IP Library Granted Patent US 9,374,302
Granted Patent B2
US 9,374,302 · App. 14/262,694 · Granted Jun 21, 2016

Distributed methodology for peer-to-peer transmission of stateful packet flows

Inventors: Robert Bays (San Francisco, CA); Mike Larson (San Francisco, CA); Stephen Hemminger (Beaverton, OR)
Assignee: Brocade Communications Systems, Inc.
H04L45/74G06F9/45558H04L45/302H04L47/2441H04L67/104G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,374,302
App. No.
14/262,694
Granted
Jun 21, 2016
Kind
B2
Abstract

Techniques for enabling peer-to-peer transmission of stateful packet flows in a virtualized network environment are provided. In certain embodiments, a computer system receives a packet belonging to a stateful flow between a first virtual machine and a second virtual machine, accesses flow associating information (e.g., network address) from the packet, determines a second computer system comprising a state analysis owner for the stateful flow, using the flow associating information, and transmits the first packet to the second computer system.

Claims (61)

1. A method comprising:

receiving, by a computer system, a first packet belonging to a stateful flow between a first virtual machine and a second virtual machine;

accessing, by the computer system, flow associating information from the first packet, the flow associating information comprising a source network address and a destination network address;

determining, by the computer system, a source host computer system using the source network address and a destination host computer system using the destination network address;

selecting, by the computer system, from among the source host computer system and the destination host computer system, the host computer system with a lower network address as a state analysis owner for the stateful flow; and

transmitting, by the computer system, the first packet to the selected host computer system.

2. The method of claim 1 , wherein the flow associating information further comprises one or more of session ID or query subset for the first packet belonging to the stateful flow.

3. The method of claim 1 , wherein the state analysis owner for the stateful flow performs run-to-completion state processing on the first packet.

4. The method of claim 1 , wherein the state analysis owner for the stateful flow performs routing functions for packets between the first virtual machine and the second virtual machine.

5. The method of claim 1 , wherein the stateful flow comprises one of firewall traffic, network address translation (NAT) traffic, or application layer classification for Quality of Service (QoS).

6. A non-transitory computer readable medium having stored thereon program code executable by a processor, the program code comprising:

code that causes the processor to receive a first packet belonging to a stateful flow between a first virtual machine and a second virtual machine;

code that causes the processor to access flow associating information from the first packet, the flow associating information comprising a source network address and a destination network address for the first packet;

code that causes the processor to determine that only one of the source network address and the destination network address is resolvable to a host computer system;

code that causes the processor to select the host computer system as a state analysis owner for the stateful flow; and

code that causes the processor to transmit the first packet to the selected host computer system.

7. The non-transitory computer readable medium of claim 6 , wherein the flow associating information further comprises one or more of session ID or query subset for the first packet belonging to the stateful flow.

8. The non-transitory computer readable medium of claim 6 , wherein the state analysis owner for the stateful flow performs run-to-completion state processing on the first packet.

9. The non-transitory computer readable medium of claim 6 , wherein the state analysis owner for the stateful flow performs routing functions for packets between the first virtual machine and the second virtual machine.

10. The non-transitory computer readable medium of claim 6 , wherein the stateful flow comprises one of firewall traffic, network address translation (NAT) traffic, or application layer classification for Quality of Service (QoS).

11. A computer system comprising:

a processor; and

a non-transitory computer readable medium having stored thereon executable program code which, when executed by the processor, causes the processor to:

receive a first packet belonging to a stateful flow between a first virtual machine and a second virtual machine;

access flow associating information from the first packet, the flow associating information comprising a source network address and a destination network address;

determine a source host computer system using the source network address and a destination host computer system using the destination network address;

select, from among the source host computer system and the destination host computer system, the host computer system with a higher network address as a state analysis owner for the stateful flow; and

transmit the first packet to the selected host computer system.

12. The computer system of claim 11 , wherein the flow associating information further comprises one or more of session ID or query subset for the first packet belonging to the stateful flow.

13. The computer system of claim 11 , wherein the state analysis owner for the stateful flow is further configured to perform run-to-completion state processing on the first packet.

14. The computer system of claim 11 , wherein the stateful flow comprises one of firewall traffic, network address translation (NAT) traffic, or application layer classification for Quality of Service (QoS).

15. A method comprising:

receiving, by a computer system, a first packet belonging to a stateful flow between a first virtual machine and a second virtual machine;

accessing, by the computer system, flow associating information from the first packet, the flow associating information comprising a source network address and a destination network address;

determining, by the computer system, a source host computer system using the source network address and a destination host computer system using the destination network address;

selecting, by the computer system, from among the source host computer system and the destination host computer system, the host computer system with a higher network address as a state analysis owner for the stateful flow; and

transmitting, by the computer system, the first packet to the selected host computer system.

16. A method comprising:

receiving, by a computer system, a first packet belonging to a stateful flow between a first virtual machine and a second virtual machine;

accessing, by the computer system, flow associating information from the first packet, the flow associating information comprising a source network address and a destination network address;

determining, by the computer system, that only one of the source network address and the destination network address is resolvable to a host computer system;

selecting, by the computer system, the host computer system with the resolvable network address as a state analysis owner for the stateful flow; and

transmitting, by the computer system, the first packet to the selected host computer system.

17. A computer system comprising:

a processor; and

a non-transitory computer readable medium having stored thereon executable program code which, when executed by the processor, causes the processor to:

receive a first packet belonging to a stateful flow between a first virtual machine and a second virtual machine;

access flow associating information from the first packet, the flow associating information comprising a source network address and a destination network address;

determine a source host computer system using the source network address and a destination host computer system using the destination network address;

select from among the source host computer system and the destination host computer system, the host computer system with a lower network address as a state analysis owner for the stateful flow; and

transmit the first packet to the selected host computer system.

18. The computer system of claim 17 , wherein the state analysis owner for the stateful flow performs one or more of run-to-completion state processing on the first packet or routing functions for packets between the first virtual machine and the second virtual machine.

19. A computer system comprising:

a processor; and

a non-transitory computer readable medium having stored thereon executable program code which, when executed by the processor, causes the processor to:

receive a first packet belonging to a stateful flow between a first virtual machine and a second virtual machine;

access flow associating information from the first packet, the flow associating information comprising a source network address and a destination network address;

determine that only one of the source network address and the destination network address is resolvable to a host computer system;

select the host computer system with the resolvable network address as the state analysis owner for the stateful flow; and

transmit the first packet to the selected host computer system.

20. The computer system of claim 19 , wherein the state analysis owner for the stateful flow performs one or more of run-to-completion state processing on the first packet or routing functions for packets between the first virtual machine and the second virtual machine.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 11, 2021
From: AT&T INTELLECTUAL PROPERTY I, LP
To: CIENA CORPORATION
Reel/Frame 058088/0833 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2017
From: BROCADE COMMUNICATIONS SYSTEMS, INC.
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 043248/0750 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 18, 2014
From: BAYS, ROBERT; LARSON, MIKE; HEMMINGER, STEPHEN
To: BROCADE COMMUNICATIONS SYSTEMS, INC.
Reel/Frame 033126/0361 →
Continuity (2)
Provisional Application 61816571 · Apr 26, 2013
Related Publication 20140341218A1 · Nov 20, 2014