IP Library Granted Patent US 12,375,533
Granted Patent B2
US 12,375,533 · App. 18/605,095 · Granted Jul 29, 2025

Network address translation in active-active edge cluster

Inventors: Yong Wang (San Jose, CA); Jayant Jain (Cupertino, CA); Ganesh Sadasivan (Fremont, CA); Abhishek Goliya (Pune, IN)
Assignee: VMware LLC
H04L65/1036H04L45/38H04L61/256H04L61/2596
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,375,533
App. No.
18/605,095
Granted
Jul 29, 2025
Kind
B2
Abstract

Some embodiments provide a method for forwarding data messages at multiple edge gateways of a logical network that process data messages between the logical network and an external network. At a first edge gateway, the method receives a data message, having an external address as a destination address, from the logical network. Based on the destination address, the method applies a default route to the data message that routes the data message to a second edge gateway and specifies a first output interface of the first edge gateway for the data message. After routing the data message, the method applies a stored NAT entry that (i) modifies a source address of the data message to be a public NAT address associated with the first edge gateway and (ii) redirects the modified data message to a second output interface of the first edge gateway instead of the first output interface.

Claims (37)

1. A method for operating an edge gateway device, the method comprising:

receiving a first data message from an external network, the first data message having an external address as a source address and a public NAT address as a destination address;

performing network address translation (NAT) on the first data message to modify the destination address to be a logical network address associated with a particular machine in a logical network; and

receiving a second data message from the logical network, the second data message having an external address as a destination address;

based on the external destination address of the second data message, applying a default route to the second data message that routes the second data message to a second one of a plurality of edge gateways and specifies a first output interface of a first edge gateway of the plurality of edge gateways for the second data message; and

after routing the second data message, applying a stored NAT entry for modifying a source address of the second data message to be a public NAT address associated with the first edge gateway.

2. The method of claim 1 , wherein:

the first output interface comprises an interface for traffic between the first edge gateway and other edge gateways; and

a second output interface, of the first edge gateway, comprises an uplink interface for connecting to external networks.

3. The method of claim 1 , wherein: the NAT entry maps the logical network address to the public NAT address for a data message flow to which the first and second data messages belong, wherein the NAT entry redirects the second data message to a second output interface of the first edge gateway instead of the first output interface of the first edge gateway.

4. The method of claim 3 , wherein the stored NAT entry identifies the data message flow based on source and destination network addresses, source and destination transport layer port numbers, and transport layer protocol.

5. The method of claim 1 , wherein the logical network is implemented in a virtual datacenter configured on a set of host computers in a public cloud, the virtual datacenter comprising (i) a set of workloads executing on the host computers and (ii) the plurality of edge gateways executing on the host computers.

6. The method of claim 5 , wherein:

the virtual datacenter workloads comprise (i) a set of network management components and (ii) a set of logical network endpoints connected by the logical network; and

the logical network is managed by the network management components of the virtual datacenter.

7. The method of claim 5 , wherein the external address corresponds to a virtual desktop client connecting to a shared resource operating on one or more workloads in the virtual datacenter.

8. The method of claim 7 , wherein the shared resource receives a plurality of connections from a plurality of virtual desktop clients via a plurality of edge gateways.

9. The method of claim 5 , wherein the default route routes the second data message to the second edge gateway because the second edge gateway provides a set of services for the virtual datacenter workloads that are not scaled to all of the edge gateways.

10. The method of claim 9 , wherein the set of services comprises at least one of domain name service (DNS) and virtual private network (VPN) service.

11. The method of claim 1 , wherein:

applying the stored NAT entry to redirect the second data message further comprises modifying a media access control (MAC) address of the second data message from a source MAC address corresponding to the first output interface to a source MAC address corresponding to a second output interface.

12. The method of claim 11 , wherein the stored NAT entry comprises a data link layer header based on a third data message previously received from the external network.

13. The method of claim 1 , wherein the edge gateways comprise at least two groups of edge gateways, each group associated with a different NAT address.

14. The method of claim 13 , wherein the first and second edge gateways belong to different groups.

15. A non-transitory machine-readable medium storing a program for execution by at least one processing unit of a host computer that implements a first edge gateway, the program comprising sets of instructions for:

receiving a first data message from an external network having an external address as a source address and a public NAT address as a destination address;

performing network address translation (NAT) on the first data message to modify the destination address to be a logical network address associated with a particular machine in a logical network; and

receiving a second data message from a logical network, the second data message having an external address as a destination address;

based on the external destination address of the second data message, applying a default route to the second data message that routes the second data message to a second one of a plurality of edge gateways and specifies a first output interface of the first edge gateway for the second data message; and

after routing the second data message, applying a stored NAT entry for modifying a source address of the second data message to be a public NAT address associated with the first edge gateway.

16. The non-transitory machine-readable medium of claim 15 , wherein:

the first output interface comprises an interface for traffic between the first edge gateway and other edge gateways; and

a second output interface, of the first edge gateway, comprises an uplink interface for connecting to external networks.

17. The non-transitory machine-readable medium of claim 15 , wherein the NAT entry maps the logical network address to the public NAT address for a data message flow to which the first and second data messages belong, wherein the NAT entry redirects the second data message to a second output interface of the first edge gateway instead of the first output interface of the first edge gateway.

18. The non-transitory machine-readable medium of claim 15 , wherein the logical network is implemented in a virtual datacenter configured on a set of host computers in a public cloud, the virtual datacenter comprising (i) a set of workloads executing on the host computers and (ii) the plurality of edge gateways executing on the host computers.

19. The non-transitory machine-readable medium of claim 18 , wherein the default route routes the second data message to the second edge gateway because the second edge gateway provides a set of services for the virtual datacenter workloads that are not scaled to all of the edge gateways.

20. The non-transitory machine-readable medium of claim 15 , wherein: the set of instructions for applying the stored NAT entry to redirect the second data message further comprises a set of instructions for modifying a media access control (MAC) address of the second data message from a source MAC address corresponding to the first output interface to a source MAC address corresponding to a second output interface.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2024
From: WANG, YONG; JAIN, JAYANT; SADASIVAN, GANESH; GOLIYA, ABHISHEK
To: VMWARE, INC.
Reel/Frame 066775/0968 →
CHANGE OF NAME Recorded Mar 14, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066798/0386 →
Continuity (2)
Continuation 17845716 · Jun 21, 2022
Related Publication 20240250903A1 · Jul 25, 2024
References Cited (108)
US 8830835B2 · Casado et al. · 2014 [cited by applicant]
US 8964767B2 · Koponen et al. · 2015 [cited by applicant]
US 9137052B2 · Koponen et al. · 2015 [cited by applicant]
US 9209998B2 · Casado et al. · 2015 [cited by applicant]
US 9288081B2 · Casado et al. · 2016 [cited by applicant]
US 9444651B2 · Koponen et al. · 2016 [cited by applicant]
US 9755960B2 · Moisand et al. · 2017 [cited by applicant]
US 9819581B2 · Chanda · 2017 [cited by examiner]
US 9876672B2 · Casado et al. · 2018 [cited by applicant]
US 9935880B2 · Hammam et al. · 2018 [cited by applicant]
US 10091028B2 · Koponen et al. · 2018 [cited by applicant]
US 10129142B2 · Goliya · 2018 [cited by examiner]
US 10193708B2 · Koponen et al. · 2019 [cited by applicant]
US 10389682B1 · Wu · 2019 [cited by examiner]
US 10686625B2 · Cidon · 2020 [cited by examiner]
US 10735263B1 · McAlary et al. · 2020 [cited by applicant]
US 10754696B1 · Chinnam et al. · 2020 [cited by applicant]
US 10931481B2 · Casado et al. · 2021 [cited by applicant]
US 11005710B2 · Garg et al. · 2021 [cited by applicant]
US 11005963B2 · Maskalik et al. · 2021 [cited by applicant]
US 11095480B2 · Coimbatore Natarajan · 2021 [cited by examiner]
US 11171878B1 · Devireddy et al. · 2021 [cited by applicant]
US 11212238B2 · Cidon et al. · 2021 [cited by applicant]
US 11240203B1 · Eyada · 2022 [cited by applicant]
US 11362992B2 · Devireddy et al. · 2022 [cited by applicant]
US 11582147B2 · Raman et al. · 2023 [cited by applicant]
US 11606290B2 · Patel et al. · 2023 [cited by applicant]
US 11729094B2 · Arumugam et al. · 2023 [cited by applicant]
US 11729095B2 · Sadasivan et al. · 2023 [cited by applicant]
US 20070058604A1 · Lee et al. · 2007 [cited by applicant]
US 20080159150A1 · Ansari · 2008 [cited by applicant]
US 20090003235A1 · Jiang · 2009 [cited by applicant]
US 20090296713A1 · Kompella · 2009 [cited by applicant]
US 20090307713A1 · Anderson et al. · 2009 [cited by applicant]
US 20110126197A1 · Larsen et al. · 2011 [cited by applicant]
US 20110131338A1 · Hu · 2011 [cited by applicant]
US 20120054624A1 · Owens, Jr. et al. · 2012 [cited by applicant]
US 20120110651A1 · Biljon et al. · 2012 [cited by applicant]
US 20120127995A1 · Singh · 2012 [cited by examiner]
US 20130044641A1 · Koponen et al. · 2013 [cited by applicant]
US 20130044751A1 · Casado et al. · 2013 [cited by applicant]
US 20130044752A1 · Koponen et al. · 2013 [cited by applicant]
US 20130044761A1 · Koponen et al. · 2013 [cited by applicant]
US 20130044762A1 · Casado et al. · 2013 [cited by applicant]
US 20130044763A1 · Koponen et al. · 2013 [cited by applicant]
US 20130044764A1 · Casado et al. · 2013 [cited by applicant]
US 20130142203A1 · Koponen et al. · 2013 [cited by applicant]
US 20130185413A1 · Beaty et al. · 2013 [cited by applicant]
US 20130283364A1 · Chang et al. · 2013 [cited by applicant]
US 20140282525A1 · Sapuram et al. · 2014 [cited by applicant]
US 20140334495A1 · Stubberfield et al. · 2014 [cited by applicant]
US 20140376367A1 · Jain et al. · 2014 [cited by applicant]
US 20150113146A1 · Fu · 2015 [cited by applicant]
US 20150193246A1 · Luft · 2015 [cited by applicant]
US 20160105392A1 · Thakkar et al. · 2016 [cited by applicant]
US 20160127202A1 · Dalvi et al. · 2016 [cited by applicant]
US 20160170809A1 · Schmidt et al. · 2016 [cited by applicant]
US 20160182336A1 · Doctor et al. · 2016 [cited by applicant]
US 20160234161A1 · Banerjee et al. · 2016 [cited by applicant]
US 20170033924A1 · Jain et al. · 2017 [cited by applicant]
US 20170063673A1 · Maskalik et al. · 2017 [cited by applicant]
US 20170195517A1 · Seetharaman et al. · 2017 [cited by applicant]
US 20170353351A1 · Cheng et al. · 2017 [cited by applicant]
US 20180091432A1 · Ma · 2018 [cited by examiner]
US 20180176130A1 · Banerjee · 2018 [cited by examiner]
US 20180270308A1 · Shea et al. · 2018 [cited by applicant]
US 20180287902A1 · Chitalia et al. · 2018 [cited by applicant]
US 20180295036A1 · Krishnamurthy et al. · 2018 [cited by applicant]
US 20180332001A1 · Ferrero et al. · 2018 [cited by applicant]
US 20190068500A1 · Hira · 2019 [cited by applicant]
US 20190104051A1 · Cidon et al. · 2019 [cited by applicant]
US 20190104413A1 · Cidon et al. · 2019 [cited by applicant]
US 20190149360A1 · Casado et al. · 2019 [cited by applicant]
US 20190149463A1 · Bajaj et al. · 2019 [cited by applicant]
US 20190238502A1 · Bottorff · 2019 [cited by examiner]
US 20190327112A1 · Nandoori et al. · 2019 [cited by applicant]
US 20190342179A1 · Barnard et al. · 2019 [cited by applicant]
US 20200021483A1 · Boutros · 2020 [cited by examiner]
US 20210067375A1 · Cidon et al. · 2021 [cited by applicant]
US 20210067439A1 · Kommula et al. · 2021 [cited by applicant]
US 20210067468A1 · Cidon et al. · 2021 [cited by applicant]
US 20210075727A1 · Chen et al. · 2021 [cited by applicant]
US 20210112034A1 · Sundararajan et al. · 2021 [cited by applicant]
US 20210126860A1 · Ramaswamy et al. · 2021 [cited by applicant]
US 20210136140A1 · Tidemann et al. · 2021 [cited by applicant]
US 20210184898A1 · Koponen et al. · 2021 [cited by applicant]
US 20210218587A1 · Mishra · 2021 [cited by examiner]
US 20210314291A1 · Chandrashekhar · 2021 [cited by examiner]
US 20210314388A1 · Zhou et al. · 2021 [cited by applicant]
US 20210336886A1 · Vijayasankar et al. · 2021 [cited by applicant]
US 20210359948A1 · Durrani et al. · 2021 [cited by applicant]
US 20220094666A1 · Devireddy et al. · 2022 [cited by applicant]
US 20220311707A1 · Patel et al. · 2022 [cited by applicant]
US 20220311714A1 · Devireddy et al. · 2022 [cited by applicant]
US 20220377009A1 · Raman et al. · 2022 [cited by applicant]
US 20220377020A1 · Sadasivan et al. · 2022 [cited by applicant]
US 20220377021A1 · Sadasivan et al. · 2022 [cited by applicant]
US 20230006920A1 · Arumugam · 2023 [cited by examiner]
US 20230006941A1 · Natarajan et al. · 2023 [cited by applicant]
US 20230239238A1 · Patel et al. · 2023 [cited by applicant]
US 20230262022A1 · Wang et al. · 2023 [cited by applicant]
US 20230396536A1 · Sadasivan et al. · 2023 [cited by applicant]
US 20230396562A1 · Devireddy et al. · 2023 [cited by applicant]
CN 101977156A · 2011 [cited by applicant]
CN 111478850A · 2020 [cited by applicant]
WO 2013026050A1 · 2013 [cited by applicant]
WO 2022060464A1 · 2022 [cited by applicant]
WO 2022250735A1 · 2022 [cited by applicant]