IP Library › Granted Patent US 9,674,139
Granted Patent B2
US 9,674,139 · App. 15/195,043 · Granted Jun 6, 2017

Detection of a misconfigured duplicate IP address in a distributed data center network fabric

Inventors: Vipin Jain (San Jose, CA); Anil Lohiya (Cupertino, CA); Dhananjaya Rao (Milpitas, CA)
Assignee: Cisco Technology, Inc.
H04L61/2046G06F9/45558H04L41/044H04L41/0659H04L43/04H04L43/0823H04L43/16H04L49/70H04L61/103H04L61/2007H04L67/10G06F2009/45595H04L61/20H04L61/2092
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,674,139
App. No.
15/195,043
Granted
Jun 6, 2017
Kind
B2
Abstract

Presented herein are techniques to detect a misconfigured duplicate Internet Protocol (IP) address in a distributed data center network fabric. A network topology is provided that includes a plurality of network elements. A network element receives a configuration message comprising an IP address from a first host associated with the first network element. The IP address is detected to already be in use by a second host associated with a second network element. A request message is provided to the second network element, the request message configured to cause the second network element to attempt to contact the second host. A reply message is received from the second network element. If the reply message indicates that the second host exists at the second network element, an indication of a misconfiguration event is generated. Otherwise, the IP address is associated with the first host.

Claims (55)

1. A method comprising:

at a first network element in an underlay network including a plurality of network elements, receiving, from a first virtual host associated with the first network element, a configuration message comprising an Internet Protocol (IP) address;

querying address information stored on the first network element to determine whether the IP address is already in use by a second virtual host associated with a second network element;

sending to the second network element a message configured to cause the second network element to attempt to contact the second virtual host;

receiving a reply message from the second network element; and

generating an indication of a misconfiguration event when the reply message indicates that the second virtual host exists at the second network element.

2. The method of claim 1 , further comprising associating the IP address with the first virtual host when the reply message indicates that the second virtual host does not exist at the second network element.

3. The method of claim 1 , further comprising:

detecting that a number of misconfiguration events in a log exceeds a pre-defined threshold; and

disabling a port on the first network element associated with the first virtual host.

4. The method of claim 1 , further comprising:

querying a management controller to determine if the first virtual host is associated with a valid event;

receiving a query response from the management controller; and

if the query response indicates that the first virtual host is associated with a valid event, associating the IP address with the first virtual host.

5. The method of claim 4 , wherein the valid event is selected from a group consisting of:

a virtual machine mobility event, and a network interface card (NIC) failover event.

6. The method of claim 1 , wherein generating the indication of the misconfiguration event comprises notifying the first virtual host that the IP address is already in use.

7. The method of claim 1 , further comprising associating the IP address with the first virtual host by providing routes to other network elements in the network.

8. An apparatus comprising:

a plurality of network ports;

a switch unit coupled to the plurality of network ports; and

a processor coupled to the switch unit, and configured to:

receive, from a first virtual host associated with a first network element, a configuration message comprising an Internet Protocol (IP) address;

query stored address information stored to determine whether the IP address is already in use by a second virtual host associated with a second network element;

send to the second network element a message configured to cause the second network element to attempt to contact the second virtual host;

receive a reply message from the second network element; and

generate an indication of a misconfiguration event when the reply message indicates that the second virtual host exists at the second network element.

9. The apparatus of claim 8 , wherein the processor is further configured to associate the IP address with the first virtual host when the reply message indicates that the second virtual host does not exist at the second network element.

10. The apparatus of claim 8 , wherein the processor is further configured to:

detect that a number of misconfiguration events in a log exceeds a pre-defined threshold; and

disable a port on the first network element associated with the first virtual host.

11. The apparatus of claim 8 , wherein the processor is further configured to:

query a management controller to determine if the first virtual host is associated with a valid event;

receive a query response from the management controller; and

if the query response indicates that the first virtual host is associated with a valid event, associating the IP address with the first virtual host.

12. The apparatus of claim 11 , wherein the valid event is selected from a group consisting of:

a virtual machine mobility event, and a network interface card (NIC) failover event.

13. The apparatus of claim 8 , wherein the processor is configured to generate the indication of the misconfiguration event by notifying the first virtual host that the IP address is already in use.

14. The apparatus of claim 8 , wherein the processor is configured to log the misconfiguration event in a log.

15. The apparatus of claim 8 , wherein the processor is configured to associate the IP address with the first virtual host by providing routes to other network elements in the network.

16. A non-transitory processor readable storage media encoded with software comprising computer executable instructions, that when executed by a processor, cause the processor to:

at a first network element in an underlay network including a plurality of network elements, receive, from a first virtual host associated with the first network element, a configuration message comprising an Internet Protocol (IP) address;

query address information stored on the first network element to determine whether the IP address is already in use by a second virtual host associated with a second network element;

send to the second network element a message configured to cause the second network element to attempt to contact the second virtual host;

receive a reply message from the second network element; and

generate an indication of a misconfiguration event when the reply message indicates that the second virtual host exists at the second network element.

17. The processor readable storage media of claim 16 , further comprising instructions that cause the processor to associate the IP address with the first virtual host when the reply message indicates that the second virtual host does not exist at the second network element.

18. The processor readable storage media of claim 16 , further comprising instructions that cause the processor to:

detect that a number of misconfiguration events in a log exceeds a pre-defined threshold; and

disable a port on the first network element associated with the first virtual host.

19. The processor readable storage media of claim 18 , wherein the valid event is selected from a group consisting of: a virtual machine mobility event, and a network interface card (NIC) failover event.

20. The processor readable storage media of claim 16 , further comprising instructions that cause the processor to:

query a management controller to determine if the first host is associated with a valid event;

receive a query response from the management controller; and

if the query response indicates that the first host is associated with a valid event, associate the IP address with the first host.

Continuity (2)
Continuation 14097747 · Dec 5, 2013
Related Publication 20160308825A1 · Oct 20, 2016