IP Library › Granted Patent US 12,250,147
Granted Patent B2
US 12,250,147 · App. 18/343,935 · Granted Mar 11, 2025

Scalable multi-tenant underlay network supporting multi-tenant overlay network

Inventors: William Stuart Mackie (Carmel, NY); Marcel Wiget (Zug, CH)
Assignee: Juniper Networks, Inc.
H04L45/64H04L12/4641H04L41/12H04L45/586H04L49/252H04L49/354H04L61/256
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,147
App. No.
18/343,935
Filed
Jun 29, 2023
Granted
Mar 11, 2025
Kind
B2
Art Unit
2461
USPC
370/254
Abstract

Techniques are disclosed for scalable virtualization of tenants and subtenants on a virtualized computing infrastructure. In one example, a first controller for the virtualized computing infrastructure configures underlay network segments in the virtualized computing infrastructure by configuring respective Virtual Extensible Local Area Network (VXLAN) segments of a plurality of VXLAN segments of a VXLAN in a switch fabric comprising network switches. Each VXLAN segment provides underlay network connectivity among a different subset of host computing devices of the virtualized computing infrastructure to enable orchestration of multiple tenants in the VXLAN. A second controller for a first subset of the host computing devices has underlay network connectivity through operation of a first VXLAN segment. The second controller configures overlay networks in the first subset of the host computing devices to enable orchestration of multiple subtenants in the first subset of the host computing devices.

Claims (44)

1. A method comprising:

configuring, by a controller for a virtualized computing infrastructure, a plurality of Virtual Extensible Local Area Network (VXLAN) segments in a switch fabric, thereby enabling orchestration of respective tenants in the plurality of VXLAN segments,

wherein each VXLAN segment of the plurality of VXLAN segments provides underlay network connectivity among a different subset of host computing devices of the virtualized computing infrastructure, and

wherein a plurality of overlay networks are configured in a first subset of the host computing devices having underlay network connectivity by operation of a first VXLAN segment of the plurality of VXLAN segments, thereby enabling orchestration of multiple subtenants of a first tenant in the first subset of the host computing devices; and

assigning, by the controller and to the first VXLAN segment, a plurality of floating IP (FIP) addresses for configuring overlay networks of the plurality of overlay networks configured in the first subset of the host computing devices.

2. The method of claim 1 , further comprising assigning, by the controller and to each overlay network of the plurality of overlay networks configured in the first subset of the host computing devices, a different subset of the plurality of FIP addresses.

3. The method of claim 2 , further comprising assigning, by the controller and to each virtual router of a plurality of virtual routers of a first overlay network of the plurality of overlay networks, a different FIP address of a first subset of the plurality of FIP addresses, the first subset assigned to the first overlay network.

4. The method of claim 1 , wherein the plurality of FIP addresses comprises a first plurality of FIP addresses, the method further comprising:

assigning, by the controller and to a second VXLAN segment of the plurality of VXLAN segments, a second plurality of FIP addresses for configuring overlay networks of the plurality of overlay networks configured in a second subset of the host computing devices having underlay network connectivity by operation of the second VXLAN segment, wherein the second plurality of FIP addresses are different from the first plurality of FIP addresses.

5. The method of claim 1 , wherein the plurality of FIP addresses comprises a first plurality of FIP addresses, the method further comprising:

assigning, by the controller and to a second VXLAN segment of the plurality of VXLAN segments, a second plurality of FIP addresses for configuring overlay networks of the plurality of overlay networks configured in a second subset of the host computing devices having underlay network connectivity by operation of the second VXLAN segment, wherein the second plurality of FIP addresses are the same as the first plurality of FIP addresses.

6. The method of claim 1 , further comprising:

assigning, by the controller and to each VXLAN segment of the plurality of VXLAN segments, a different tenant of the respective tenants; and

controlling, by the controller, forwarding of network traffic for each tenant of the respective tenants to the corresponding VXLAN segment of the plurality of VXLAN segments to which the tenant is assigned.

7. The method of claim 1 , further comprising:

assigning, by the controller and to each overlay network of the plurality of overlay networks in the first subset of the host computing devices, a different subtenant of the multiple subtenants of the first tenant; and

controlling, by the controller, forwarding of network traffic for each subtenant of the multiple subtenants of the first tenant to the corresponding overlay network of the plurality of overlay networks in the first subset of the host computing devices to which the subtenant is assigned.

8. The method of claim 1 , further comprising provisioning, by the controller and for the first VXLAN segment, a Source Network Address Translation (SNAT) gateway between a VXLAN Tunnel Endpoint (VTEP) of the first VXLAN segment and the plurality of overlay networks of the first VXLAN segment.

9. The method of claim 8 , wherein provisioning, for the first VXLAN segment, the SNAT gateway comprises provisioning, in a virtual router of the first subset of the host computing devices, the SNAT gateway.

10. The method of claim 1 , further comprising configuring, for a first overlay network of the plurality of overlay networks in the first subset of the host computing devices, a plurality of virtual routers configured to process network traffic for a subtenant of the multiple subtenants that is assigned to the first overlay network.

11. A computing system comprising processing circuitry having access to a memory, the processing circuitry configured to execute a controller for a virtualized computing infrastructure, the controller configured to:

configure a plurality of Virtual Extensible Local Area Network (VXLAN) segments in a switch fabric, thereby enabling orchestration of respective tenants in the plurality of VXLAN segments,

wherein each VXLAN segment of the plurality of VXLAN segments provides underlay network connectivity among a different subset of host computing devices of the virtualized computing infrastructure, and

wherein a plurality of overlay networks are configured in a first subset of the host computing devices having underlay network connectivity by operation of a first VXLAN segment of the plurality of VXLAN segments, thereby enabling orchestration of multiple subtenants of a first tenant in the first subset of the host computing devices; and

assign, to the first VXLAN segment, a plurality of floating IP (FIP) addresses for configuring overlay networks of the plurality of overlay networks configured in the first subset of the host computing devices.

12. The computing system of claim 11 , wherein the controller is further configured to assign, to each overlay network of the plurality of overlay networks configured in the first subset of the host computing devices, a different subset of the plurality of FIP addresses.

13. The computing system of claim 11 , wherein the controller is further configured to assign, to each virtual router of a plurality of virtual routers of a first overlay network of the plurality of overlay networks, a different FIP address of a first subset of the plurality of FIP addresses, the first subset assigned to the first overlay network.

14. The computing system of claim 11 , wherein the plurality of FIP addresses comprises a first plurality of FIP addresses, wherein the controller is further configured to:

assign, to a second VXLAN segment of the plurality of VXLAN segments, a second plurality of FIP addresses for configuring overlay networks of the plurality of overlay networks configured in a second subset of the host computing devices having underlay network connectivity by operation of the second VXLAN segment, wherein the second plurality of FIP addresses are different from the first plurality of FIP addresses.

15. The computing system of claim 11 , wherein the plurality of FIP addresses comprises a first plurality of FIP addresses, wherein the controller is further configured to:

assign, to a second VXLAN segment of the plurality of VXLAN segments, a second plurality of FIP addresses for configuring overlay networks of the plurality of overlay networks configured in a second subset of the host computing devices having underlay network connectivity by operation of the second VXLAN segment, wherein the second plurality of FIP addresses are the same as the first plurality of FIP addresses.

16. The computing system of claim 11 , wherein the controller is further configured to:

assign, to each VXLAN segment of the plurality of VXLAN segments, a different tenant of the respective tenants; and

control forwarding of network traffic for each tenant of the respective tenants to the corresponding VXLAN segment of the plurality of VXLAN segments to which the tenant is assigned.

17. The computing system of claim 11 , wherein the controller is further configured to:

assign, to each overlay network of the plurality of overlay networks in the first subset of the host computing devices, a different subtenant of the multiple subtenants of the first tenant; and

control forwarding of network traffic for each subtenant of the multiple subtenants of the first tenant to the corresponding overlay network of the plurality of overlay networks in the first subset of the host computing devices to which the subtenant is assigned.

18. The computing system of claim 11 , wherein the controller is further configured to provision, for the first VXLAN segment, a Source Network Address Translation (SNAT) gateway between a VXLAN Tunnel Endpoint (VTEP) of the first VXLAN segment and the plurality of overlay networks of the first VXLAN segment.

19. The computing system of claim 18 , wherein, to provision, for the first VXLAN segment, the SNAT gateway, the controller is configured to provision, in a virtual router of the first subset of the host computing devices, the SNAT gateway.

20. Non-transitory, computer-readable media comprising instructions that, when executed, are configured to cause processing circuitry to:

configure a plurality of Virtual Extensible Local Area Network (VXLAN) segments in a switch fabric, thereby enabling orchestration of respective tenants in the plurality of VXLAN segments,

wherein each VXLAN segment of the plurality of VXLAN segments provides underlay network connectivity among a different subset of host computing devices of virtualized computing infrastructure, and

wherein a plurality of overlay networks are configured in a first subset of the host computing devices having underlay network connectivity by operation of a first VXLAN segment of the plurality of VXLAN segments, thereby enabling orchestration of multiple subtenants of a first tenant in the first subset of the host computing devices; and

assign, to the first VXLAN segment, a plurality of floating IP (FIP) addresses for configuring overlay networks of the plurality of overlay networks configured in the first subset of the host computing devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2025
From: MACKIE, WILLIAM STUART; WIGET, MARCEL
To: JUNIPER NETWORKS, INC.
Reel/Frame 072546/0001 →
Continuity (3)
Continuation 17301288 · Mar 30, 2021
Continuation 16370091 · Mar 29, 2019
Related Publication 20230344759A1 · Oct 26, 2023
References Cited (48)
US 9571394B1 · Sivaramakrishnan et al. · 2017 [cited by applicant]
US 9912582B2 · Pourzandi et al. · 2018 [cited by applicant]
US 9948579B1 · Sivaramakrishnan · 2018 [cited by applicant]
US 10009443B1 · Guigli · 2018 [cited by applicant]
US 10972386B2 · Mackie · 2021 [cited by examiner]
US 11316822B1 · Gawade · 2022 [cited by examiner]
US 11736396B2 · Mackie · 2023 [cited by examiner]
US 20130329548A1 · Nakil et al. · 2013 [cited by applicant]
US 20130332577A1 · Nakil et al. · 2013 [cited by applicant]
US 20140064283A1 · Balus et al. · 2014 [cited by applicant]
US 20140233569A1 · Yong et al. · 2014 [cited by applicant]
US 20140372582A1 · Ghanwani · 2014 [cited by examiner]
US 20150156118A1 · Madani et al. · 2015 [cited by applicant]
US 20150304117A1 · Dong et al. · 2015 [cited by applicant]
US 20160105393A1 · Thakkar et al. · 2016 [cited by applicant]
US 20160134528A1 · Lin et al. · 2016 [cited by applicant]
US 20160188527A1 · Cherian et al. · 2016 [cited by applicant]
US 20170346736A1 · Chander et al. · 2017 [cited by applicant]
US 20180131605A1 · Jain · 2018 [cited by applicant]
US 20180173557A1 · Nakil et al. · 2018 [cited by applicant]
US 20180254981A1 · Babu et al. · 2018 [cited by applicant]
US 20190042325A1 · Nair · 2019 [cited by examiner]
US 20190068493A1 · Ram et al. · 2019 [cited by applicant]
US 20200036624A1 · Michael et al. · 2020 [cited by applicant]
US 20210218672A1 · Mackie et al. · 2021 [cited by applicant]
CA 3207315A1 · 2018 [cited by applicant]
CN 105224385A · 2016 [cited by applicant]
CN 108540381A · 2018 [cited by applicant]
WO 20131848846A1 · 2013 [cited by applicant]
WO 2016063267A1 · 2016 [cited by applicant]
WO 2018044341A1 · 2018 [cited by applicant]
First Examination Report, and Translation Thereof, from Counterpart Chinese Application No. 202210858421.2 dated Jul. 28, 2023, 18 pp. [cited by applicant]
“Cisco Programmable Fabric with VXLAN BGP EVPN Configuration Guide,” Multi-Tenancy, Jan. 28, 2019, 18 pp. [cited by applicant]
“Configuring VXLANs,” Cisco Nexus, Sep. 18, 2018, 20 pp. [cited by applicant]
“Deploy a VXLAN Network with an MP-BGP EVPN Control Plane,” Cisco, Jun. 2015, 17 pp. [cited by applicant]
Communication pursuant to Article 94(3) EPC from counterpart European Application No. 19181482.1 dated Aug. 5, 2022, 9 pp. [cited by applicant]
Extended Search Report from counterpart European Application No. 19181482.1, dated Jan. 16, 2020, 9 pp. [cited by applicant]
Fekih Ahmed, “Towards Flexible, Scalable and Autonomic Virtual Tenant Slices,” Montreal, Jan. 28, 2014, 170 pp. [cited by applicant]
First Office Action and Search Report, and translation thereof, from counterpart Chinese Application No. 201910923130.5, dated Jul. 19, 2021, 17 pp. [cited by applicant]
Prosecution History for U.S. Appl. No. 16/370,091, dated Jul. 17, 2020 to Dec. 9, 2020, 25 pp. [cited by applicant]
Prosecution History from U.S. Appl. No. 17/301,288, dated Apr. 21, 2021 through Apr. 3, 2023, 26 pp. [cited by applicant]
Response to Communication pursuant to Article 94(3) EPC dated Aug. 5, 2022, from counterpart European Application No. 19181482.1 filed Dec. 5, 2022, 16 pp. [cited by applicant]
Response to Extended Search Report from counterpart European Application No. 19181482.1, filed Mar. 29, 2021, 4 pp. [cited by applicant]
Notice of Intent to Grant, and translation thereof, from counterpart Chinese Application No. 202210858421.2 dated Feb. 28, 2024, 6 pp. [cited by applicant]
“Contrail Architecture,” White Paper, Juniper Networks, Dec. 31, 2015, 44 pp. [cited by applicant]
Summons to Attend Oral Proceedings Pursuant to Rule 115(1) EPC from counterpart European Application No. 19181482.1 dated Apr. 19, 2024, 12 pp. [cited by applicant]
Extended Search Report from counterpart European Application No. 24194951.0 dated Dec. 11, 2024, 12 pp. [cited by applicant]
Juniper Networks, “Contrail Architecture”, White Papers, Juniper Networks, Inc., Sep. 2015, 44 pp. [cited by applicant]