IP Library › Granted Patent US 10,277,420
Granted Patent B2
US 10,277,420 · App. 15/688,836 · Granted Apr 30, 2019

System and method for providing private instances of shared resources using VxLAN

Inventor: Michael Emory Mazarick (Raleigh, NC)
H04L12/467G06F9/5038H04L12/4633H04L63/0272
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,277,420
App. No.
15/688,836
Granted
Apr 30, 2019
Kind
B2
Abstract

A system and method for providing private instances of shared resources utilizing VxLAN technology is disclosed; the system consisting of a private management local area network (MLAN), a separate virtual local area network (VLAN) to place resources that are to be shared, and private instances (replicas) of the shared resources that are located on a client's private network.

Claims (60)

1. A method for sharing network resources, the method comprising the steps of:

initializing and maintaining, by at least one of a plurality of computing devices, a management local area network (MLAN) comprising at least a physical firewall or a virtual firewall/vtep/router; wherein the virtual firewall/vtep/router contains a virtual Ethernet port;

initializing and maintaining a plurality of client virtual local area networks (VLANs) that utilizes VxLAN standard for providing private instances; wherein each client VLAN comprises a corresponding virtual firewall;

adding a plurality of network resources to the client VLANs; and

removing all VLAN tags, QinQ tags and VxLAN tags by a management system before placing inside a corresponding client's virtual data center;

wherein a plurality of the network resources are virtual resources allocated on at least one networkable computing device, and the step of initializing and maintaining a plurality of client VLANs comprises creating an Ethernet device without IP address and routing information.

2. The method of claim 1 , wherein the plurality of client VLANs share network resources.

3. The method of claim 1 , wherein the plurality of client VLANs share the plurality of network resources.

4. The method of claim 1 , wherein the plurality of network resources are virtual resources.

5. The method of claim 1 , wherein at least one of the plurality of network resources is physical hardware.

6. The method of claim 1 , further comprising the step of: creating, by a client connected with said at least one of a plurality of computing devices, private instances of the plurality of network resources on the client's network.

7. The method of claim 6 , further comprising the step of: adding, by said client, replicas of said private instances of the plurality of network resources and having their MAC/IP assigned and made visible.

8. A system for sharing network resources, the system comprising:

At least one network switch;

At least one client;

A plurality of computing devices, each of said plurality of the computing devices comprising at least one network connection, at least one management console to interface with said at least one client and at least one storage device containing software configured to:

initializing and maintaining a management local area network (MLAN) comprising at least a physical firewall or a virtual firewall/vtep/router; wherein the virtual firewall/vtep/router contains a virtual Ethernet port;

initializing and maintaining a plurality of client virtual local area networks (VLANs) that utilizes VxLAN standard for providing private instances; wherein each client VLAN comprises a corresponding virtual firewall;

adding a plurality of network resources to the client VLANs; and

removing all VLAN tags, QinQ tags and VxLAN tags, by a management system before placing inside a corresponding client's virtual data center;

wherein a plurality of the network resources are virtual resources allocated on at least one networkable computing device, and the step of initializing and maintaining a plurality of client VLANs comprises creating an Ethernet device without IP address and routing information.

9. The system of claim 8 , further comprising a group of storage servers configured to start redundant copies of the firewall/vtep/router; wherein each instance of the firewall/vtep/router containing the same MAC address and network assignment for any attached Ethernet ports.

10. The system of claim 8 , wherein the plurality of client VLANs share network resources.

11. The system of claim 8 , wherein the plurality of client VLANs share the plurality of network resources.

12. The system of claim 8 , wherein the plurality of network resources are virtual resources.

13. The system of claim 8 , wherein at least one of the plurality of network resources is physical hardware.

14. The system claim 8 , further comprising software configured to: create, by said client, private instances of the plurality of network resources on the client's network.

15. The system of claim 14 , further comprising software configured to: add, by said client, replicas of said private instances of the plurality of network resources and having their MAC/IP assigned and made visible.

16. A method for sharing network resources, the method comprising:

providing a management system comprising one or more computing devices and a. management local area network (MLAN):

implementing the MLAN to have a respective device with an Ethernet port, the respective device of the MLAN comprising one of a firewall, a router, or a VTEP;

implementing client virtual local area networks (VLANs) as virtual extensible local area networks (VxLANs) for providing private instances, each of the client VLANs comprising a respective device with a communications port, and each of the client VLANs including an Ethernet device addressable from only the MEAN;

adding a plurality of network resources to the client V LANs, wherein the plurality of network resources are virtual resources allocated on a networkable computing device;

receiving a data packet via the Ethernet port of the respective device of the MLAN; using the management system, removing from the data packet all WAN tags, all QinQ tags and all VLAN tags to provide a filtered packet; and

communicating the filtered packet to the communications port of the respective device of one of the client VLANs.

17. The method of claim 16 , wherein the respective device of the MLAN is a virtual device.

18. The method of claim 16 , wherein the respective device of the MLAN is a physical device.

19. The method of claim 16 , wherein the respective device with the communications port is one of a virtual firewall, a virtual router, and a virtual VTEP.

20. The method of claim 16 , wherein the respective device with the communications port is one of a physical firewall, a physical router, and a physical VTEP.

21. The method of claim 16 , wherein the plurality of client VLANs share the plurality of network resources.

22. The method of claim 16 , wherein at least one of the plurality of network resources is physical hardware.

23. The method of claim 16 , further comprising the step of: creating, by a client connected with said at least one of a plurality of computing devices, private instances of the plurality of network resources on the client's network.

24. The method of claim 23 , further comprising the step of: adding, by said client, replicas of said private instances of the plurality of network resources and having their MAC/IP assigned and made visible.

25. A system for sharing resources, the system comprising:

At least one network switch;

At least one client

A plurality of computing devices, each of said plurality of the computing devices comprising at least one network connection, at least one client and at least one storage device containing software configured to:

implement a management system and a management local area network (MLAN) comprising at least a firewall or a firewall/vtep/router; wherein the firewall/vtep/router contains a. communications port;

implement client virtual local area networks (VLANs) as virtual extensible local area networks (VxLANs) for providing private instances, each of the client VLANs comprising a respective device with a communications port, and each of the client VLANs including a communications device addressable from only the MLAN;

adding a plurality of network resources to the client VLANs wherein the plurality of network resources are resources allocated on a networkable computing device; and

removing all VLAN tags, QinQ tags and VxLAN tags, by a management system before placing inside a corresponding client's virtual data center; wherein a plurality of the network resources are virtual resources allocated on at least one networkable computing device, and the step of initializing and maintaining a plurality of client VLANs comprises creating an Ethernet device without IP address and routing information.

26. The system of claim 25 , wherein the respective device of the MLAN is a virtual device.

27. The system of claim 25 , wherein the respective device of the MLAN is a physical device.

28. The system of claim 25 , wherein the respective device with the communications port is one of a virtual firewall, a virtual router, and a virtual VTEP.

29. The system of claim 25 , wherein the respective device with the communications port is one of a physical firewall, a physical router, and a physical VTEP.

30. The system of claim 25 , further comprising a group of storage servers configured to start redundant copies of the firewall/vtep/router; wherein each instance of the firewall/vtep/router containing the same MAC address and network assignment for any attached communications ports.

31. The system of claim 25 , wherein the plurality of client VLANs share the plurality of network resources.

32. The system of claim 25 , wherein at least one of the plurality of network resources is physical hardware.

33. The system claim 25 , further comprising software configured to: create, by said client, private instances of the plurality of network resources on the client's network.

34. The system of claim 33 , further comprising software configured to: add, by said client, replicas of said private instances of the plurality of network resources and having their MAC/IP assigned and made visible.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2019
From: MAZARICK, MICHAEL E.
To: VDC HOLDINGS LLC
Reel/Frame 048406/0874 →
Continuity (1)
Related Publication 20190068402A1 · Feb 28, 2019