IP Library Granted Patent US 12,413,527
Granted Patent B2
US 12,413,527 · App. 18/607,325 · Granted Sep 9, 2025

Offloading network address translation and firewall rules to tier-1 routers for gateway optimization

Inventors: Gaurav Jindal (Pune, IN); Chandan Ghosh (Bangalore, IN); Neeraj Mantri (Pune, IN); Rajesh Sahu (Bangalore, IN)
Assignee: VMware LLC
H04L47/18H04L12/66H04L61/2528H04L61/2557
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,413,527
App. No.
18/607,325
Granted
Sep 9, 2025
Kind
B2
Abstract

The disclosure provides an approach for gateway optimization. Embodiments include receiving, at a first gateway associated with a first tenant within a data center, a packet directed to a first public network address of an endpoint associated with a second tenant within the data center. Embodiments include performing, by the first gateway, network address translation (NAT) to translate the first public network address to a private network address of the endpoint. Embodiments include forwarding, by the first gateway, the packet to an edge gateway of the data center. Embodiments include forwarding, by the edge gateway, the packet to a second gateway associated with the second tenant within the data center without sending the packet to a public interface of the edge gateway. Embodiments include forwarding, by the second gateway, the packet to the endpoint.

Claims (63)

1. A method of gateway optimization, comprising:

receiving, at a first gateway associated with a first tenant within a data center, a packet directed to a first public network address of an endpoint associated with a second tenant within the data center;

performing, by the first gateway, network address translation (NAT) to translate the first public network address to a private network address of the endpoint;

forwarding, by the first gateway, the packet to an edge gateway of the data center;

forwarding, by the edge gateway, the packet to a second gateway associated with the second tenant within the data center without sending the packet to a public interface of the edge gateway; and

forwarding, by the second gateway, the packet to the endpoint.

2. The method of claim 1 , further comprising:

receiving, by the first gateway, one or more NAT table entries from the edge gateway, wherein the performing of the NAT to translate the first public network address to the private network address of the endpoint is based on the one or more NAT table entries.

3. The method of claim 1 , further comprising:

determining, by the second gateway, that the packet did not undergo firewall inspection at the edge gateway; and

applying, by the second gateway, one or more firewall rules to the packet based on the determining that the packet did not undergo firewall inspection at the edge gateway.

4. The method of claim 3 , wherein the determining, by the second gateway, that the packet did not undergo firewall inspection at the edge gateway is based on an indication in the packet.

5. The method of claim 4 , wherein the indication in the packet comprises:

a packet format associated with the data center;

a packet marker; or

absence of the packet marker.

6. The method of claim 3 , further comprising:

receiving, by the second gateway, the one or more firewall rules from the edge gateway as part of a firewall synchronization.

7. The method of claim 1 , further comprising:

maintaining, by the second gateway, state information related to the packet; receiving, by the second gateway, from the endpoint, an additional packet in response to the packet; and

performing, by the second gateway, NAT on the additional packet based on the state information related to the packet.

8. A system for gateway optimization, comprising:

at least one memory; and

at least one processor coupled to the at least one memory, the at least one processor and the at least one memory configured to:

receive, at a first gateway associated with a first tenant within a data center, a packet directed to a first public network address of an endpoint associated with a second tenant within the data center;

perform, by the first gateway, network address translation (NAT) to translate the first public network address to a private network address of the endpoint;

forward, by the first gateway, the packet to an edge gateway of the data center;

forward, by the edge gateway, the packet to a second gateway associated with the second tenant within the data center without sending the packet to a public interface of the edge gateway; and

forward, by the second gateway, the packet to the endpoint.

9. The system of claim 8 , wherein the at least one processor and the at least one memory are further configured to:

receive, by the first gateway, one or more NAT table entries from the edge gateway, wherein the performing of the NAT to translate the first public network address to the private network address of the endpoint is based on the one or more NAT table entries.

10. The system of claim 8 , wherein the at least one processor and the at least one memory are further configured to:

determine, by the second gateway, that the packet did not undergo firewall inspection at the edge gateway; and

apply, by the second gateway, one or more firewall rules to the packet based on the determining that the packet did not undergo firewall inspection at the edge gateway.

11. The system of claim 10 , wherein the determining, by the second gateway, that the packet did not undergo firewall inspection at the edge gateway is based on an indication in the packet.

12. The system of claim 11 , wherein the indication in the packet comprises:

a packet format associated with the data center;

a packet marker; or

absence of the packet marker.

13. The system of claim 10 , wherein the at least one processor and the at least one memory are further configured to:

receive, by the second gateway, the one or more firewall rules from the edge gateway as part of a firewall synchronization.

14. The system of claim 8 , wherein the at least one processor and the at least one memory are further configured to:

maintain, by the second gateway, state information related to the packet;

receive, by the second gateway, from the endpoint, an additional packet in response to the packet; and

perform, by the second gateway, NAT on the additional packet based on the state information related to the packet.

15. A non-transitory computer readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to:

receive, at a first gateway associated with a first tenant within a data center, a packet directed to a first public network address of an endpoint associated with a second tenant within the data center;

perform, by the first gateway, network address translation (NAT) to translate the first public network address to a private network address of the endpoint;

forward, by the first gateway, the packet to an edge gateway of the data center;

forward, by the edge gateway, the packet to a second gateway associated with the second tenant within the data center without sending the packet to a public interface of the edge gateway; and

forward, by the second gateway, the packet to the endpoint.

16. The non-transitory computer readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

receive, by the first gateway, one or more NAT table entries from the edge gateway, wherein the performing of the NAT to translate the first public network address to the private network address of the endpoint is based on the one or more NAT table entries.

17. The non-transitory computer readable medium of claim 15 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

determine, by the second gateway, that the packet did not undergo firewall inspection at the edge gateway; and

apply, by the second gateway, one or more firewall rules to the packet based on the determining that the packet did not undergo firewall inspection at the edge gateway.

18. The non-transitory computer readable medium of claim 17 , wherein the determining, by the second gateway, that the packet did not undergo firewall inspection at the edge gateway is based on an indication in the packet.

19. The non-transitory computer readable medium of claim 18 , wherein the indication in the packet comprises:

a packet format associated with the data center;

a packet marker; or

absence of the packet marker.

20. The non-transitory computer readable medium of claim 17 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:

receive, by the second gateway, the one or more firewall rules from the edge gateway as part of a firewall synchronization.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2024
From: JINDAL, GAURAV; GHOSH, CHANDAN; MANTRI, NEERAJ; SAHU, RAJESH
To: VMWARE, INC.
Reel/Frame 066939/0094 →
CHANGE OF NAME Recorded Mar 28, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066945/0839 →
Continuity (1)
Related Publication 20250119383A1 · Apr 10, 2025
References Cited (19)
US 10880265B1 · Li · 2020 [cited by examiner]
US 11375005B1 · Rolando · 2022 [cited by examiner]
US 20170063782A1 · Jain · 2017 [cited by examiner]
US 20180062880A1 · Yu · 2018 [cited by examiner]
US 20180287996A1 · Tripathy · 2018 [cited by examiner]
US 20190245949A1 · Wang · 2019 [cited by examiner]
US 20200106706A1 · Mayya · 2020 [cited by examiner]
US 20200186496A1 · Mohanty · 2020 [cited by examiner]
US 20210067378A1 · Coimbatore Natarajan · 2021 [cited by examiner]
US 20220231944A1 · Jindal · 2022 [cited by examiner]
US 20220231993A1 · Sharma · 2022 [cited by examiner]
US 20220239629A1 · Wu · 2022 [cited by examiner]
US 20220263791A1 · Brar · 2022 [cited by examiner]
US 20220263793A1 · Baker · 2022 [cited by examiner]
US 20220286431A1 · Winn · 2022 [cited by examiner]
US 20220394017A1 · Solanki · 2022 [cited by examiner]
US 20230031821A1 · Keane · 2023 [cited by examiner]
US 20230420147A1 · Baker · 2023 [cited by examiner]
US 20240406101A1 · Hawari · 2024 [cited by examiner]