High availability of host data path with tunneling in software defined networks
Techniques are described for managing connection states at an active network appliance and a backup network appliance. The active network appliance and backup network appliance are configured to process connections in a software defined network (SDN). The active network appliance is configured to actively process connections, and the backup network appliance maintains connection states such that the backup network appliance can actively process connections in response to a failure of the active network appliance.
1 . A method for managing connection states at an active network appliance and a backup network appliance, the method comprising:
receiving, at the active network appliance, a packet associated with a communication session of a VM in a software defined network (SDN), wherein:
the active network appliance and backup network appliance are configured to process connections in the SDN,
the active network appliance is configured to actively process connections and the backup network appliance maintains connection states such that the backup network appliance can actively process the packet associated with the communication session in response to a failure of the active network appliance, and
network interfaces from the VM are provisioned on multiple network interface devices at each of the active and backup network appliances;
identifying an active network interface device on the active network appliance associated with the communication session, wherein a backup network interface device on the backup network appliance is also associated with the communication session;
forwarding the packet to the active network interface device for processing the packet associated with the communication session; and
in response to determining that the active network interface device has failed, causing subsequent packets associated with the communication session to be routed to the backup network interface device associated with the communication session, thereby allowing the backup network interface device to maintain connection state information and avoid performing new connection state processing for the communication session.
2 . The method of claim 1 , wherein the identifying is based on an autonomous system number (ASN) prepend that indicates preference of a route.
3 . The method of claim 2 , wherein the routing is performed using a VXLAN tunnel.
4 . The method of claim 1 , wherein the determining is based on probing the primary and active network interface device and wherein the causing is based on updating customer address (CA) to physical address (PA) mapping.
5 . The method of claim 4 , further comprising advertising BGP without prepend by the primary and secondary network interface devices.
6 . The method of claim 5 , wherein the network appliances are SDN appliances.
7 . The method of claim 6 , wherein a network interface device on the primary SDN appliance is paired with a network interface device from a backup SDN appliance.
8 . The method of claim 7 , wherein pairwise flow replication is implemented for each paired network interface device.
9 . A system comprising:
an active network appliance; and
a backup network appliance;
the system configured to perform operations comprising:
receiving a packet associated with a communication session of a VM in a software defined network (SDN), wherein:
the active network appliance and backup network appliance are configured to process connections in the SDN;
the active network appliance is configured to actively process connections, and the backup network appliance maintains connection states such that the backup network appliance can actively process connections in response to a failure of the active network appliance;
network interfaces from the VM are provisioned on multiple network interface devices at each of the network appliances;
identifying an active network interface device on the active network appliance associated with the communication session, wherein a backup network interface device on the backup network appliance is also associated with the communication session;
forwarding the packet to the active network interface device for processing the packet associated with the communication session; and
in response to determining that the active network interface device has failed, causing subsequent packets associated with the communication session to be routed to the backup network interface device associated with the communication session, thereby allowing the backup network interface device to maintain connection state information and avoid performing new connection state processing for the communication session.
10 . The system of claim 9 , wherein the identifying is based on an autonomous system number (ASN) prepend that indicates preference of a route.
11 . The system of claim 10 , wherein the routing is performed using a VXLAN tunnel.
12 . The system of claim 9 , wherein the determining is based on probing the primary and active network interface device and wherein the causing is based on updating customer address (CA) to physical address (PA) mapping.
13 . The system of claim 12 , wherein the system is configured to perform operations comprising advertising BGP without prepend by the primary and secondary network interface devices.
14 . The system of claim 13 , wherein the network appliances are SDN appliances.
15 . The system of claim 14 , wherein a network interface device on the primary SDN appliance is paired with a network interface device from a backup SDN appliance.
16 . The system of claim 15 , wherein pairwise flow replication is implemented for each paired network interface device.
17 . A network appliance comprising a plurality of network interface devices, the network appliance configured to perform operations comprising:
receiving a packet associated with a communication session of a VM of a software defined network (SDN), wherein:
the network appliance is configured to process connections in the SDN,
the network appliance includes an active network interface device communicatively coupled to a backup network interface device that maintains connection states such that the backup network interface can actively process connections in response to a failure of the active network interface, and
network interfaces from the VM are provisioned on multiple network interface devices at the network appliance;
identifying an active network interface device of the network appliance that is associated with the communication session, wherein a backup network interface device of the network appliance is also associated with the communication session;
forwarding the packet to the active network interface device for processing the packet associated with the communication session; and
in response to determining that the active network interface device has failed, causing subsequent packets associated with the communication session to be routed to the backup network interface device associated with the communication session, thereby allowing the backup network interface device to maintain connection state information and avoid performing new connection state processing for the communication session.
18 . The network appliance of claim 17 , wherein the identifying is based on an autonomous system number (ASN) prepend that indicates preference of a route.
19 . The network appliance of claim 18 , wherein the routing is performed using a VXLAN tunnel.
20 . The network appliance of claim 17 , wherein the determining is based on probing the primary and active network interface device and wherein the causing is based on updating customer address (CA) to physical address (PA) mapping.