IP Library Granted Patent US 12,587,499
Granted Patent B2
US 12,587,499 · App. 18/212,674 · Granted Mar 24, 2026

High-availability egress access with consistent source IP addresses for workloads

Inventors: Quan Tian (Beijing, CN); Jianjun Shen (Redwood City, CA); Donghai Han (Beijing, CN); Shuyang Xin (Shanghai, CN); Wenqi Qiu (Beijing, CN)
Assignee: VMware, Inc.
H04L61/103H04L45/04H04L63/0236
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,587,499
App. No.
18/212,674
Granted
Mar 24, 2026
Kind
B2
Abstract

Systems and methods for configuring an egress node for an egress pod set comprising one or more pods are provided. The egress pod set may be allocated one or more egress internet protocol (IP) addresses. The egress node may be selected among nodes of a cluster including the one or more pods. The egress node may be configured as the routing destination for an egress IP address selected among the one or more egress internet protocol (IP) addresses.

Claims (46)

1 . A method for configuring an egress node for an egress pod set comprising one or more pods, the method comprising:

selecting a node of a cluster of nodes to act as the egress node for the egress pod set, wherein the egress pod set is allocated a plurality of egress internet protocol (IP) addresses;

determining an egress IP address of the plurality of egress IP addresses to be an active egress IP address of the egress pod set based on an IP address of the egress node;

configuring the egress node to receive packets with a destination IP address set to the active egress IP address;

receiving, at the egress node, an encapsulated packet comprising:

an outer header including a destination IP address set as the active egress IP address, and or more pods;

an inner header including a source IP address set as an IP address of one of the one of the one or more pods;

decapsulating the encapsulated packet to generate a packet with a header that is the inner header; and

translating the source IP address of the header of the packet by setting the source IP address as the active egress IP address.

2 . The method of claim 1 , wherein the cluster of nodes are located in a plurality of subnets, and wherein each of the plurality of egress IP addresses is associated with a different subnet of the plurality of subnets.

3 . The method of claim 2 , wherein the plurality of egress IP addresses are ordered in order of preference, and wherein selecting the node comprises selecting the node based on a subnet of the node, subnets of the plurality of egress IP addresses, and the order of preference of the plurality of egress IP addresses.

4 . The method of claim 1 , wherein selecting the node comprises selecting the node based on a number of egress pod sets associated with the node.

5 . The method of claim 1 , wherein configuring the egress node comprises the egress node advertising the active egress IP address as associated with the egress node via address resolution protocol (ARP) or neighbor discover protocol (NDP).

6 . The method of claim 1 , wherein configuring the egress node comprises configuring the active egress IP address as a secondary IP address of the egress node.

7 . The method of claim 1 , further comprising applying a firewall policy to the packet based on the source IP address.

8 . One or more non-transitory computer readable media comprising instructions that, when executed by one or more processors of a computing system, cause the computing system to perform operations for configuring an egress node for an egress pod set comprising one or more pods, the operations comprising:

selecting a node of a cluster of nodes to act as the egress node for the egress pod set, wherein the egress pod set is allocated a plurality of egress internet protocol (IP) addresses;

determining an egress IP address of the plurality of egress IP addresses to be an active egress IP address of the egress pod set based on an IP address of the egress node;

configuring the egress node to receive packets with a destination IP address set to the active egress IP address;

receiving, at the egress node, an encapsulated packet comprising:

an outer header including a destination IP address set as the active egress IP address, and or more pods;

an inner header including a source IP address set as an IP address of one of the one of the one or more pods;

decapsulating the encapsulated packet to generate a packet with a header that is the inner header; and

translating the source IP address of the header of the packet by setting the source IP address as the active egress IP address.

9 . The one or more non-transitory computer readable media of claim 8 , wherein the cluster of nodes are located in a plurality of subnets, and wherein each of the plurality of egress IP addresses is associated with a different subnet of the plurality of subnets.

10 . The one or more non-transitory computer readable media of claim 9 , wherein the plurality of egress IP addresses are ordered in order of preference, and wherein selecting the node comprises selecting the node based on a subnet of the node, subnets of the plurality of egress IP addresses, and the order of preference of the plurality of egress IP addresses.

11 . The one or more non-transitory computer readable media of claim 8 , wherein selecting the node comprises selecting the node based on a number of egress pod sets associated with the node.

12 . The one or more non-transitory computer readable media of claim 8 , wherein configuring the egress node comprises the egress node advertising the active egress IP address as associated with the egress node via address resolution protocol (ARP) or neighbor discover protocol (NDP).

13 . The one or more non-transitory computer readable media of claim 8 , wherein configuring the egress node comprises configuring the active egress IP address as a secondary IP address of the egress node.

14 . A computer system, the computer system comprising:

one or more memories; and

one or more processors, the one or more processors being configured to perform operations for configuring an egress node for an egress pod set comprising one or more pods, the operations comprising:

selecting a node of a cluster of nodes to act as the egress node for the egress pod set, wherein the egress pod set is allocated a plurality of egress internet protocol (IP) addresses;

determining an egress IP address of the plurality of egress IP addresses to be an active egress IP address of the egress pod set based on an IP address of the egress node;

configuring the egress node to receive packets with a destination IP address set to the active egress IP address;

receiving, at the egress node, an encapsulated packet comprising:

an outer header including a destination IP address set as the active egress IP address, and or more pods;

an inner header including a source IP address set as an IP address of one of the one of the one or more pods;

decapsulating the encapsulated packet to generate a packet with a header that is the inner header; and

translating the source IP address of the header of the packet by setting the source IP address as the active egress IP address.

15 . The computer system of claim 14 , wherein the cluster of nodes are located in a plurality of subnets, and wherein each of the plurality of egress IP addresses is associated with a different subnet of the plurality of subnets.

16 . The computer system of claim 15 , wherein the plurality of egress IP addresses are ordered in order of preference, and wherein selecting the node comprises selecting the node based on a subnet of the node, subnets of the plurality of egress IP addresses, and the order of preference of the plurality of egress IP addresses.

17 . The computer system of claim 14 , wherein selecting the node comprises selecting the node based on a number of egress pod sets associated with the node.

18 . The computer system of claim 14 , wherein configuring the egress node comprises the egress node advertising the active egress IP address as associated with the egress node via address resolution protocol (ARP) or neighbor discover protocol (NDP).

19 . The computer system of claim 14 , wherein configuring the egress node comprises configuring the active egress IP address as a secondary IP address of the egress node.

20 . The one or more non-transitory computer readable media of claim 8 , wherein the operations further comprise applying a firewall policy to the packet based on the source IP address.

Assignments (2)
CHANGE OF NAME Recorded May 8, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067355/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2023
From: TIAN, QUAN; SHEN, JIANJUN; HAN, DONGHAI; XIN, SHUYANG; QIU, WENQI
To: VMWARE, INC.
Reel/Frame 065274/0060 →
Continuity (1)
Related Publication 20240388559A1 · Nov 21, 2024
References Cited (8)
US 20110182289A1 · Raman · 2011 [cited by examiner]
US 20210266259A1 · Renner, III et al. · 2021 [cited by applicant]
US 20220029917A1 · Masnauskas et al. · 2022 [cited by applicant]
US 20240388523A1 · Tian et al. · 2024 [cited by applicant]
CN 118435581A · 2024 [cited by examiner]
A Guide to the Kubernetes Networking Model. Kevin Sookocheff Jul. 11, 2018 (Year: 2018). [cited by examiner]
Extended European Search Report, European Application No. 24174619.7 dated Oct. 9, 2024, 11 pages. [cited by applicant]
Sookocheff, Kevin: “A Guide to the Kubernetes Networking Model”, Jul. 11, 2018, pp. 1-29, XP093065536, Retrieved from the Internet: URL: https://sookocheff.com/post/kubernetes/understanding-kubernetes-networking, 29 pag… [cited by applicant]