IP Library Granted Patent US 12,177,130
Granted Patent B2
US 12,177,130 · App. 18/224,466 · Granted Dec 24, 2024

Performing deep packet inspection in a software defined wide area network

Inventors: Navaneeth Krishnan Ramaswamy (Chennai, IN); Ganesh Srinivasan (Chennai, IN)
Assignee: VMware LLC
H04L47/36H04L43/026H04L45/38H04L47/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,177,130
App. No.
18/224,466
Granted
Dec 24, 2024
Kind
B2
Abstract

Some embodiments provide a method for performing deep packet inspection (DPI) for an SD-WAN (software defined, wide area network) established for an entity by a plurality of edge nodes and a set of one or more cloud gateways. At a particular edge node, the method uses local and remote deep packet inspectors to perform DPI for a packet flow. Specifically, the method initially uses the local deep packet inspector to perform a first DPI operation on a set of packets of a first packet flow to generate a set of DPI parameters for the first packet flow. The method then forwards a copy of the set of packets to the remote deep packet inspector to perform a second DPI operation to generate a second set of DPI parameters. In some embodiments, the remote deep packet inspector is accessible by a controller cluster that configures the edge nodes and the gateways. In some such embodiments, the method forwards the copy of the set of packets to the controller cluster, which then uses the remote deep packet inspector to perform the remote DPI operation. The method receives the result of the second DPI operation, and when the generated first and second DPI parameters are different, generates a record regarding the difference.

Claims (34)

1. For an SD-WAN (software defined, wide area network) established by a plurality of edge nodes and a set of one or more cloud gateways, a method of using deep packet inspection (DPI) to control packet flows through the SD-WAN, the method comprising:

at a server,

identifying, from sets of parameters collected for packet flows processed by a first set of two or more edge nodes for which DPI operations were performed, a subset of parameters related to a plurality of flows associated with a particular application identifier specified by the DPI operations;

analyzing the identified subset of parameters to identify at least one particular packet flow with an undesirable path through the SD-WAN; and

distributing adjusted forwarding records to a second set of one or more edge nodes to modify the path used by the second set of edge nodes for the identified particular flow associated with the particular application identifier and the undesirable path through the SD-WAN.

2. The method of claim 1 , wherein at least a subset of the DPI operations is performed at the edge nodes.

3. The method of claim 1 , wherein at least a subset of the DPI operations is performed at a physical location that is remote form physical locations at which the first set of edge nodes operate.

4. The method of claim 1 , wherein the collected sets of parameters comprise operational metrics relating to a set of packet flows processed by the edge nodes.

5. The method of claim 4 , wherein at least a set of the operational metrics are collected at the set of edge nodes.

6. The method of claim 5 , wherein the collected packets comprise packets associated with the particular application identifier specified by DPI operations that were performed for the collected packets.

7. The method of claim 6 , wherein the DPI operations are performed at both source and destination edge nodes.

8. The method of claim 6 , wherein the DPI operations are performed at the source edge node and application identifiers are provided by the source edge nodes to the destination edge nodes.

9. The method of claim 6 , wherein the number of collected packets for a flow relate to number of packets needed for the DPI operation on the flow.

10. The method of claim 4 , wherein at least a set of the operational metrics are collected by at least one gateway.

11. The method of claim 1 , wherein analyzing the identified subset of parameters comprises determining durations of time for packets in each of a plurality of packet flows to traverse from a source edge node of the flow through the SD-WAN to reach a destination edge node of the flow.

12. The method of claim 1 , wherein analyzing the identified subsets of parameters comprises determining durations of time for packets in each flow in a plurality of packet flows to traverse through a gateway to reach a destination edge node for the flow.

13. The method of claim 1 , wherein

a first node initially receives a first forwarding record and then receives a second forwarding record;

based on the first forwarding record, the first node forwards a first packet flow through a first gateway before receiving the second forwarding record; and

based on the second forwarding record, the first node stops forwarding the first packet flow through the first gateway and instead forwards the first packet flow through a second gateway.

14. The method of claim 1 , wherein

a first node initially receives a first forwarding record and then receives a second forwarding record;

based on the first forwarding record, the first node uses a first gateway to forward a first packet flow associated with a first DPI parameter to a first destination of the first packet flow; and

based on the second forwarding record, the first node uses a second gateway to forward a second packet flow associated with the first DPI parameter to a second destination of the second packet flow.

15. The method of claim 1 , wherein first and second destinations are same destination.

16. The method of claim 1 , wherein the first set of edge nodes is a subset of the second set of edge nodes.

17. The method of claim 16 , wherein the second set of edge nodes includes at least one edge node not in the first set.

18. The method of claim 1 further comprising collecting parameters from a set of gateways, wherein the collected parameters comprise statistics collected by the gateways in the set.

19. The method of claim 1 further comprising:

receiving, for each of a plurality of flow passing through the SD-WAN, packets collected by the source and destination edge nodes and parameters associated with the collected packets.

20. A non-transitory machine readable medium storing a program for using deep packet inspection (DPI) to control packet flows through an SD-WAN (software defined, wide area network) established by a plurality of edge nodes, the program for execution on a host computer, the program comprising sets of instructions for:

receiving, from sets of parameters collected for packet flows processed by a first set of two or more edge nodes for which DPI operations were performed, a subset of parameters associated with a plurality of flows relating to a particular application identifier specified by the DPI operations, wherein the first set of edge nodes comprises first and second edge nodes that are edge nodes in different offices or datacenters of an entity for which the SD-WAN is deployed, and the host computer is at a different location than at least one of the first and second edge nodes;

analyzing the identified subset of parameters to identify a set of packet flows that is associated with the particular application identifier and that uses a set of undesirable paths through the SD-WAN; and

to change the path of at least one packet flow in the identified set, distributing adjusted forwarding records to the first and second edge nodes to modify paths used by the first and second edge nodes for at least one flow in the identified set.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 5, 2025
From: VMWARE, LLC
To: VELOCLOUD NETWORKS, LLC
Reel/Frame 072326/0693 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 29, 2024
From: RAMASWAMY, NAVANEETH KRISHNAN; SRINIVASAN, GANESH
To: VMWARE, INC.
Reel/Frame 069051/0651 →
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
Priority Claims (1)
IN 201941051486 · Dec 12, 2019 · national
Continuity (3)
Continuation 17976784 · Oct 29, 2022
Continuation 16792908 · Feb 18, 2020
Related Publication 20230379263A1 · Nov 23, 2023