IP Library Granted Patent US 8,265,071
Granted Patent B2
US 8,265,071 · App. 12/558,126 · Granted Sep 11, 2012

Methods and apparatus related to a flexible data center security architecture

Assignee: Juniper Networks, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,265,071
App. No.
12/558,126
Filed
Sep 11, 2009
Granted
Sep 11, 2012
Kind
B2
Examiner
DUONG, DUC T
Art Unit
2467
USPC
370/388
Abstract

In one embodiment, edge devices can be configured to be coupled to a multi-stage switch fabric and peripheral processing devices. The edge devices and the multi-stage switch fabric can collectively define a single logical entity. A first edge device from the edge devices can be configured to be coupled to a first peripheral processing device from the peripheral processing devices. The second edge device from the edge devices can be configured to be coupled to a second peripheral processing device from the peripheral processing devices. The first edge device can be configured such that virtual resources including a first virtual resource can be defined at the first peripheral processing device. A network management module coupled to the edge devices and configured to provision the virtual resources such that the first virtual resource can be migrated from the first peripheral processing device to the second peripheral processing device.

Claims (50)

1. An apparatus, comprising:

a multi-stage switch fabric;

a plurality of edge devices having a first plurality of ports configured to be coupled to the multi-stage switch fabric and a second plurality of ports configured to be coupled to the plurality of peripheral processing devices, the plurality of edge devices and the multi-stage switch fabric collectively defining a single logical entity, the plurality of edge devices includes a first edge device and a second edge device, the first edge device being configured to be coupled to a first peripheral processing device from the plurality of peripheral processing devices, the second edge device being configured to be coupled to a second peripheral processing device from the plurality of peripheral processing devices, the first edge device being configured such that a plurality of virtual resources including a first virtual resource are defined at the first peripheral processing device; and

a network management module coupled to the plurality of edge devices, the network management module configured to provision the plurality of virtual resources such that the first virtual resource can be migrated from the first peripheral processing device to the second peripheral processing device.

2. The apparatus of claim 1 , wherein:

a number of ports in the second plurality of ports for the plurality of edge devices is at least 1,000 ports.

3. The apparatus of claim 1 , wherein:

a number of ports in the second plurality of ports for the plurality of edge devices is at least 100,000 ports.

4. The apparatus of claim 1 , wherein:

a number of ports in the first plurality of ports for the plurality of edge devices is less than a number of ports in the second plurality of ports of the plurality of edge devices.

5. The apparatus of claim 1 , wherein:

the network management module is configured to provision the plurality of virtual resources such that a virtual resource from a plurality of virtual resources from each peripheral processing device can be moved from the plurality of peripheral processing devices to at least one of the remaining peripheral processing device from the plurality of peripheral processing devices.

6. The apparatus of claim 1 , wherein:

the plurality of edge devices and the multi-stage switch fabric collectively are configured to provide connectivity at line rate for each edge device from the plurality of edge devices to each remaining edge device from the plurality of edge devices such that congestion at the first virtual resource is isolated from data traffic sent to and received from a second virtual resource at the first peripheral processing device from the plurality of peripheral processing devices.

7. The apparatus of claim 1 , wherein:

the second edge device is configured to be coupled to a second peripheral processing device from the plurality of peripheral processing devices; and

the plurality of edge devices and the multi-stage switch fabric collectively are configured to provide connectivity at line rate for each edge device from the plurality of edge devices to each remaining edge device from the plurality of edge devices such that congestion at the first virtual resource is isolated from data traffic sent to and received from a second virtual resource at the second peripheral processing.

8. An apparatus, comprising:

a multi-stage switch fabric;

a first plurality of edge devices, the first plurality of edge devices collectively having a plurality of output ports coupled to the multi-stage switch fabric and collectively having at least 1,000 input ports configured to be coupled to a plurality of peripheral processing devices, each edge device from the plurality of edge devices being configured such that a plurality of virtual resources are defined at the plurality of peripheral processing devices;

a second plurality of edge devices coupled to the multi-stage switch fabric, the first plurality of edge devices, the second plurality of edge devices and the multi-stage switch fabric collectively defining a single logical entity; and

a network management module coupled to the first plurality of edge devices and the second plurality of edge devices, the network management module configured to provision the plurality of processing devices such that the plurality of virtual resources from a first peripheral processing device from the plurality of peripheral processing devices can be migrated to a second peripheral processing from the plurality of peripheral processing devices.

9. The apparatus of claim 8 , wherein:

the second plurality of edge devices collectively has a plurality of ports coupled to the multi-stage switch fabric and collectively having at least 1,000 ports configured to be coupled to a plurality of peripheral processing devices.

10. The apparatus of claim 8 , wherein:

the second plurality of edge devices collectively has a plurality of ports coupled to the multi-stage switch fabric and collectively having at least 100,000 ports configured to be coupled to a plurality of peripheral processing devices.

11. An apparatus, comprising:

a multi-stage switch fabric; and

a plurality of edge devices having a first plurality of ports configured to be coupled to the multi-stage switch fabric and a second plurality of ports configured to be coupled to the plurality of peripheral processing devices, a number of ports in the first plurality of ports of the plurality of edge devices being less than a number of ports in the second plurality of ports of the plurality of edge devices, each edge device from the plurality of edge devices being configured such that a plurality of virtual resources are defined at the plurality of peripheral processing devices, the plurality of edge devices and the multi-stage switch fabric collectively defining a single logical entity,

the plurality of edge devices and the multi-stage switch fabric collectively configured such that data traffic sent from each virtual resource from the plurality of virtual resources through a respective edge device from the plurality of edge devices and through the multi-stage switch fabric is isolated from data traffic sent from the remaining virtual resources from the plurality of virtual resources associated with the remaining edge devices from the plurality of edge devices.

12. The apparatus of claim 11 , wherein the multi-stage switch fabric configured to provide connectivity at line rate for each edge device from the plurality of edge devices to each remaining edge device from the plurality of edge devices such that each virtual resource from the plurality of virtual resources is equitably accessible by each remaining virtual resource from the plurality of virtual resources.

13. The apparatus of claim 11 , wherein:

the plurality of edge devices includes a first edge device;

the plurality of virtual resources including a first virtual resource and a second virtual resource to which the first edge device is configured to be coupled; and

the multi-stage switch fabric configured to provide connectivity at line rate for each edge device from the plurality of edge devices to each remaining edge device from the plurality of edge devices such that congestion at the first virtual resource does not affect data traffic sent to and received from the second virtual resource.

14. The apparatus of claim 11 , wherein:

the plurality of edge devices includes a first edge device and a second edge device;

the plurality of virtual resources including a first virtual resource to which the first edge device is configured to be coupled and a second virtual resource to which the second edge device is configured to be coupled; and

the multi-stage switch fabric configured to provide connectivity at line rate for each edge device from the plurality of edge devices to each remaining edge device from the plurality of edge devices such that congestion at the first virtual resource does not affect data traffic sent to and received from the second virtual resource.

15. The apparatus of claim 11 , wherein:

the plurality of edge devices collectively having a plurality of ports coupled to the multi-stage switch fabric and collectively having at least 1,000 ports configured to be coupled to a plurality of peripheral processing devices.

16. The apparatus of claim 11 , wherein:

the plurality of edge devices collectively having a plurality of ports coupled to the multi-stage switch fabric and collectively having at least 100,000 ports configured to be coupled to a plurality of peripheral processing devices.

17. The apparatus of claim 11 , wherein:

the multi-stage switch fabric is configured as a deterministic network that admits a plurality of cells associated with a packet from an edge device from the plurality of edge devices when delivery within the switch fabric of the plurality of cells can be substantially guaranteed without loss through the multi-stage switch fabric.

18. The apparatus of claim 11 , wherein the plurality of peripheral processing devices includes a first peripheral processing device configured to communicate with a fiber channel protocol and a second peripheral processing device configured to communicate with a fiber-channel-over-Ethernet protocol.

19. The apparatus of claim 11 , wherein the plurality of edge devices includes a first edge device having a plurality of queues, the apparatus further comprising:

a flow control module coupled to the first edge device and configured to provide flow control on a per queue basis, each queue from the plurality of queues being uniquely associated with a virtual resource from the plurality of virtual resources at the peripheral processing device coupled to the first edge device.

20. The apparatus of claim 11 , further comprising:

a flow control module coupled to the plurality of edge devices, the flow control module configured to provide flow control for each virtual resource from the plurality of virtual resources for each edge device from the plurality of edge devices.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2009
From: SINDHU, PRADEEP; AYBAY, GUNES; FRAILONG, JEAN-MARC; VENKATRAMANI, ANJAN; VOHRA, QUAIZAR
To: JUNIPER NETWORKS, INC.
Reel/Frame 023527/0541 →
Continuity (15)
Continuation In Part 12343728 · Dec 24, 2008
Continuation In Part 12345500 · Dec 29, 2008
Continuation In Part 12345502 · Dec 29, 2008
Continuation In Part 12242224 · Sep 30, 2008
Continuation In Part 12558126
Continuation In Part 12242230 · Sep 30, 2008
Continuation In Part 12558126
Continuation In Part 12495337 · Jun 30, 2009
Continuation In Part 12495344 · Jun 30, 2009
Continuation In Part 12495358 · Jun 30, 2009
Continuation In Part 12495361 · Jun 30, 2009
Continuation In Part 12495364 · Jun 30, 2009
Provisional Application 61098516 · Sep 19, 2008
Provisional Application 61096209 · Sep 11, 2008
Related Publication 20100061242A1 · Mar 11, 2010