IP Library › Granted Patent US 11,876,696
Granted Patent B2
US 11,876,696 · App. 17/463,202 · Granted Jan 16, 2024

Methods and systems for network flow tracing within a packet processing pipeline

Inventors: Vijay Srinivasan (Santa Clara, CA); Sarat Kamisetty (Fremont, CA); Krishna Doddapaneni (Cupertino, CA); John Cruz (San Jose, CA); Loganathan Nallusamy (Bengaluru, IN)
Assignee: PENSANDO SYSTEMS INC.
H04L43/10H04L41/12H04L43/062H04L49/3063H04L69/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,876,696
App. No.
17/463,202
Granted
Jan 16, 2024
Kind
B2
Abstract

Network appliances can use packet processing pipeline circuits to implement network rules for processing network packet flows by configuring the pipeline's processing stages to execute specific policies for specific network packets in accordance with the network rules. Trace reports that indicate network rules implemented at specific processing stages can be more informative than those indicating policies implemented by the processing stages. A method implemented by a network appliance can store network rules for processing network flows by the processing stages of a packet processing pipeline circuit. The method can produce a trace report in response to receiving a trace directive for one of the network flows wherein one of the processing stages has applied a network rule to a network packet in one of the network flows. The trace report can indicate the network rule in association with the processing stage and the network flow.

Claims (60)

1. A network appliance comprising:

a packet processing pipeline circuit that includes a plurality of processing stages; and

a memory configured to store a plurality of network rules for processing a plurality of network flows,

wherein the packet processing pipeline circuit and the memory are configured to implement network flow tracing, wherein the network flow tracing includes:

using the plurality of network rules and a trace directive to produce a configuration data that includes a plurality of policies;

using the plurality of network rules to produce a configuration map;

using the configuration data to configure the plurality of processing stages of the packet processing pipeline circuit to implement the plurality of policies to process the plurality of network flows;

producing, by the packet processing pipeline circuit, a metadata while processing a network packet of one of the plurality of network flows, the metadata including a hardware identifier and a policy identifier;

using the hardware identifier, the policy identifier, and the configuration map to identify one of the plurality of network rules; and

producing, by the network appliance, a trace report that indicates the one of the plurality of network rules in association with a one of the plurality of processing stages and the one of the plurality of network flows.

2. The network appliance of claim 1 wherein the hardware identifier indicates the one of the plurality of processing stages.

3. The network appliance of claim 1 wherein the policy identifier indicates the one of the plurality of network rules applied to the network packet by the one of the plurality of processing stages.

4. The network appliance of claim 1 wherein the packet processing pipeline circuit is configured to process a second network packet of a second one of the plurality of network flows without producing a second metadata that includes a second hardware identifier and a second policy identifier.

5. The network appliance of claim 1 , wherein:

the metadata is produced in response to determining that the trace directive indicates the one of the plurality of network flows.

6. The network appliance of claim 1 , wherein the network appliance is configured to:

inject a debug packet into the packet processing pipeline circuit;

receive a second metadata from the packet processing pipeline circuit; and

use the second metadata to identify a second one of the plurality of network rules, wherein

the trace report indicates application of the second one of the plurality of network rules to the debug packet.

7. The network appliance of claim 6 wherein the debug packet is injected into an inbound network flow or into an outbound network flow.

8. The network appliance of claim 6 wherein the debug packet is transmitted via an egress port.

9. The network appliance of claim 6 wherein the debug packet is not transmitted via an egress port.

10. The network appliance of claim 1 wherein the packet processing pipeline circuit is configured to drop the network packet in accordance with the plurality of network rules.

11. The network appliance of claim 1 wherein the trace report shows a source IP address of the network packet in association with the one of the plurality of network rules.

12. The network appliance of claim 1 wherein the trace report shows a destination IP address and a destination port of the network packet in association with the one of the plurality of network rules.

13. The network appliance of claim 1 wherein

the packet processing pipeline circuit includes a parser that is configured to produce a packet header vector from the network packet, and

the packet header vector produced by the parser does not include the trace directive.

14. A network appliance comprising:

a memory that is configured to store a plurality of network rules for processing a plurality of network flows; and

a packet processing pipeline circuit that includes a plurality of processing stages,

wherein the packet processing pipeline circuit and the memory are configured to implement network flow tracing, wherein the network flow tracing includes:

using the plurality of network rules and a trace directive to produce a configuration data that includes a plurality of policies;

using the configuration data to configure the packet processing pipeline circuit to implement the plurality of policies, the plurality of policies configuring the packet processing pipeline circuit to process the network flows and to produce a metadata for a network packet that is in one of the plurality of network flows;

the metadata including a hardware identifier that indicates one of the plurality of processing stages;

the metadata including a policy identifier that indicates one of the plurality of policies applied by the one of the plurality of processing stages to the network packet;

configuring the network appliance to use the policy identifier and the hardware identifier to identify one of the plurality of network rules; and

configuring the network appliance to produce a trace report that indicates the one of the plurality of network rules in association with the one of the plurality of processing stages and the one of the plurality of network flows.

15. The network appliance of claim 14 wherein the network appliance is configured to:

use the plurality of network rules to produce a configuration map; and

use the configuration map, the policy identifier, and the hardware identifier to identify one of the plurality of network rules.

16. The network appliance of claim 14 wherein the network appliance is configured to:

use the plurality of network rules to generate a configuration map; and

use the configuration map to identify the one of the plurality of network rules.

17. The network appliance of claim 14 wherein the network appliance is configured to:

inject a debug packet into the packet processing pipeline circuit;

receive a second metadata from the packet processing pipeline circuit; and

use a second hardware identifier and a second policy identifier in the second metadata to identify a second one of the plurality of network rules that is one of the plurality of network rules,

wherein

the trace report indicates application of the second one of the plurality of network rules to the debug packet.

18. A network appliance comprising:

a packet processing pipeline circuit that includes a plurality of processing stages;

a storage means for storing a plurality of network rules for processing a network packet in a network flow;

a compilation means for producing a configuration means for configuring the processing stages to implement a plurality of polices and a mapping means for using a hardware identifier and a policy identifier to identify one of the network rules and one of the processing stages;

a control plane means for using the configuration means to configure the processing stages to process the network packet and to produce a metadata that includes the hardware identifier and the policy identifier; and

a reporting means for using the metadata and the mapping means to produce a trace report,

wherein:

the trace report indicates the one of the network rules in association with the one of the processing stages and the network flow.

19. The network appliance of claim 18 wherein the packet processing pipeline circuit is configured via the configuration means to not produce a second metadata while processing a second network packet of a second network flow.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2021
From: SRINIVASAN, VIJAY; KAMISETTY, SARAT; DODDAPANENI, KRISHNA; CRUZ, JOHN; NALLUSAMY, LOGANATHAN
To: PENSANDO SYSTEMS INC.
Reel/Frame 057371/0312 →
Continuity (1)
Related Publication 20230068914A1 · Mar 2, 2023