IP Library Granted Patent US 10,097,403
Granted Patent B2
US 10,097,403 · App. 14/856,342 · Granted Oct 9, 2018

Methods and systems for controller-based data forwarding rules without routing protocols

Inventors: Venkataraman Anand (San Ramon, CA); Arivu Ramasamy (San Jose, CA)
Assignee: CLOUDGENIX, INC.
H04L41/0668G06F17/30598G06F17/30876H04L12/4633H04L12/4641H04L43/0817H04L45/28H04L47/781H04L47/825H04L69/40H04L43/0811H04L43/10H04L45/22H04L61/1511H04L61/1523H04L61/2503H04W84/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,097,403
App. No.
14/856,342
Filed
Sep 16, 2015
Granted
Oct 9, 2018
Kind
B2
Art Unit
2443
USPC
709/224
Abstract

A method includes determining a plurality of network segments comprising a network, determining a manner in which the plurality of segments are connected, determining network segments and how segments are connected, at least in part, without a routing protocol, discovering a plurality of external network segments via a hub device associated with the network and utilizing the plurality of network segments comprising the network, the manner in which the plurality of segments are connected and the plurality of external network segments.

Claims (27)

1. A method comprising:

determining a plurality of network segments comprising a network;

determining a manner in which the plurality of network segments are connected by determining a plurality of entities connected via the plurality of network segments and identifying, for each entity of the plurality of entities, whether the entity is a hub device or a spoke device;

wherein the determining the plurality of network segments comprising the network and the manner in which the plurality of network segments are connected, are determined, at least in part, without use of a routing protocol;

discovering a plurality of external network segments via an identified hub device associated with the network;

storing the plurality of network segments, the manner in which the plurality of network segments are connected, and the plurality of external network segments in a database of a multi-tenant controller; and

utilizing the plurality of network segments comprising the network, the manner in which the plurality of network segments are connected, the plurality of external network segments, by the multi-tenant controller, and a set of rules to create a forwarding table, wherein the set of rules includes a rule that no traffic is allowed to transit through a spoke device, a rule that traffic is allowed to transit through a hub device, a rule that no direct traffic is allowed between hub devices, and a rule that each hub device has at most one path for a given IP prefix.

2. The method of claim 1 , wherein the utilizing further comprises performing network topology identification, simulation, and load testing.

3. The method of claim 2 , wherein the identification, simulation, and load testing are controlled by the multi-tenant controller.

4. The method of claim 1 , further comprising detecting asymmetric network data traffic and associated network devices.

5. The method of claim 1 , wherein the network comprises connectivity selected from a group including hybrid, physical, and logical.

6. The method of claim 1 , wherein the network employs routing protocols selected from a group including BGP, IS-IS, EIGRP, and OSPF.

7. The method of claim 1 , wherein routing in the network is based, at least in part, on a network prefix type.

8. A centrally controllable multi-tenant controller for controlling a plurality of assets across a plurality of distributed computing environments wherein the controller includes a database for storing program instructions and is configured to:

determine a plurality of network segments comprising a network;

determine a manner in which the plurality of network segments are connected;

identify, for each asset of the plurality of assets, whether the asset is a hub device or a spoke device;

where the determination of the plurality of network segments comprising the network and the manner in which the plurality of network segments are connected, are determined, at least in part, without use of a routing protocol;

discover a plurality of external network segments via an identified hub device associated with the network;

store the plurality of network segments, the manner in which the plurality of network segments are connected, and the plurality of external segments in the database; and

utilize the plurality of network segments and addresses comprising the network, the manner in which the plurality of segments are connected, the plurality of external network segments, and a set of rules to establish at least one forwarding table, wherein the set of rules includes a rule that no traffic is allowed to transit through a spoke device, a rule that traffic is allowed to transit through a hub device, a rule that no direct traffic is allowed between hub devices, and a rule that each hub device has at most one path for a given IP prefix.

9. The centrally controllable multi-tenant controller of claim 8 , wherein the utilizing further comprises performing network topology identification, simulation and load testing.

10. The centrally controllable multi-tenant controller of claim 9 , wherein the identification, simulation and load testing are controlled by a multi-tenant controller.

11. The centrally controllable multi-tenant controller of claim 8 , further configured to detect asymmetric network data traffic and associated network devices.

12. The centrally controllable multi-tenant controller of claim 8 , wherein the network comprises connectivity selected from a group including hybrid, physical and logical.

13. The centrally controllable multi-tenant controller of claim 8 , wherein the network employs routing protocols selected from a group including BGP, IS-IS, EIGRP and OSPF.

14. The centrally controllable multi-tenant controller of claim 8 , wherein routing in the network is based, at least in part, on a network prefix type.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 21, 2021
From: CLOUDGENIX INC.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 058449/0010 →
RELEASE OF SECURITY INTEREST Recorded May 5, 2020
From: COMERICA BANK
To: CLOUDGENIX, INC.
Reel/Frame 052573/0502 →
SECURITY INTEREST Recorded Aug 22, 2018
From: CLOUDGENIX, INC.
To: COMERICA BANK
Reel/Frame 046668/0798 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2015
From: ANAND, VENKATARAMAN; RAMASAMY, ARIVU
To: CLOUDGENIX, INC.
Reel/Frame 036691/0337 →
Continuity (2)
Provisional Application 62051293 · Sep 16, 2014
Related Publication 20160080211A1 · Mar 17, 2016
Cited By (17)
US 12,191,926 US 12,237,873 US 12,244,359 US 12,259,711 US 12,282,837 US 12,327,168 US 12,333,401 US 12,333,402 US 12,333,403 US 12,372,946 US 12,535,801 US 12,556,443 US 12,572,136 US 12,578,707 US 12,585,255 US 12,596,351 US 12,656,757