IP Library Granted Patent US 12,407,598
Granted Patent B2
US 12,407,598 · App. 18/119,208 · Granted Sep 2, 2025

Connectivity between virtual datacenters

Inventors: Hitesh Patel (Newark, CA); Dileep K. Devireddy (San Jose, CA); Mingsheng Peng (Pleasanton, CA)
Assignee: VMware LLC
H04L45/586H04L45/02H04L45/3065H04L45/42H04L67/567
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,407,598
App. No.
18/119,208
Granted
Sep 2, 2025
Kind
B2
Abstract

Some embodiments provide a method that receives (i) definition of a group of virtual datacenters and (ii) addition of at least two virtual datacenters to the group. Each virtual datacenter is defined in a public cloud and includes a set of network management components and a set of network endpoints connected by a logical network that is managed by the network management components of the virtual datacenter. Based on the definition of the group, the method configures a gateway router to which each of the virtual datacenters of the group connect. The gateway router is for routing traffic between the virtual datacenters of the group. The method also configures, at each respective virtual datacenter, a respective router to route data traffic between the respective virtual datacenter and the other virtual datacenters to route traffic for the other virtual datacenters to the gateway router.

Claims (45)

1. A method for routing data traffic between a group of virtual datacenters implemented in a public cloud, the method comprising:

at a gateway router to which each of at least two of the virtual datacenters in the group of virtual datacenters connect, each respective virtual datacenter comprising a respective set of network management components implemented in the public cloud and a respective set of network endpoints executing in the public cloud and connected by a respective logical network that is managed by the respective network management components of respective virtual datacenter:

receiving routes advertised by the respective logical network at each of the virtual datacenters that connect to the gateway router; and

using the received routes to route data traffic, sent between the logical networks of the virtual datacenters of the group, to routers configured between the logical networks at each of the virtual datacenters and the gateway router;

wherein first traffic entering and exiting a virtual datacenter is associated with a first tier router and a second traffic between the network management components is associated with a second tier router, the first tier router and the second tier router being configured to separate the first traffic and the second traffic, the first tier router being a tier-0 router, the second tier router being a tier-1 router, a virtual datacenter being defined with two tier-1 routers connected to a tier-0 router, the tier-0 router comprising a logical router configured to handle traffic entering and exiting the virtual datacenter, the two tier-1 routers comprising a management gateway and a compute gateway segregated by the tier-0 router.

2. The method of claim 1 , wherein the routes for each virtual datacenter comprise (i) routes for network addresses associated with the network management components of the virtual datacenter and (ii) routes for network addresses associated with the logical network endpoints of the virtual datacenter.

3. The method of claim 1 , wherein (i) the gateway router and (ii) the routers configured for each of the virtual datacenters to connect the virtual datacenters to the gateway router are configured by a cloud management platform.

4. The method of claim 1 , wherein the logical network at a particular virtual datacenter comprises:

a first logical router for handling data traffic entering and exiting the particular virtual datacenter;

a second logical router for connecting one or more management network segments to the first logical router, wherein the network management components are connected to the management network segments; and

a third logical router for connecting one or more logical network segments with network endpoints to the first logical router.

5. The method of claim 4 , wherein the routes received from the particular datacenter are advertised by the second and third logical routers.

6. The method of claim 1 further comprising:

receiving routes for network addresses associated with a virtual private cloud (VPC) of the public cloud that hosts services native to the public cloud; and

using the routes for the network addresses associated with the VPC to route data traffic, sent from the logical networks of the virtual datacenters to the services hosted at the VPC, to a network attachment for the VPC.

7. The method of claim 1 , wherein the group is associated with a particular enterprise, wherein the gateway router is a first gateway router, wherein the method further comprises:

receiving routes for network addresses associated with an on-premises datacenter of the enterprise that belongs to the group; and

using the routes for the network addresses associated with the on-premises datacenter to route data traffic, sent from the logical networks of the virtual datacenters to network endpoints located at the on-premises datacenter, to a second gateway router that provides connectivity for the on-premises datacenter.

8. The method of claim 7 , wherein the second gateway is implemented in the public cloud and uses one of a virtual private network (VPN) and a dedicated line to communicate with the on-premises datacenter.

9. The method of claim 7 , wherein the first gateway router (i) allows data traffic between the virtual datacenters and the on-premises datacenter, (ii) allows data traffic between the virtual datacenters and any VPCs added to the group, (iii) does not allow traffic between the on-premises datacenter and any other on-premises datacenters added to the group, and (iv) does not allow traffic between the on-premises datacenter and any VPCs added to the group.

10. The method of claim 1 , wherein the gateway router and the at least two datacenters are located in a first region of the public cloud, wherein the gateway router is a first gateway router, wherein the method further comprises:

receiving routes advertised by the respective logical networks at each of a set of one or more virtual datacenters that are located in a second region of the public cloud and connect to a second gateway router also located in the second region of the public cloud; and

using said routes to route data traffic, sent from the logical networks of the virtual datacenters located in the first region to the logical networks of the virtual datacenters located in the second region, to the second gateway router.

11. The method of claim 1 , wherein the gateway router is implemented as a horizontally scalable router in the public cloud.

12. A non-transitory machine-readable medium storing a program which when executed by at least one processing unit implements a gateway router for routing data traffic between a group of virtual datacenters implemented in a public cloud, the program comprising sets of instructions for:

receiving routes advertised by a respective logical network at each of at least two virtual datacenters in the group of virtual datacenters that connect to the gateway router, each respective virtual datacenter comprising a respective set of network management components implemented in the public cloud and a respective set of network endpoints executing in the public cloud and connected by a respective logical network that is managed by the respective network management components of respective virtual datacenter; and

using the received routes to route data traffic, sent between the logical networks of the virtual datacenters of the group, to routers configured between the logical networks at each of the virtual datacenters and the gateway router;

wherein a first traffic entering and existing a virtual datacenter is associated with a first tier router and a traffic between the network management components is associated with a second tier router, the first tier router and the second tier router being configured to separate the first traffic and the second traffic, the first tier router being a tier-0 router, the second tier router being a tier-1 router, a virtual datacenter being defined with two tier-1 routers connected to a tier-0 router, the tier-0 router comprising a logical router configured to handle traffic entering and exiting the virtual datacenter, the two tier-1 routers comprising a management gateway and a compute gateway segregated by the tier-0 router.

13. The non-transitory machine-readable medium of claim 12 , wherein the routes for each virtual datacenter comprise (i) routes for network addresses associated with the network management components of the virtual datacenter and (ii) routes for network addresses associated with the logical network endpoints of the virtual datacenter.

14. The non-transitory machine-readable medium of claim 12 , wherein (i) the gateway router and (ii) the routers configured for each of the virtual datacenters to connect the virtual datacenters to the gateway router are configured by a cloud management platform.

15. The non-transitory machine-readable medium of claim 12 , wherein the logical network at a particular virtual datacenter comprises:

a first logical router for handling data traffic entering and exiting the particular virtual datacenter;

a second logical router for connecting one or more management network segments to the first logical router, wherein the network management components are connected to the management network segments; and

a third logical router for connecting one or more logical network segments with network endpoints to the first logical router.

16. The non-transitory machine-readable medium of claim 12 , wherein the program further comprises sets of instructions for:

receiving routes for network addresses associated with a virtual private cloud (VPC) of the public cloud that hosts services native to the public cloud; and

using the routes for the network addresses associated with the VPC to route data traffic, sent from the logical networks of the virtual datacenters to the services hosted at the VPC, to a network attachment for the VPC.

17. The non-transitory machine-readable medium of claim 12 , wherein the group is associated with a particular enterprise, wherein the gateway router is a first gateway router, wherein the program further comprises sets of instructions for:

receiving routes for network addresses associated with an on-premises datacenter of the enterprise that belongs to the group; and

using the routes for the network addresses associated with the on-premises datacenter to route data traffic, sent from the logical networks of the virtual datacenters to network endpoints located at the on-premises datacenter, to a second gateway router that provides connectivity for the on-premises datacenter.

18. The non-transitory machine-readable medium of claim 17 , wherein the second gateway is implemented in the public cloud and uses one of a virtual private network (VPN) and a dedicated line to communicate with the on-premises datacenter.

19. The non-transitory machine-readable medium of claim 17 , wherein the first gateway router (i) allows data traffic between the virtual datacenters and the on-premises datacenter, (ii) allows data traffic between the virtual datacenters and any VPCs added to the group, (iii) does not allow traffic between the on-premises datacenter and any other on-premises datacenters added to the group, and (iv) does not allow traffic between the on-premises datacenter and any VPCs added to the group.

20. The non-transitory machine-readable medium of claim 2 , wherein the gateway router and the at least two datacenters are located in a first region of the public cloud, wherein the gateway router is a first gateway router, wherein the program further comprises sets of instructions for:

receiving routes advertised by the respective logical networks at each of a set of one or more virtual datacenters that are located in a second region of the public cloud and connect to a second gateway router also located in the second region of the public cloud; and

using said routes to route data traffic, sent from the logical networks of the virtual datacenters located in the first region to the logical networks of the virtual datacenters located in the second region, to the second gateway router.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2025
From: PATEL, HITESH; DEVIREDDY, DILEEP K.; PENG, MINGSHENG
To: VMWARE, INC.
Reel/Frame 071130/0797 →
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
Continuity (2)
Continuation 17212662 · Mar 25, 2021
Related Publication 20230239238A1 · Jul 27, 2023
References Cited (96)
US 8830835B2 · Casado et al. · 2014 [cited by applicant]
US 8964767B2 · Koponen et al. · 2015 [cited by applicant]
US 9137052B2 · Koponen et al. · 2015 [cited by applicant]
US 9209998B2 · Casado et al. · 2015 [cited by applicant]
US 9288081B2 · Casado et al. · 2016 [cited by applicant]
US 9444651B2 · Koponen et al. · 2016 [cited by applicant]
US 9755960B2 · Moisand et al. · 2017 [cited by applicant]
US 9876672B2 · Casado et al. · 2018 [cited by applicant]
US 9935880B2 · Hammam et al. · 2018 [cited by applicant]
US 10091028B2 · Koponen et al. · 2018 [cited by applicant]
US 10193708B2 · Koponen et al. · 2019 [cited by applicant]
US 10735263B1 · McAlary et al. · 2020 [cited by applicant]
US 10754696B1 · Chinnam et al. · 2020 [cited by applicant]
US 10931481B2 · Casado et al. · 2021 [cited by applicant]
US 11005710B2 · Garg et al. · 2021 [cited by applicant]
US 11005963B2 · Maskalik et al. · 2021 [cited by applicant]
US 11171878B1 · Devireddy et al. · 2021 [cited by applicant]
US 11212238B2 · Cidon et al. · 2021 [cited by applicant]
US 11240203B1 · Eyada · 2022 [cited by examiner]
US 11362992B2 · Devireddy et al. · 2022 [cited by applicant]
US 11582147B2 · Raman et al. · 2023 [cited by applicant]
US 11588819B1 · Wei · 2023 [cited by examiner]
US 11606290B2 · Patel et al. · 2023 [cited by applicant]
US 11729094B2 · Arumugam et al. · 2023 [cited by applicant]
US 11729095B2 · Sadasivan et al. · 2023 [cited by applicant]
US 20070058604A1 · Lee et al. · 2007 [cited by applicant]
US 20080159150A1 · Ansari · 2008 [cited by applicant]
US 20090003235A1 · Jiang · 2009 [cited by applicant]
US 20090296713A1 · Kompella · 2009 [cited by applicant]
US 20090307713A1 · Anderson et al. · 2009 [cited by applicant]
US 20110126197A1 · Larsen et al. · 2011 [cited by applicant]
US 20110131338A1 · Hu · 2011 [cited by applicant]
US 20120054624A1 · Owens, Jr. et al. · 2012 [cited by applicant]
US 20120110651A1 · Biljon et al. · 2012 [cited by applicant]
US 20130044641A1 · Koponen et al. · 2013 [cited by applicant]
US 20130044751A1 · Casado et al. · 2013 [cited by applicant]
US 20130044752A1 · Koponen et al. · 2013 [cited by applicant]
US 20130044761A1 · Koponen et al. · 2013 [cited by applicant]
US 20130044762A1 · Casado et al. · 2013 [cited by applicant]
US 20130044763A1 · Koponen et al. · 2013 [cited by applicant]
US 20130044764A1 · Casado et al. · 2013 [cited by applicant]
US 20130142203A1 · Koponen et al. · 2013 [cited by applicant]
US 20130185413A1 · Beaty et al. · 2013 [cited by applicant]
US 20130283364A1 · Chang et al. · 2013 [cited by applicant]
US 20140282525A1 · Sapuram et al. · 2014 [cited by applicant]
US 20140334495A1 · Stubberfield · 2014 [cited by examiner]
US 20140376367A1 · Jain et al. · 2014 [cited by applicant]
US 20150113146A1 · Fu · 2015 [cited by examiner]
US 20150193246A1 · Luft · 2015 [cited by applicant]
US 20160105392A1 · Thakkar et al. · 2016 [cited by applicant]
US 20160127202A1 · Dalvi et al. · 2016 [cited by applicant]
US 20160170809A1 · Schmidt et al. · 2016 [cited by applicant]
US 20160182336A1 · Doctor et al. · 2016 [cited by applicant]
US 20160234161A1 · Banerjee et al. · 2016 [cited by applicant]
US 20170033924A1 · Jain et al. · 2017 [cited by applicant]
US 20170063673A1 · Maskalik et al. · 2017 [cited by applicant]
US 20170195517A1 · Seetharaman et al. · 2017 [cited by applicant]
US 20170353351A1 · Cheng · 2017 [cited by examiner]
US 20180270308A1 · Shea et al. · 2018 [cited by applicant]
US 20180287902A1 · Chitalia et al. · 2018 [cited by applicant]
US 20180295036A1 · Krishnamurthy et al. · 2018 [cited by applicant]
US 20180332001A1 · Redondo Ferrero · 2018 [cited by examiner]
US 20190068500A1 · Hira · 2019 [cited by applicant]
US 20190104051A1 · Cidon et al. · 2019 [cited by applicant]
US 20190104413A1 · Cidon et al. · 2019 [cited by applicant]
US 20190149360A1 · Casado et al. · 2019 [cited by applicant]
US 20190149463A1 · Bajaj et al. · 2019 [cited by applicant]
US 20190327112A1 · Nandoori et al. · 2019 [cited by applicant]
US 20190342179A1 · Barnard et al. · 2019 [cited by applicant]
US 20200235990A1 · Janakiraman · 2020 [cited by examiner]
US 20210067375A1 · Cidon et al. · 2021 [cited by applicant]
US 20210067439A1 · Kommula et al. · 2021 [cited by applicant]
US 20210067468A1 · Cidon et al. · 2021 [cited by applicant]
US 20210075727A1 · Chen et al. · 2021 [cited by applicant]
US 20210112034A1 · Sundararajan et al. · 2021 [cited by applicant]
US 20210126860A1 · Ramaswamy et al. · 2021 [cited by applicant]
US 20210136140A1 · Tidemann et al. · 2021 [cited by applicant]
US 20210184898A1 · Koponen et al. · 2021 [cited by applicant]
US 20210314388A1 · Zhou et al. · 2021 [cited by applicant]
US 20210336886A1 · Vijayasankar et al. · 2021 [cited by applicant]
US 20210359948A1 · Durrani et al. · 2021 [cited by applicant]
US 20220094666A1 · Devireddy et al. · 2022 [cited by applicant]
US 20220311707A1 · Patel et al. · 2022 [cited by applicant]
US 20220311714A1 · Devireddy et al. · 2022 [cited by applicant]
US 20220377009A1 · Raman et al. · 2022 [cited by applicant]
US 20220377020A1 · Sadasivan et al. · 2022 [cited by applicant]
US 20220377021A1 · Sadasivan et al. · 2022 [cited by applicant]
US 20230006920A1 · Arumugam et al. · 2023 [cited by applicant]
US 20230006941A1 · Natarajan et al. · 2023 [cited by applicant]
CN 101977156A · 2011 [cited by applicant]
CN 111478850A · 2020 [cited by applicant]
WO 2013026050A1 · 2013 [cited by applicant]
WO 2022060464A1 · 2022 [cited by applicant]
WO 2022250735A1 · 2022 [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/235,869, filed Aug. 20, 2023, 50 pages, VMware, Inc. [cited by applicant]
Non-Published Commonly Owned U.S. Appl. No. 18/235,874, filed Aug. 20, 2023, 69 pages, VMware, Inc. [cited by applicant]