IP Library Granted Patent US 12,141,599
Granted Patent B2
US 12,141,599 · App. 18/219,234 · Granted Nov 12, 2024

Architecture of networks with middleboxes

Inventors: Teemu Koponen (San Francisco, CA); Ronghua Zhang (San Jose, CA); Pankaj Thakkar (Cupertino, CA); Martin Casado (Portola Valley, CA)
Assignee: Nicira, Inc.
G06F9/45558G06F9/455G06F9/45533G06F15/177H04L41/08H04L41/0803H04L41/0806H04L41/0813H04L41/0823H04L41/0889H04L41/0893H04L41/12H04L45/64H04L45/74H04L49/70H04L61/2503H04L61/2517H04L61/2521H04L61/256H04L63/0218H04L67/1008G06F2009/4557G06F2009/45595H04L45/02H04L49/15
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,141,599
App. No.
18/219,234
Granted
Nov 12, 2024
Kind
B2
Abstract

Some embodiments provide a system for implementing a logical network that includes a set of end machines, a first logical middlebox, and a second logical middlebox connected by a set of logical forwarding elements. The system includes a set of nodes. Each of several nodes includes (i) a virtual machine for implementing an end machine of the logical network, (ii) a managed switching element for implementing the set of logical forwarding elements of the logical network, and (iii) a middlebox element for implementing the first logical middlebox of the logical network. The system includes a physical middlebox appliance for implementing the second logical middlebox.

Claims (30)

1. A method of performing a middlebox service operation in a data center comprising a plurality of host computers that execute source and destination machines for data message flows, the method comprising:

deploying a set of two or more middlebox service modules to execute on a set of two or more host computers to implement a plurality of distributed logical middleboxes for performing the middlebox service operation for a plurality of logical networks, each distributed logical middlebox implemented by at least two middlebox modules executing on at least two host computers;

distributing at least one logical middlebox service for each logical network;

configuring each middlebox service module with a set of middlebox service rules for the middlebox service modules to use to perform the middlebox service operation; and

wherein each distributed logical middlebox service is identified by a particular identifier, each particular set of middlebox service rules for each particular logical network is associated with the particular identifier of the particular logical network, and each middlebox service module uses a particular tag of the particular logical network to identify the set of middlebox service rules for the particular logical network to use while processing data messages associated with the particular logical network.

2. The method of claim 1 , wherein said configuring comprising configuring at least one middlebox service module with two different sets of middlebox service rules for two different logical networks, each middlebox service module processing flows associated with a machine that is associated with each particular logical network by using the set of middlebox service rules for the particular logical network.

3. The method of claim 1 , wherein the middlebox service operation is a firewall operation.

4. The method of claim 1 , wherein the middlebox service operation is a network address translation operation.

5. The method of claim 1 , wherein the middlebox service operation is a load balancing operation.

6. The method of claim 1 , wherein the source and destination machines comprise virtual machines (VMs).

7. The method of claim 1 , wherein a set of software switches execute on the set of host computers, and the middlebox service modules receive data messages of the data message flows from the software switches in order to perform the middlebox service operation on the data message flows.

8. The method of claim 1 , wherein the set of middlebox service modules is a first set of middlebox service modules and the distributed middlebox service rules are a first set of middlebox service rules, the method further comprising:

deploying a second set of middlebox service modules to execute on a set of devices at a boundary of a network to which the source and destination machines connect; and

configuring the second set of middlebox service modules with a second set of middlebox service rules, the second set of middlebox service modules implementing a centralized middlebox service that processes data message flows entering or exiting the network.

9. The method of claim 8 , wherein the set of devices comprise a set of gateways through which data message flows enter and exit the network.

10. The method of claim 8 , wherein the set of devices comprise a set of gateways through which data message flows enter and exit the network.

11. A system comprising:

a plurality of host computers that execute source and destination machines for data message flows;

a set of two or more middlebox service modules that execute on a set of two or more host computers to implement a plurality of distributed logical middleboxes that perform a middlebox service operation for a plurality of logical networks, each distributed logical middlebox implemented by at least two middlebox modules executing on at least two host computers and distribute at least one logical middlebox service for each logical network; and

a set of controllers that configure each middlebox service module with a set of middlebox service rules for the middlebox service modules to use to perform the middlebox service operation;

wherein each distributed logical middlebox service is identified by a particular identifier, each particular set of middlebox service rules for each particular logical network is associated with the particular identifier of the particular logical network, and each middlebox service module uses a particular tag of the particular logical network to identify the set of middlebox service rules for the particular logical network to use while processing data messages associated with the particular logical network.

12. The system of claim 11 , wherein the set of controllers comprise at least one middlebox service module that configures with two different sets of middlebox service rules for two different logical networks, each middlebox service module processing flows associated with a machine that is associated with each particular logical network by using the set of middlebox service rules for the particular logical network.

13. The system of claim 11 , wherein the middlebox service operation is a firewall operation.

14. The system of claim 11 , wherein the middlebox service operation is a network address translation operation.

15. The system of claim 11 , wherein the middlebox service operation is a load balancing operation.

16. The system of claim 11 , wherein the source and destination machines comprise virtual machines (VMs).

17. The system of claim 11 , wherein a set of software switches execute on the set of host computers, and the middlebox service modules receive data messages of the data message flows from the software switches in order to perform the middlebox service operation on the data message flows.

18. The system of claim 11 , wherein the set of middlebox service modules is a first set of middlebox service modules and the distributed middlebox service rules are a first set of middlebox service rules, the system further comprising:

a second set of middlebox service modules that execute on a set of devices at a boundary of a network to which the source and destination machines connect; and

wherein the second set of middlebox service modules configures with a second set of middlebox service rules, the second set of middlebox service modules implements a centralized middlebox service that processes data message flows entering or exiting the network.

Assignments (2)
MERGER Recorded Jan 27, 2025
From: NICIRA, INC.
To: VMWARE LLC
Reel/Frame 070187/0487 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2024
From: KOPONEN, TEEMU; ZHANG, RONGHUA; THAKKAR, PANKAJ; CASADO, MARTIN
To: NICIRA, INC.
Reel/Frame 068854/0672 →
Continuity (8)
Continuation 17850925 · Jun 27, 2022
Continuation 17140792 · Jan 4, 2021
Continuation 16238446 · Jan 2, 2019
Continuation 15618951 · Jun 9, 2017
Division 14595199 · Jan 12, 2015
Continuation 13678498 · Nov 15, 2012
Provisional Application 61560279 · Nov 15, 2011
Related Publication 20230359479A1 · Nov 9, 2023