu Koponen (San Francisco, CA); Pankaj Thakkar (Cupertino, CA); Amar Padmanabhan (Menlo Park, CA); Martin Casado (Portola Valley, CA)
Assignee: Nicira, Inc.
G06F9/45558G06F9/455G06F9/45533G06F15/177H04L41/08H04L41/0803H04L41/0806H04L41/0813H04L41/0823H04L41/0889H04L41/0893H04L41/12H04L45/64H04L45/74H04L49/70H04L61/2503H04L61/2517H04L61/2521H04L61/256H04L63/0218H04L67/1008G06F2009/4557G06F2009/45595H04L45/02H04L49/15
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,093,719
App. No.
18/114,613
Granted
Sep 17, 2024
Kind
B2
Abstract

Some embodiments provide a method for configuring a logical middlebox in a hosting system that includes a set of nodes. The logical middlebox is part of a logical network that includes a set of logical forwarding elements that connect a set of end machines. The method receives a set of configuration data for the logical middlebox. The method uses a stored set of tables describing physical locations of the end machines to identify a set of nodes at which to implement the logical middlebox. The method provides the logical middlebox configuration for distribution to the identified nodes.

Claims (26)

1. For a middlebox element executes on a host computer that executes a plurality of end machines belonging to a plurality of logical networks, a method comprising:

receiving a data packet from a managed forwarding element operating on the host computer;

based on a tag added to the data packet by the managed forwarding element, identifying one of a plurality of logical middleboxes implemented by the middlebox element for a plurality of logical networks, the tag being associated with the identified logical middlebox; wherein the tag enables the middlebox to use appropriate set of packet processing rules in order to perform operations on the packet;

processing the data packet according to a configuration for the identified logical middlebox; and

sending the processed data packet to the managed forwarding element.

2. The method of claim 1 , wherein the data packet is sent to the managed forwarding element by one of the end machines hosted on the host computer.

3. The method of claim 2 , wherein the end machine belongs to a same logical network as the identified logical middlebox.

4. The method of claim 1 , wherein the tag is prepended to the data packet by the managed forwarding element.

5. The method of claim 1 , wherein identifying the logical middlebox comprises mapping the tag to the logical middlebox using a binding table.

6. The method of claim 1 , wherein the processed data packet is sent to the managed forwarding element with the tag.

7. The method of claim 1 , wherein the managed forwarding element sends the data packet to the middlebox element according to a routing policy that routes the data packet based on data other than a destination network address of the data packet.

8. The method of claim 7 , wherein the field is an ingress port through which the data packet was received.

9. The method of claim 7 , wherein the managed forwarding receives the processed data packet and subsequently routes the processed data packet based on the destination network address of the processed data packet.

10. A non-transitory machine readable medium storing a middlebox element for execution by at least one processing unit of a host computer that executes a plurality of end machines belonging to a plurality of logical networks, the middlebox element comprising sets of instructions for:

receiving a data packet from a managed forwarding element operating on the host 6 computer;

based on a tag added to the data packet by the managed forwarding element, identifying one of a plurality of logical middleboxes implemented by the middlebox element for a plurality of logical networks, the tag being associated with the identified logical middlebox; wherein the tag enables the middlebox to use appropriate set of packet processing rules in order to perform operations on the packet;

processing the data packet according to a configuration for the identified logical middlebox; and

sending the processed data packet to the managed forwarding element.

11. The non-transitory machine readable medium of claim 10 , wherein the data packet is sent to the managed forwarding element by one of the end machines hosted on the host computer.

12. The non-transitory machine readable medium of claim 11 , wherein the end machine belongs to a same logical network as the identified logical middlebox.

13. The non-transitory machine readable medium of claim 10 , wherein the tag is prepended to the data packet by the managed forwarding element.

14. The non-transitory machine readable medium of claim 10 , wherein the set of instructions for identifying the logical middlebox comprises a set of instructions for mapping the tag to the logical middlebox using a binding table.

15. The non-transitory machine readable medium of claim 10 , wherein the processed data packet is sent to the managed forwarding element with the tag.

16. The non-transitory machine readable medium of claim 10 , wherein the managed forwarding element sends the data packet to the middlebox element according to a routing policy that routes the data packet based on data other than a destination network address of the data packet.

17. The non-transitory machine readable medium of claim 16 , wherein the field is an ingress port through which the data packet was received, wherein the managed forwarding receives the processed data packet from the middlebox element and subsequently routes the processed data packet based on the destination network address of the processed data packet.

18. The non-transitory machine readable medium of claim 10 , wherein the plurality of logical middleboxes are one of firewalls, network address translators, and load balancers.

Assignments (2)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 20, 2024
From: ZHANG, RONGHUA; KOPONEN, TEEMU; THAKKAR, PANKAJ; PADMANABHAN, AMAR; CASADO, MARTIN
To: NICIRA, INC.
Reel/Frame 068335/0761 →